The Sydney Morning Herald
Elias Visontay September 24, 2026 — 4:01pm
The Albanese government is scrambling to answer questions about national security and the dangers posed by artificial intelligence following revelations that a rogue AI agent deployed by OpenAI hacked sensitive Australian data, including aggregate Medicare records.
As officials continue to investigate what happened, and the global tech giant responsible for the agent faces a potential referral to police, here’s a run-down of everything we know so far about the incident.
What is an AI agent?
While based on the same AI models as chatbots that have become mainstream, artificially intelligent agents are an increasingly common offering and tool for both users as well as organisations.
They act autonomously to perform a task or pursue a goal specified by a user without needing specific step-by-step instructions for how to deliver that outcome.
AI agents can be deployed to act on behalf of a user to search for products, compare prices and execute transactions based on previously gathered information on their needs and preferences.
They can also be used by businesses to conduct negotiations and buy or sell products, as well as to conduct research – as was the case with this latest OpenAI incident.
What happened?
The breach occurred when OpenAI deployed an agent to conduct internet-based research into public medicine spending to test its model’s capabilities.
As part of this research, the AI agent scoured the web for Australian public health data and accessed three government websites, where it gained publicly accessible information.
However, it also attempted to access protected files from the Medicare Statistics Reporting Service portal. The agent encountered repeated blocks while seeking the information, but ultimately found ways around to gain unauthorised access to other areas.
In addition to accessing public and private files, OpenAI’s agent also wrote files to an internal government server. It is not yet known what files it wrote, or what effect that had.
How OpenAI’s Medicare breach unfolded
June 18 – An OpenAI agent breaches the Medicare Statistics Reporting Service portal. The agent also accesses three other government websites, but only captures publicly available information.
August- OpenAI becomes aware of a breach and begins investigation.
First week of September – Defence Minister Richard Marles meets OpenAI chief Sam Altman in San Francisco. The pair do not discuss the breach.
September 10 – OpenAI informs Services Australia of the breach via an email sent to a public inbox.
September 11 – Services Australia sees OpenAI’s email and investigates over the following four days.
September 15 – Services Australia reports the email to the Australian Cyber Security Centre, a unit within the Australian Signals Directorate.
September 17 – Public Service Minister Katy Gallagher is informed of the breach. She speaks with Marles, Home Affairs Minister Tony Burke, Services Australia, and the Australian Signals Directorate.
September 19/20 – Prime Minister Anthony Albanese briefed on the breach.
September 23 – (United States time)Albanese speaks with Altman and expresses “extreme concern” over the incident, holds a press conference on the sidelines of the United Nations General Assembly. Government prepares task force to investigate the matter.
Deputy Prime Minister Richard Marles likened the Medicare portal’s security to a “fence”, whereas he said Australians’ personal data held by government sat “inside a safe”, and sensitive national security information “sits behind a fortress”. This data was not national security information and was held on a “legacy” website, Finance Minister Katy Gallagher conceded, suggesting it was easier to access.
The breach has alarmed the government, including Prime Minister Anthony Albanese. “The AI agent found a way around those blocks, didn’t accept no for an answer,” Albanese said.
Why did OpenAI do this?
OpenAI has claimed it did not instruct its agent to breach Australian government security barriers to access protected files. The company said its models had accessed “several Australian government websites and services” during an internal evaluation. “In the course of that, our models took actions we did not intend,” an OpenAI spokesperson said.
AI bots do not have a human-like notion of intention and can therefore go to extreme lengths where a person would understand that hacking a government website was not a reasonable way of conducting research.
That misinterpretation of instructions can be a result of poor training, supervision or bots colluding with each other in ways that their owners did not intend or foresee. The ABC has reported that OpenAI agents had discussed how to access Australian government information on a German coding website called DSEWiki.
What information was accessed?
The protected data that the agent gained access to contained “aggregated medical statistics”, Marles said. “No individuals’ medical data was accessed here,” he said. The government said work was already under way before the breach to transfer the Medicare data to a more modern system.
However, the government has launched a forensic investigation into the breach to determine its full extent along with the spy intelligence agency the Australian Signals Directorate. That’s part of a taskforce established to examine the breach and determine whether existing processed are adequate for responding to AI-related cyber incidents.
Was it legal?
The government is also trying to determine if the matter should be referred to the Australian Federal Police.
“This is an unintended access – that’s clear – but [it] definitely does raise questions about whether the law has been broken,” Marles said.
Dr Rob Nicholls, a senior research associate at the University of Sydney’s Centre for AI, Trust and Governance, said that despite the difficulty in assessing whether various actions the agent took were against the law, broader legal principles still applied.
“What would it be like in real life if you broke into a government office, unlocked a filing cabinet and picked out a document that said “protected” or “classified” and took it away? That’s almost certainly an offence,” he said.
From a legal responsibility perspective, Nicholls said anyone using an agent was ultimately responsible for the reality that “AI agents do precisely what you tell them, even if it’s not in the way you expect”.
“They might be called AI agents, but they are not agents or principals under law, it is the person or organisation who set the agent running.
“The excuse that ‘my robot made me do it’ is not a valid defence. It’s the same as in other fields, if you were reversing your car and you accidentally clipped a parked bike, you can’t just say I didn’t intend to do that. You hit it – you are responsible.“
To read the full article click here.