Australia’s prime minister, Anthony Albanese, has ordered an urgent investigation into how an OpenAI artificial intelligence agent gained unauthorised access to a Medicare website, after the company waited almost three months to notify the government.
The incident occurred on June 18, when an OpenAI research team used an internal model to conduct internet-based research into medicines. The agent encountered repeated blocks while trying to obtain information from the Medicare Statistics Reporting Service portal, but found a way around them.
It went on to access public and non-public files and write files to an internal server, according to Services Australia. Three other systems may also have been affected: the Australian Institute of Health and Welfare, the NSW Bureau of Crime Statistics and Research, and Victoria’s Department of Health.
OpenAI discovered the breach in August and carried out an internal investigation. However, Services Australia was not informed until September 10, when the company sent an email to a public inbox.
The message was referred to the Australian Cyber Security Centre five days later. Albanese was briefed last weekend, after Public Services Minister Katy Gallagher had been informed.
“This situation is obviously unacceptable,” Albanese told reporters in New York. He said he had spoken to OpenAI chief executive Sam Altman to convey Australia’s “extreme concern” and his disappointment that the company had taken too long to report the incident.
“The nature of the way that that notification occurred as well was unacceptable,” the prime minister said.
Investigation into Medicare website breach
The government’s taskforce will include the National Cyber Security Coordinator, the Office of AI, the Australian Signals Directorate, the Australian AI Safety Institute and Services Australia.
It will assess whether existing procedures are adequate for responding to cyber incidents involving AI, and examine possible law enforcement and legislative action, including whether penalties could apply to OpenAI.
The matter will also be referred to Parliament’s Joint Select Committee on Artificial Intelligence. The government is seeking urgent advice on whether offences may have been committed and whether the incident should be referred to the Australian Federal Police.
Albanese said there was currently no evidence that personal information had been accessed or that the wider Services Australia network had been compromised. A forensic investigation is under way with assistance from the Australian Signals Directorate.
OpenAI said it was conducting an “extensive review of misaligned model activity during training and evaluation” and notifying third parties about potential breaches. It said its models had accessed several Australian government websites and services while seeking answers and statistics about Australia.
“In the course of that, our models took actions we did not intend,” an OpenAI spokesperson said.
The company said its review had found no evidence that patient records were accessed. It said the information obtained included aggregate health statistics and internal file names, but did not identify the other government websites and services involved.
Opposition Leader Angus Taylor questioned the timing of the announcement and called for the government to explain when it first became aware of the breach, what information had been accessed and what vulnerability had been exploited.
The incident comes after Albanese joined 21 other countries in backing a statement at the United Nations General Assembly calling for urgent regulation and safeguards for artificial intelligence. He has declined to say whether he discussed the breach with US President Donald Trump during a conversation on Wednesday.
