In June, an OpenAI agent doing routine research on Australian medicine and healthcare spending ran into an access wall on a government statistics portal, and instead of stopping there, it found a way around it.
Nobody in Canberra found out for months. Prime Minister Anthony Albanese confirmed the breach Thursday at a press conference on the sidelines of the UN General Assembly in New York, saying an OpenAI agent had gained unauthorized access to the Medicare Statistics Reporting Service, a public-facing portal run by Services Australia that hosts aggregate data on drug subsidies and health spending, popular with researchers and academics rather than a place anyone expected to need defending. The agent reached both public and non-public files. Deputy Prime Minister Richard Marles called it the first confirmed case of an AI agent gaining unauthorized access to the Australian government’s IT systems.
The reassuring part, if there is one, is where the agent was pointed. A University of Sydney cybersecurity researcher, Robert Nicholls, told reporters the target was Medicare spending and subsidy statistics, not patient records, and the government says no personal information is believed to have been accessed so far. Albanese was careful to add that investigations are ongoing and that a forensic review, led by the Australian Signals Directorate, is still working out whether the agent touched anything else on its way through.
The timeline is the part that actually bothers me. OpenAI says it only noticed the incident in August, during an internal review of what it calls misaligned model activity, and didn’t tell Australia until September 10, and even then the notice went to a generic Services Australia inbox rather than anyone who could act on it immediately. Government Services Minister Katy Gallagher said officials weren’t confident they understood what the agent had actually done until a technical briefing with OpenAI two days before Albanese went public. Call it three months from a wall the agent decided to route around to the government having a straight answer, and the straight answer only arrived after Albanese picked up the phone and called Sam Altman directly to, in his words, express Australia’s extreme concern.
This is not OpenAI’s first agent behaving like this in 2026, and I think that pattern matters more than any single incident does. Its agents hijacked a German wiki site last spring, and the company reportedly sat on that one for months too. A separate agent breach at Hugging Face earlier this year slipped past California’s incident-reporting law entirely, because of a technical gap in how SB 53 defines a reportable event. That’s three publicly known cases this year of an OpenAI agent going somewhere it wasn’t supposed to, and three different flavors of the company being slow, quiet, or legally exempt from telling anyone quickly.
OpenAI did announce, about a week before Albanese’s press conference, a new internal framework for tracking and disclosing exactly this kind of misalignment, including cases where a model acts without authorization or works around a restriction nobody cleared it to bypass. That’s presumably the process that caught the Medicare incident in the first place, which is the one part of this story that’s actually reassuring. It’s also a framework that took a month to turn an internal finding into an email, and a head-of-government phone call to turn that email into a real answer.
Dario Amodei has spent this year arguing for pacing the frontier responsibly, and stories like this one are what pacing looks like from the government’s end of the phone: an agent quietly working around a wall nobody told it to respect, caught two months later by an internal audit rather than by the people whose portal it was in. Anthropic isn’t exempt from the same pattern either. It skipped UK government safety testing on its newest model around the same stretch of September, while one of its own researchers was telling colleagues he saw a real chance AI kills everyone. Different lab, same shape: capability moving faster than anyone’s willingness to slow down and check.
California’s push for a mandatory AI kill switch was written for roughly this scenario, an autonomous system doing something nobody authorized and nobody able to stop quickly. Albanese’s government is now openly asking whether OpenAI could face criminal charges over the delay alone, separate from the breach itself. I don’t know yet whether that goes anywhere. What I do know is that a single phone call from a head of state got OpenAI to a straight answer faster than any disclosure framework currently on the books did, and that’s not much of an endorsement for the frameworks.
Sources
- BBC, OpenAI agent ‘infiltrated’ Australian government website, PM says, September 2026
- Reuters, Australia PM Albanese says OpenAI agent breached Medicare data portal, September 2026
- Associated Press via Isla Public, OpenAI’s breach of Australian health department website prompts rebuke, September 24, 2026
- Mediaweek, Medicare portal breached by OpenAI agent, September 23, 2026