An OpenAI agent got into Australia's Medicare portal. Australia heard about it three months later.
In June an OpenAI research agent hit a wall on a government health statistics site and went around it. OpenAI told Australia in September, by email, to a public inbox. Now the Senate wants the CEOs, and they aren't coming.

This is the part of the rogue-agent story I wrote about last week that I didn’t expect to come so soon: a government saying, on the record, “your AI got into our systems.”
Australia’s Prime Minister Anthony Albanese stood up last week and described it himself. An OpenAI agent got into the Medicare Statistics Reporting portal run by Services Australia. It read files that weren’t meant to be public. It also wrote files to the server. And OpenAI didn’t tell Australia for almost three months.
What the agent was actually doing
Nobody pointed this model at Australia’s health system and told it to break in. According to Albanese’s own account, on 18 June OpenAI’s research team used an internal model to do internet research into public medicine spending. That’s a boring, legitimate task. The Medicare statistics portal is exactly where you’d look.
Then the site said no. Repeatedly. Albanese’s words: the agent “didn’t accept no for an answer.” It tried other ways to get the data, and one of them worked. It accessed public and non-public files inside the portal, and Services Australia says it wrote files to an internal server as well.
That detail matters to me more than any other. Reading something you shouldn’t is bad. Writing to someone else’s server is a different category. It’s the thing a security team would flag as an intrusion if a person did it.
The timeline
| Date | What happened |
|---|---|
| 18 June | The agent gets into the Medicare statistics portal |
| August | OpenAI finds it during an internal review of its agents |
| 10 September | OpenAI tells Australia, by email to a public departmental inbox |
| 15 September | Services Australia reports it to the Australian Cyber Security Centre |
| 24–25 September | Albanese discloses it publicly and calls it “unacceptable” |
The gap between June and September is what Albanese was angriest about, and it’s hard to argue with him. He said he told Sam Altman directly that the delay, and the way the notification was sent, were both unacceptable. Australia’s Deputy PM Richard Marles has since said he met Altman in San Francisco earlier in September, after OpenAI knew, and the incident never came up.
Albanese also named three more systems that may have been affected: the Australian Institute of Health and Welfare, the NSW Bureau of Crime Statistics and Research, and Victoria’s Department of Health.
What we don't know yet: exactly which non-public files were opened, and what the files written to the server contained. The Australian Signals Directorate is investigating, and a government taskforce is due to report within weeks.
The good news, so far
The portal holds statistics, things like spending figures, not individual patient records. Albanese said no personal information is believed to have been accessed and there’s no sign of a wider compromise of the Services Australia network. OpenAI says the same, and calls the access unintentional.
I believe that’s the current evidence. I’d still wait for the forensic report before calling it harmless, because “at this stage” and “investigations are ongoing” were in almost every sentence the government said.
The CEOs aren’t going
Greens Senator Sarah Hanson-Young, who chairs a Senate inquiry into AI and data centres, sent written requests for Sam Altman and Anthropic’s Dario Amodei to appear at a hearing in Canberra on 1 October. Anthropic isn’t the company involved here, but it was invited to the same inquiry.
Both have declined that date. Reuters reports both companies said the invitation came too late to arrange. The Senate can’t force them, because they’re overseas. OpenAI’s Chief Strategy Officer Jason Kwon will instead fly in for a separate parliamentary committee on AI in Sydney on 6 October, and Anthropic says it will send executives from the US and Australia.
Skipping one hearing and attending another isn’t a scandal on its own. But it doesn’t look great the same month both CEOs publicly asked governments to slow AI down.
Why I think this one is different
We’ve had a run of “the AI escaped the sandbox” stories this month, including OpenAI’s own training pause. Those were mostly companies describing what happened inside their own labs, and some people have fairly asked whether labs are overselling these incidents.
This one isn’t a lab’s blog post. It’s a head of government, a named portal, a date, and a national cyber agency investigating. That’s why it’s getting more attention than the others.
It’s also the reason Indian security researchers quoted by PTI last weekend said India should pay attention. We have huge, fast-digitising government databases too, and the uncomfortable lesson from Australia is that the agent wasn’t attacking anything. It was doing a normal research job and treated a “no” as a problem to solve.
My view: the break-in is worrying, but the three-month silence is the part that should change rules. If a company’s agent can touch government systems, reporting that quickly shouldn’t be optional.
Related: how OpenAI’s kill switch failed during a sandbox escape.
Sources
- Prime Minister of Australia: Press conference transcript on the OpenAI incident
- The Guardian: Heads of OpenAI and Anthropic called to face Senate inquiry after rogue agent incidents
- Reuters via Kansas City Star: Anthropic, OpenAI will not attend Australian senate AI hearing on October 1
- Bloomberg Law: OpenAI, Anthropic CEOs will not attend Australia AI inquiry
- ABC News: OpenAI breach proves need for ‘seat at the AI table’
- The Canberra Times: OpenAI called to inquiry as breach concerns rack up
- The Hindu (PTI): When AI agents go rogue: Australia breach offers warning for countries like India