An OpenAI agent gained unauthorised access to an Australian government Medicare statistics portal on 18 June, reaching public and non-public files and reportedly writing files to an internal server. Services Australia was not notified until 10 September, 84 days later, prompting Prime Minister Anthony Albanese to raise his “extreme concern” directly with OpenAI Chief Executive Officer Sam Altman.
The standalone service contains aggregate Medicare and Pharmaceutical Benefits Scheme statistics used by researchers. It does not handle claims, payments or individual records. OpenAI found no evidence that patient records were accessed, while a government forensic investigation remains underway.
What the Agent Did on 18 June
The agent was completing an internal OpenAI evaluation involving internet research into public medicine spending. Australian officials said the system requested information, was denied and then found a way around controls protecting the public-facing portal. It accessed non-public aggregate health statistics and internal file names alongside public material.
Reports that the agent wrote files to an internal Services Australia server remain under investigation. Government Services Minister Katy Gallagher confirmed that Services Australia had requested more information from OpenAI about the writing activity. The files’ contents and purpose have not been disclosed.
Richard Marles, Acting Prime Minister of Australia, said the incident’s impact appeared minor because no personal medical information was accessed and there was no evidence of a broader compromise. He nevertheless called the unauthorised entry “a very serious incident” because the model took the action without being instructed to hack the portal.
OpenAI Says Its Models Took Unintended Actions
An OpenAI spokesperson said the company found the activity while reviewing misaligned model behaviour during training. The models had been looking for answers and statistics on several Australian government websites as part of an internal evaluation.
OpenAI said: “In the course of that, our models took actions we did not intend.” The company added that its review found no evidence of access to patient records and said the material involved aggregate health statistics and internal file names.
The model, instructions, tools and technical route into the portal have not been disclosed. An agent cannot write to an external server through text generation alone. It needs network access and tools that turn instructions into actions.
The Government Was Told 84 Days After the Access
The incident occurred on 18 June. OpenAI discovered it during a review on 11 August and emailed Services Australia’s public vulnerability-disclosure inbox on 10 September. Services Australia read the message the following day and informed the Australian Signals Directorate on 15 September. Its first technical exchange with OpenAI took place on 22 September.
Australia learned about the access nearly three months after it happened, while about one month elapsed between OpenAI discovering it and notifying Australia. Albanese criticised both the delay and the use of a general email inbox.
Albanese said he spoke with Altman to convey Australia’s “extreme concern” and disappointment. The government has established a task force led by the Department of the Prime Minister and Cabinet, with the Australian Signals Directorate and AI Safety Institute involved. It will examine the incident, government network security and whether current laws cover unauthorised actions by AI agents.
Financial Firms Are Giving Agents the Same Kind of Reach
Financial firms are connecting agents to systems that can configure KYC rules, reconcile payments and trades, or place transactions. FinanceFeeds has covered Sumsub allowing agents to build compliance workflows from AML policies and Duco introducing agentic post-trade operations.
Crypto platforms are going further. Binance lets agents trade through restricted subaccounts, while MoonPay allows ChatGPT and Claude to prepare Kamino lending and borrowing transactions. Those designs rely on permission boundaries, signing controls and audit records preventing an agent from turning a permitted objective into an unauthorised action.
A regulated firm needs to know which tool an agent called, what data it accessed, what it wrote, which control denied it and whether it tried another route. Systems such as smartTrade’s governed AI for trading and payments are being sold around that separation between assistance and authority.
Agent Incidents Need a Reporting Clock
OpenAI published a voluntary misalignment-reporting framework on 16 September, six days after notifying Services Australia. It says qualifying behaviour can be disclosed before an investigation is complete and that serious safety or security incidents should be shared with the US government. OpenAI is developing proposed reporting mechanisms with regulators, researchers and standards bodies.
The OECD has already proposed a 29-criterion common framework for AI incident reports, while the US National Institute of Standards and Technology is developing guidance on AI incident management. Neither creates a universal mandatory deadline for notifying an affected organisation.
A workable obligation would start when the developer or deployer has credible evidence that an agent crossed an authorisation boundary. The first notice should identify the affected system, time window, data and actions, model and tool configuration, containment steps and any retained credentials. Technical findings could follow without postponing the initial warning.
Researchers cited by ABC described the wider activity as the first reported instance of autonomous agents hacking a government. That is narrower than calling it the first AI hack, and related agent incidents involving companies had already been reported. What makes the Medicare case different is the combination of unauthorised government access, write capability and a disclosure gap now documented by a national government.
