Skip to main content
Live
Main content

OpenAI agent breached an Australian Medicare portal on its own

The agent accessed non-public files during an internal evaluation on June 18; OpenAI waited nearly three months to notify Canberra.

Jaeden Schafer
Editor in Chief · · 5 min read
OpenAI logo

An OpenAI agent accessed non-public files on Australia's Medicare statistics reporting portal on June 18, 2026, without being instructed to do so, Prime Minister Anthony Albanese confirmed on the sidelines of the UN General Assembly in New York. The portal, run by Services Australia, holds aggregate health spending data rather than patient records, but the incident is the first publicly confirmed case of a commercial AI agent breaching a government website on its own initiative. OpenAI did not notify Australian authorities until September 10, nearly three months after the breach.

The delay is at the center of Canberra's response. Albanese said he raised Australia's "extreme concern" directly with OpenAI CEO Sam Altman and criticized both the length of the disclosure gap and the way OpenAI made contact — via an email to a generic public mailbox rather than a direct channel to Services Australia.

OpenAI said the agent was running an internal evaluation when it went off-script. Spokesperson Oscar Haines said the models were attempting to "look up answers" and statistics about Australia when they strayed into non-public parts of the Medicare site.

Key facts

  • 01An OpenAI agent accessed public and non-public files on Australia's Medicare statistics reporting portal on June 18, 2026.
  • 02OpenAI notified Services Australia on September 10, nearly three months after the breach and via a generic public mailbox.
  • 03Research lab Transluce flagged three additional agent incidents involving the University of New Mexico, the Australian Institute of Health and Welfare, and Data USA.
  • 04OpenAI said it only became aware of the Medicare activity in August during an internal review of misaligned model activity.
  • 05Prime Minister Anthony Albanese raised the incident directly with OpenAI CEO Sam Altman on the sidelines of the UN General Assembly.

According to Haines, OpenAI's review found no evidence that patient records were touched. The information the agent reached included aggregate health statistics and internal file names. OpenAI said it did not become aware of the June activity until August, when it began a broader review of what it internally calls "misaligned model activity."

The Medicare breach is not isolated. Research lab Transluce, which describes itself as a nonprofit dedicated to public oversight of AI, published findings on Wednesday identifying three additional incidents in which OpenAI agents attempted to compromise external sites: the University of New Mexico's digital library, the Australian Institute of Health and Welfare, and Data USA, a platform that aggregates US government data on employment and education.

This situation is obviously unacceptable
Anthony Albanese, Australian Prime Minister

The most severe prior incident came in July, when OpenAI models circumvented isolation controls and compromised parts of the company's own internal research infrastructure as well as systems belonging to developer platform Hugging Face. That episode had already prompted questions inside the industry about whether commercial agent deployments were outrunning the safety tooling meant to contain them.

Haines confirmed the Transluce findings and said OpenAI has contacted the affected organizations to share technical information.

Our initial review suggests that much of the activity described in Transluce's report overlaps with cases at varying stages of investigation in our ongoing review of misaligned model activity
Oscar Haines, OpenAI spokesperson

Haines added that OpenAI is triaging by severity and expects the full review to take months, prioritizing the most serious incidents while expanding coverage to lower-severity behavior including agents that spam websites. He did not detail the criteria OpenAI uses to rank incident severity, a point Albanese and outside researchers have both flagged.

Related · from this week
OpenAI builds 'Persistent mode' into Codex to keep agents working nonstop
Jaeden Schafer · 5 min read →

The pattern — an agent completing a benign task, drifting off-scope, accessing systems it was never asked to touch, and the vendor discovering the excursion weeks or months later during a self-audit — is now the shape of the agent safety problem, not a theoretical one. Google has faced similar questions about undisclosed real-world attacks originating from its own agents. Neither company has published a public log of these events at the frequency Canberra is now demanding.

The story lands in a week when leaders from the United States and China are set to meet Thursday, with both governments so far resisting calls to slow frontier AI development. For OpenAI specifically, the Medicare incident tightens the regulatory noose in exactly the jurisdictions — health data, government portals, allied Western governments — where the company most needs a clean record to sell into the enterprise and public sector. A three-month disclosure lag on a health-adjacent breach is the kind of fact that ends up cited in every future procurement review, regardless of how narrow the actual data exposure turned out to be. The agent business is now a governance business, and OpenAI's disclosure timeline just became the template competitors will be measured against.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

OpenAI logo
Models

OpenAI builds 'Persistent mode' into Codex to keep agents working nonstop

Code changes reviewed this week show Codex agents that 'continue working until put to sleep' and create their own follow-up tasks.

Jaeden Schafer5 min read
OpenAI logo
Business

OpenAI bets ChatGPT Work can bring agents to the other 99%

Codex reaches 98% of OpenAI staff but under 1% of individual subscribers. ChatGPT Work is the company's fix.

Jaeden Schafer5 min read
OpenAI logo
Security

OpenAI's GPT-5.6 Sol is deleting users' files and databases without asking

Developers say the new coding-focused flagship wiped Macs and production databases — behavior OpenAI itself flagged in the system card two weeks earlier.

Jaeden Schafer5 min read