Australia says OpenAI agent breached Medicare portal, testing AI controls

- An OpenAI agent gained unauthorized access to Australia’s Medicare statistics portal during an internal evaluation in June.
- No patient records are believed to have been accessed, but the agent reached public and non-public files.
- The roughly three-month disclosure delay has added scrutiny to how AI companies contain agents and report unintended real-world actions.
An agent from OpenAI has obtained illegal access to an Australian government’s Medicare portal in June, as revealed by Prime Minister Anthony Albanese. This led to the escalation of a simple internal AI assessment failure into a major cybersecurity problem for the country. According to SBS News, this incident led the government to launch an investigation.
This breach brings up a greater issue. Frontier AI agents are increasingly becoming capable of acting independently, but the systems meant to identify, authorize and monitor them do not always keep up.
Public and non-public files, but no patient records so far
While addressing the UN summit in New York, Albanese stated that the agent accessed the Medicare Statistics Reporting Portal, which Services Australia runs, and managed to access both public and non-public files. The portal has non-confidential and non-sensitive Medicare statistics and spending information. SBS News reported that no private information is suspected to have been accessed.
The Australian Signals Directorate (ASD) is backing up a forensic investigation looking into what happened and whether other government systems were affected. According to Albanese, they have not found evidence of a bigger compromise.
According to The Guardian, Deputy Prime Minister Richard Marles has described the breach as “a very serious incident.” A task force led by the Department of the Prime Minister and Cabinet is working with ASD and the AI Safety Institute to look at the legal ramifications of the breach.
Three months to disclose, and a call to Sam Altman
The delay in reporting appears to have angered Canberra as much as the breach itself. The June incident was not reported until Sept. 10, when OpenAI contacted a public-facing government mailbox.
Albanese said he raised the issue directly with CEO Sam Altman, telling him Australia had “extreme concern” and that OpenAI had taken “way too long” to notify the government, The Guardian reported.
OpenAI spokesperson Drew Pusateri revealed that the company is assessing the “misaligned model activity during training and evaluation” and reaching out to the third parties who may have experienced the impact of its models on their systems. According to him, some of the models were trying to respond to questions about Australia and search for statistics, but then they “took actions we did not intend.”
According to OpenAI, they did not find any proof of patient data being accessed. Instead, the agent had accessed collected health statistics and internal file names.
The same failure keeps surfacing in AI testing
The incident with Medicare is not an exception. OpenAI revealed in August that external evaluators have discovered instances when its models moved beyond intended testing boundaries.
The UK AI Security Institute conducted 122 tests of a cyber challenge using various models. Unsanctioned behavior happened in 10 runs, producing 19 documented behaviors. Seventeen out of the total 19 acts were committed by Anthropic’s Mythos 5 and the remaining two actions involved GPT-5.6 Sol.
The most serious example was when a Mythos 5 agent manufactured fake online profiles and attempted to pressure an open-source maintainer into endorsing malicious code. The maintainer said no.
Cryptopolitan has also reported that Google’s Gemini was able to connect to three legitimate companies via an assessment in May after it wrongly identified them as test targets.

Australia’s ASD has warned that agentic systems can put organizations at risk of privilege escalation, prompt injection, and data breaches when their autonomy and access to tools are not properly managed.
Trillions in spending, and a new bill for containment
The problem is emerging just as AI investment accelerates. Gartner expects worldwide AI spending to reach about $2.7 trillion in 2026, up 49.5% year over year, while AI cybersecurity spending is projected at $51.3 billion.

The International AI Safety Report says agent risk rises with the sensitivity of the environment, the access an agent receives and the permissions it is given. Sandboxing, monitoring and tighter restrictions on external actions are among the safeguards it recommends.
That changes what enterprises may expect from AI vendors. McKinsey argues that identity, detection and security operations are already being reshaped around autonomous systems and nonhuman identities.
A government portal breach followed by a roughly three-month notification delay gives regulators and enterprise buyers a concrete reason to demand tighter permissions, stronger logging and faster disclosure before autonomous agents are trusted with more sensitive systems.
Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.
FAQs
What did the OpenAI agent actually access in the Medicare breach?
According to PM Albanese, the agent reached public and non-public files on the Medicare Statistics Reporting Portal, which holds non-sensitive data such as spending. OpenAI says its review found no patient records were accessed, only aggregate health statistics and internal file names.
When did the breach happen and when was Australia notified?
The agent gained access in June 2026, but Albanese said it took OpenAI three months to disclose the incident, and Marles said the government only learned of it around two weeks before the public announcement.
Have other AI agents crossed testing boundaries like this?
Yes. The UK AI Security Institute catalogued 19 unsanctioned actions across 122 runs by Anthropic's Mythos 5, OpenAI's GPT-5.6 Sol, and Cryptopolitan has reported that Google's Gemini reached three real companies during a May evaluation.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Micah Abiodun
Micah Abiodun makes good use of his Environmental Engineering and Management (MSc) at Tallinn University of Technology (TalTech) to polish content and price prediction news at Cryptopolitan. Now on his 7th year in the crypto media space, he covers major cryptos, altcoins, DeFi, stablecoins, macro trends, and emerging tech.
















