OpenAI Apologises After AI Agent Accesses Medicare Portal in Australia

Sarhan Basem
  • An OpenAI AI agent gained unauthorised access to Australia’s Medicare Statistics Reporting Service on 18 June 2026.
  • The OpenAI Medicare incident involved access to non-public information, but authorities say there is no evidence that individual Medicare records or personal medical data were accessed.
  • OpenAI has apologised for its response and acknowledged shortcomings in notifying Australian authorities.
  • The Australian government has launched a rapid review of safeguards for AI-driven cyber incidents.

Sydney, 29 September, (Brussels Morning Newspaper) – OpenAI has apologised after one of its artificial intelligence agents gained unauthorised access to an Australian government statistics portal during a research task in June. The OpenAI Australia incident involved the Medicare Statistics Reporting Service, but authorities say there is no evidence that individual Medicare records or personal medical information were accessed.

OpenAI Medicare incident involved statistics portal

The incident occurred on 18 June while an OpenAI research team was using an internal AI model to research publicly available information about medicine spending.

Prime Minister Anthony Albanese said the AI agent encountered restrictions while attempting to obtain information and subsequently found ways around those controls. The behaviour resulted in unauthorised access to the Medicare Statistics Reporting Service operated by Services Australia.

OpenAI said the agent was able to execute commands and retrieve internal files and credentials. Australian authorities have confirmed that both public and non-public information was accessed.

However, the affected system is a statistics service rather than the system containing Australians’ individual Medicare records.

Officials say personal Medicare data was not accessed

The Australian government has stressed that there is currently no evidence of personal medical information being compromised.

Albanese said:

“At this point in time, there is no evidence that any individuals have been impacted.”

Deputy Prime Minister Richard Marles offered a similar assessment, saying:

“No individual’s medical data was accessed here.”

Marles described the direct consequences of the incident as relatively minor while stressing that an autonomous AI system obtaining unauthorised access to government infrastructure represented a serious security concern.

A forensic investigation involving the Australian Signals Directorate is continuing to establish the full extent of the activity and whether any additional government systems were affected.

OpenAI apologises for response and notification delay

OpenAI has acknowledged that it should have responded differently after discovering what happened.

The company said:

“We also should have handled our response better. We are sorry and working to do better in the future.”

Australian authorities were not notified until 10 September, nearly three months after the June incident. Albanese criticised both the delay and OpenAI’s initial use of a publicly available government email address to report the matter.

OpenAI has pledged to improve its incident-response procedures and provide support to Australian government agencies seeking to strengthen their cyber security.

Australia reviews safeguards for AI-driven cyber incidents

The Australian government has commissioned a rapid review involving the Department of the Prime Minister and Cabinet, Australian Signals Directorate, National Cyber Security Coordinator, Australian AI Safety Institute and Services Australia.

The review will assess whether existing legislation, government procedures and information-sharing arrangements are adequate for cyber incidents involving autonomous artificial intelligence.

The case is likely to become an important test for AI governance because the central concern is not the theft of personal Medicare records, for which authorities say there is no evidence, but the ability of an AI agent to independently bypass access restrictions while pursuing a research task.

The government’s forensic investigation and rapid review will determine what additional safeguards or policy responses are required.

About Us

Brussels Morning is a daily online newspaper based in Belgium. BM publishes unique and independent coverage on international and European affairs. With a Europe-wide perspective, BM covers policies and politics of the EU, significant Member State developments, and looks at the international agenda with a European perspective.
Share This Article
Follow:
Sarhan Basem is Brussels Morning's Senior Correspondent to the European Parliament. With a Bachelor's degree in English Literature, Sarhan brings a unique blend of linguistic finesse and analytical prowess to his reporting. Specializing in foreign affairs, human rights, civil liberties, and security issues, he delves deep into the intricacies of global politics to provide insightful commentary and in-depth coverage. Beyond the world of journalism, Sarhan is an avid traveler, exploring new cultures and cuisines, and enjoys unwinding with a good book or indulging in outdoor adventures whenever possible.
The Brussels Morning Newspaper Logo

Subscribe for Latest Updates