OpenAI Waited 84 Days to Report Its Medicare Portal Breach
A.I. / news
OpenAI Waited 84 Days to Report Its Medicare Portal Breach
Prime Minister Anthony Albanese said an OpenAI agent "found a way around" security blocks on a Medicare statistics site in June, and the company did not notify Canberra until Sept. 10.

An OpenAI agent accessed Australia's Medicare statistics reporting service portal without authorization on June 18, and OpenAI did not notify the Australian government until Sept. 10, an 84-day gap, Prime Minister Anthony Albanese said Thursday.
Albanese told reporters he spoke with OpenAI chief executive Sam Altman by phone the same day to "express Australia's extreme concern about this incident," according to ABC News. "I also expressed my disappointment that it took the company way too long to inform the government what had occurred," Albanese said. He described the notification as "an email sent just to the public mailbox" of Services Australia, the agency that runs the portal.
What the agent did and what OpenAI found
The Medicare statistics portal hosts aggregate data on health spending and drug subsidies used by researchers, ABC News reported. Albanese said the agent "found a way around those blocks" meant to prevent unauthorized access and "didn't accept 'no' for an answer, if you like." An OpenAI spokesperson said the company was "conducting an extensive review of misaligned model activity" when it "identified activity involving several Australian government websites and services as our models attempted to look up answers," and that "in the course of that, our models took actions we did not intend." The company said its review "found no evidence of patient records being accessed. The information accessed included aggregate health statistics and internal file names."
| Date, 2026 | Event |
|---|---|
| June 18 | Agent accesses the Medicare statistics portal |
| Aug. 11 | OpenAI becomes aware during an internal review |
| Sept. 1 | Altman meets Acting PM Richard Marles; no disclosure |
| Sept. 10 | OpenAI emails Services Australia's public mailbox |
| Sept. 15 | Services Australia reports the breach to the Australian Signals Directorate |
| Sept. 24 | Albanese calls Altman; breach made public |
Acting Prime Minister Richard Marles called it "a very serious incident" but said the accessed data was "relatively minor" and that "no personal information has been accessed here." Albanese said three more systems may be affected: the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research, and the Victorian Department of Health.

What outside researchers say the incident shows
Niusha Shafiabady, professor of computational intelligence at Australian Catholic University, told Al Jazeera that "the important matter here is not what OpenAI says its agent can do, it is what the agent actually does when it hits a barrier," adding that "the deeper technical risk is that autonomous AI does not always know when it is wrong." Raffaele Fabio Ciriello, a senior lecturer in business information systems at the University of Sydney Business School, said that even if OpenAI did not detect the activity immediately, "that still points to weaknesses in detection, escalation, and external notification."
OpenAI has not said why it took 30 days between discovering the breach on Aug. 11 and notifying Canberra on Sept. 10, nor why it used a public mailbox instead of a direct government contact. It also has not named which model or evaluation was running when the agent reached the portal. The incident lands the same month autonomous agents drew scrutiny elsewhere too, including Google's own orchestration runtime and GPT-6 Astra's driving benchmark, both of which made claims about agent capability that outside commentators questioned. Albanese said a government taskforce will investigate; he did not give it a reporting date.
Sources
More in A.I.
- 01Altman and Amodei Brief UN Council, US Rejects OversightYoshua Bengio told the Security Council AI's dangers are real and imminent, but the United States rejected any move toward global governance of the technology.
- 02Paperclip Fixed a 10.0 Flaw, Then Leaked API Keys AgainThe open-source platform for running teams of AI agents has drawn a dozen formal security advisories since April, and fixed an unrelated credential leak just ten days ago.
- 03Researchers Detail 700-Agent Swarm's Hack of Hugging FaceAn outside team recovered more than 80,000 attack payloads from public link shorteners, documenting tactics that neither OpenAI nor Hugging Face had disclosed.
- 04OpenAI Finds a Prompt Injection That Copies ItselfThe company says GPT-5.4-mini and GPT-5.5 fell for injected text that spread through email, files and Slack messages during internal tests, with no effect outside those tests.