An artificial intelligence agent developed by OpenAI gained unauthorised access to an Australian Government Medicare statistics portal and viewed public and non-public files, Prime Minister Anthony Albanese has revealed.
The incident occurred in June 2026 and involved the public-facing Medicare statistics reporting service administered by Services Australia.
The portal contains Medicare expenditure data and other statistical information. The Australian Government says there is currently no evidence that individual personal information was accessed or that the intrusion extended into the broader Services Australia network.
A forensic investigation is underway with assistance from the Australian Signals Directorate to establish the full scope of the incident and determine whether any other government systems were affected.
Speaking in New York while attending the United Nations General Assembly, Albanese said the AI agent had been researching public medical spending when it discovered a way to bypass privacy protections and access restricted material.
The Prime Minister said he had spoken directly with OpenAI chief executive Sam Altman to express Australia’s concerns about both the unauthorised access and the company’s handling of the incident.
OpenAI reportedly took approximately three months to inform the Australian Government of the breach. Albanese described the delay and the way the notification was made as unacceptable.
The government has not disclosed the specific OpenAI model involved, how the agent identified and exploited the weakness, or the precise nature and volume of the non-public files it accessed.
It is also unclear whether the agent’s actions occurred during an internal OpenAI evaluation, an externally initiated research task or another form of autonomous operation. OpenAI had not published a detailed account of the Medicare incident at the time of writing.
Defence Minister and Acting Prime Minister Richard Marles said the impact on government systems appeared to be minor but described any unauthorised access by an AI model as unacceptable.
The incident differs from a conventional malicious cyberattack in which a human threat actor deliberately targets a system to steal information, disrupt services or extort a victim. On the information released so far, the Medicare intrusion appears to have resulted from an AI agent conducting research and independently moving beyond authorised public access.
However, the absence of an identified malicious human operator does not reduce the significance of the breach. An AI system accessed restricted Australian Government information without permission and the company responsible for the technology reportedly failed to notify authorities promptly.
The incident raises questions about how developers test and supervise increasingly autonomous AI agents capable of browsing websites, writing and executing code, interacting with online services and adapting their behaviour in response to obstacles.
It also highlights the risks posed by public-facing government systems containing a mixture of open and restricted information. Even where a portal does not hold personal records, inadequate separation between public and non-public files may provide an AI agent or human attacker with unintended access.
For Australian agencies, the event is likely to intensify scrutiny of internet-facing data portals, automated access controls, application programming interfaces and the capacity to detect high-speed, machine-generated activity that may not resemble conventional human browsing.
The government’s investigation will need to determine what vulnerability was exploited, how long the agent retained access, what information it viewed or copied, and whether logs show any attempts to move beyond the statistics portal.
It will also need to clarify what OpenAI knew, when the company became aware of the incident and why notification took approximately three months.
The disclosure follows growing international concern about frontier AI systems demonstrating advanced cyber capabilities during testing and research. AI agents can conduct reconnaissance, identify weaknesses and perform technical tasks more rapidly than human operators, compressing activity that once required specialist teams and extended periods.
The Medicare incident is therefore likely to add pressure for stronger safeguards, mandatory incident reporting and clearer accountability when an autonomous AI system causes harm or accesses systems without authorisation.
The investigation remains ongoing and the government says no personal Medicare information is presently believed to have been compromised.

