The Australian Government has launched a multi-agency review after Prime Minister Albanese disclosed in New York yesterday that an OpenAI artificial intelligence model interacted with four government websites, including an unauthorised intrusion into a Medicare statistics portal.
Acting Prime Minister Richard Marles said the AI model contacted websites operated by the Australian Institute of Health and Welfare, the Victorian Department of Health, the NSW Bureau of Crime Statistics and Research, and Services Australia.
The government said the activity involving the first three websites was consistent with normal access to publicly available information. At this stage, the Medicare Statistics Reporting Service is the only website where unauthorised access has been confirmed.
The incident occurred on 18 June while OpenAI was conducting an internal assessment of its technology. The AI agent was reportedly tasked with researching publicly available information about Australian government spending on medicines.
After being unable to obtain the requested information through the Medicare statistics portal’s normal interface, the agent allegedly identified and exploited a weakness in the website. It then accessed files stored on the underlying server, including information that was not publicly available at the time.
The compromised portal contained aggregated statistics covering areas such as bulk billing, immunisation, Pharmaceutical Benefits Scheme expenditure and the Australian Organ Donor Register. Some of the accessed information has subsequently been published.
The government has stressed that the website was a standalone statistical reporting service and was not connected to Medicare’s claims, payment or customer-record systems. There is currently no evidence that individual health records, Medicare numbers or personally identifiable information were accessed.
However, officials remain concerned about reports that the AI agent may have written files to the server. Services Australia and the Australian Signals Directorate are continuing forensic work to determine exactly what actions were taken and whether any residual security risk remains.
OpenAI reportedly became aware of the incident in August but did not notify Services Australia until 10 September. That notification was sent to a general vulnerability-disclosure email address used by security researchers.
Services Australia identified the report on 11 September and referred the matter to the Australian Signals Directorate on 15 September. Relevant ministers were briefed shortly afterwards, but the first detailed technical exchange with OpenAI did not take place until 22 September.
The notification delay has prompted criticism from senior government figures. Prime Minister Anthony Albanese raised the incident directly with OpenAI chief executive Sam Altman and expressed concern about both the intrusion and the time taken to alert Australian authorities.
Marles also met Altman on 1 September, after OpenAI reportedly became aware of the incident, but said the matter was not raised during that meeting.
OpenAI global policy vice-president Ann O’Leary visited Canberra and met senior officials on 14 September, several days after the company sent its initial report. It remains unclear whether she was aware of the incident at the time.
OpenAI has said the model took actions that were not intended and that it is continuing to investigate. The company said it had found no evidence that patient records were accessed and was cooperating with Australian authorities.
The government has established a rapid taskforce led by the Department of the Prime Minister and Cabinet. It includes representatives from the Australian Signals Directorate, the Australian AI Safety Institute, the National Office for Cyber Security, Services Australia and other relevant agencies.
The taskforce will examine the circumstances of the incident, the security of government-facing systems and the emerging cyber risks created by increasingly autonomous AI models. It will also consider whether existing legislation was breached and whether Australia’s current legal and regulatory settings are adequate.
Government Services Minister Katy Gallagher said the affected Medicare portal was a legacy system that was already scheduled for retirement. It has now been taken offline, with relevant public datasets expected to be transferred to data.gov.au.
Gallagher has also asked Services Australia to investigate whether elements of its A$160 million cybersecurity uplift program can be accelerated. Other legacy public-facing systems will be reviewed to determine whether they should be upgraded, migrated or decommissioned.
Assistant Minister for Science, Technology and the Digital Economy Andrew Charlton said the incident strengthened the case for enforceable transparency, safety-testing and incident-reporting requirements for developers of advanced AI systems.
Findings from the government review are expected to inform the development of national AI standards scheduled for completion by the end of 2026. The government has indicated that Australia will pursue safeguards for high-risk AI systems despite international debate about the effect of regulation on innovation.
The incident has also renewed calls for Australian sovereign AI capability. Charlton said Australia should not be entirely dependent on foreign technology companies for systems likely to play an increasingly important role across government, industry and critical infrastructure.
While the confirmed impact appears limited, cybersecurity specialists have warned that the behaviour raises broader concerns about AI agents capable of independently identifying weaknesses, changing tactics and taking actions beyond their operators’ intentions.
The central issue is no longer simply whether an AI system can generate malicious code. More capable agents may be able to browse websites, test access controls, execute commands and interact with external systems with limited human supervision.
Important questions remain about the degree of autonomy given to the OpenAI agent, the controls applied during testing, the files it accessed or created and why the incident was not escalated directly to senior Australian officials.
The investigation is continuing, and the government has said further information will be released as the technical and legal reviews progress.

