The Australian government is reviewing its processes for handling cybersecurity incidents involving artificial intelligence, after it announced on Thursday that an AI agent from US tech giant OpenAI hacked into a Medicare data portal earlier this year.
Speaking at a press conference in New York, Prime Minister Anthony Albanese revealed OpenAI’s agent had not only gained unauthorised access to Medicare’s standalone statistics reporting service portal, but had also touched both public and non-public files.
It is understood the Medicare statistics portal, which is typically used by researchers and academics for access to aggregated data, was first broached by the AI agent for routine access to statistical information.
Deputy Prime Minister Richard Marles revealed the agent instead opted to hack or “scale the fence” of the statistics portal after it was refused access to certain information.
Albanese emphasised that although the statistics portal was “non-sensitive” in nature and personal Medicare details did not appear to be impacted, the situation was still “obviously unacceptable”.
“There were blocks which were clearly coming back [and] telling the AI agent, ‘no’,” said Albanese.
“The AI agent found a way around those blocks — didn't accept ‘no’ for an answer, if you like.”
A taskforce has been established to provide an “urgent and immediate review” into the hack and determine whether the government’s existing processes are appropriate for responding to AI-related cyber incidents.
Albanese also declared a forensic investigation aided by the Australian Signals Directorate (ASD) has been launched to ascertain more information, including what other government systems were affected.
OpenAI misbehaviour involved ‘several’ government websites
The incident took place on 18 June while OpenAI was conducting internet-based research into public medicine spending.
After OpenAI made headlines for mistakenly attacking open-source platform Hugging Face and numerous other platforms in July, an OpenAI spokesperson said the company had initiated an extensive review of “misaligned model activity”.
A company spokesperson said this review had identified “activity” involving several Australian government websites and services – including the Medicare hack – and saw OpenAI’s models attempt to look up answers and statistics for questions about Australia.
“In the course of that, our models took actions we did not intend,” an OpenAI spokesperson told Information Age.
“Our review found no evidence of patient records being accessed.
“The information accessed included aggregate health statistics and internal file names.”

Prime Minister Anthony Albanese says the OpenAI agent 'didn't accept 'no' for an answer'. Image: ABC News / YouTube
Albanese said he was aware that three other websites may have been interacted with – including at the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research, and the Victorian Department of Health.
Marles confirmed these interactions ultimately appeared to be “entirely normal”, with only public information being accessed.
He also emphasised the Medicare incident was low-impact in nature.
“The government is taking this very seriously,” said Marles.
“That said, it is important to reassure the Australian public that the impact of this incident is relatively minor.”
Marles added that although the Medicare system itself had “not been in any way compromised”, the incident meant an AI agent had entered into an Australian government website in a way that was “unauthorised”.
Given the hacked service portal was a dated legacy system, Minister for Government Services Katy Gallagher has requested that its data be moved to data.gov.au – the government’s current, better-protected platform for accessing open government data.
OpenAI took ‘way too long’ to inform Canberra, PM says
Though the incident occurred in June, Albanese said no notification was given to the government by OpenAI until 10 September.
When this notification did arrive, it came in the form of an email to a public Medicare mailbox typically used by researchers to report potential vulnerabilities.
It wasn’t until 15 September when Services Australia – which administers the impacted statistics portal – was able to appropriately disclose the incident to ASD’s Australian Cyber Security Centre.
OpenAI’s notice finally reached Albanese on the weekend, leading the prime minister to speak directly with OpenAI chief executive Sam Altman.
During this conversation, Albanese said he expressed “Australia's extreme concern about this incident”, as well as his personal “disappointment” over the delayed notification.
“It took the company way too long to inform the government what had occurred and the nature of the way that notification occurred as well was unacceptable,” he said.
Services Australia was contacted for comment.

Deputy Prime Minister Richard Marles (left) and Minister for Government Services Katy Gallagher (right) hold a press conference on Thursday. Image: ABC News / YouTube
Taskforce to weigh possible law enforcement
The prime minister said a dedicated taskforce would weigh “possible law enforcement” and “legislative responses” following the OpenAI incident.
“We'll seek urgent advice on whether any offences have occurred and whether this should be referred to the Australian Federal Police,” said Albanese.
Though the prime minister said “there will obviously be legal consequences”, Marles said the government was still working to determine whether OpenAI had broken any Australian laws.
This week, Albanese joined a cohort of world leaders in signing a joint statement that urged for better AI safeguards, and warned that containment efforts weren’t keeping pace with the technology’s development.
The federal government has also signalled upcoming national standards for AI and data centres which may involve a mandatory reporting mechanism for AI firms which mistakenly hack other companies.
“This [OpenAI] incident is a clear illustration of why we are moving to establish Australian standards for AI,” Albanese said.
Dr Prins Ralston, CEO of the Australian Computer Society (ACS) – which represents Australian technology workers – said the OpenAI incident is “a reminder” that the nation’s digital sovereignty depends on domestic cybersecurity capability.
“As AI increases both the sophistication and speed of cyber threats, building and maintaining a highly capable technology workforce must be treated as a matter of national interest,” he said in a statement.
“Digital sovereignty ultimately depends on people as much as technology.
“Australia needs the skills, capability and professional standards to secure its own systems, protect its data and respond when something goes wrong because public confidence depends on it.”
ACS is the publisher of Information Age.