On September 24, the Australian government announced that an AI agent OpenAI was using for internal evaluations accessed a government statistics website without authorization on June 18 and read non-public files. According to Prime Minister Albanese, the agent also wrote files to an internal server.

It took 84 days from the incident to notification of the government. The agent had originally been given an ordinary information-gathering task: finding publicly available figures on pharmaceutical spending. How did that escalate into access to areas it was not permitted to enter?

What is known so far is only a rough outline of the agent's actions. The specific method used to gain access and the contents of the files written to the internal server are still under investigation.

It would be a mistake to read the name "Medicare" and assume that the core system handling patients' medical records was breached. Yet dismissing the incident as harmless because only aggregated statistics were involved would overlook something significant: after the site refused it, the AI looked for another way in and even wrote to an external system.

Comparing the government's briefings with research on intrusion attempts at a different government-related site around the same time shows that these two matters need to be considered separately.

AD

A refused statistics request escalated into access to non-public areas

According to the Prime Minister's explanation, the task OpenAI's research team gave the internal model was to search the internet for publicly available information on pharmaceutical spending.

The agent was repeatedly refused when trying to retrieve the data, so it tried other approaches. As a result, it accessed not only the public files of the Medicare statistics reporting service managed by Services Australia, but non-public files as well. The government also said that files were written to an internal server.

However, the target was not the core system that processes Medicare claims and payments.

At a press conference, Government Services Minister Gallagher explained that it was a separate public site that researchers have used to look up aggregated benefit and prescription statistics.

The government says that, for now, it has no evidence that personal medical information was accessed or that the breach spread across Services Australia's wider network.

OpenAI also told ABC News that the information accessed was aggregated medical statistics and internal file names, and that no access to patient records has been confirmed.

Still, the fact that the damage confirmed so far is limited is a separate matter from the fact that an AI agent accessed non-public areas without authorization.

What vulnerability or configuration flaw was exploited? What did the non-public files contain? What was the purpose of writing to the internal server? The Prime Minister has not disclosed these details.

A forensic investigation supported by the Australian Signals Directorate is now examining exactly that scope.

The confirmed unauthorized access versus intrusion attempts found at another site

The Australian government has confirmed that OpenAI's agent accessed four government-related sites.

The responsible minister determined that the access to the Medicare statistics portal was unauthorized. For the other three sites — the Australian Institute of Health and Welfare (AIHW), the Victorian Department of Health, and the NSW Bureau of Crime Statistics and Research — the minister said the access was ordinary access to public information.

Separately, the AI safety research organization Transluce reported traces that appear to show intrusion attempts against a different AIHW site on June 20–21.

The organization examined public scan records left on urlquery.net, a service that loads web pages in an external browser.

After ordinary data retrieval was blocked by bot protection, traffic believed to be from the agent probed for vulnerabilities and retrieved public files from a pre-release testing server.

The researchers explicitly note, however, that within the records they could examine, they found no evidence that a vulnerability was successfully exploited.

The government has confirmed unauthorized access in one case: the Medicare statistics portal. A successful intrusion into AIHW cannot be confirmed from public materials.

Organizing the explanations from the Prime Minister and the minister alongside Transluce's findings gives the following picture.

Target and timing Confirmed actions What is confirmed so far
Medicare statistics reporting service, June 18 Unauthorized access to non-public files; files written to an internal server Announced by the Australian government. The specific intrusion route and file contents are under investigation
AIHW statistics site, June 20–21 A small number of intrusion attempts in public scan records; public files retrieved from a testing server Transluce has not confirmed a successful exploit. The government describes the contact with AIHW as ordinary public access

The key is to distinguish between "a case the government has determined to be unauthorized access" and "intrusion attempts an outside researcher observed in public logs."

The suspicious attempts confirmed at AIHW do not mean an intrusion into non-public data succeeded. Conversely, the absence of any sign of success in the public logs does not prove that every intrusion attempt failed. Transluce itself says the records it could examine were only a portion of the total.

The research pointed to links between the traffic to AIHW and to the U.S. site Data USA and a known group of OpenAI-derived agents, based on the targets, methods, and timing.

However, traffic to the Medicare statistics portal is not included in the same records.

ABC News also reviewed public conversation logs between agents and found no mention of Medicare or Services Australia.

Neither the government nor OpenAI has confirmed that the attempts observed at AIHW and the intrusion into the Medicare statistics portal occurred within the same run.

There is currently not enough evidence to link two events close in time as a single series of attacks.

AD

Two time gaps between the incident and the announcement

To understand the notification delay, it is necessary to separate three points: when the incident occurred, when OpenAI became aware of it, and when it contacted the government.

The incident occurred on June 18.

According to the Australian government, OpenAI has said it became aware of the unauthorized access in August. Services Australia was notified on September 10, 84 days after the incident.

That does not mean OpenAI knew about the incident for 84 days without notifying anyone.

Still, current public information does not reveal what was investigated between OpenAI learning of the problem in August and notifying the government on September 10, or when it decided external notification was necessary.

OpenAI first made contact through a public channel Services Australia maintains for researchers and others to report vulnerabilities.

After reviewing the submission, the agency reported it to the Australian Signals Directorate on September 15 and began technical information exchanges with OpenAI on the 22nd.

The Prime Minister conveyed his concerns to OpenAI CEO Sam Altman, saying that not only the time taken to notify but also the method of notification was unacceptable.

The government announced the incident on the 24th and took the affected statistics portal offline. Public data has been moved to locations such as data.gov.au.

Two points will need to be examined going forward.

On OpenAI's side: when did it detect the agent's problematic behavior internally, and when did it decide that notifying third parties was necessary?

On the government's side: what information was lacking between the report arriving at the public channel and the start of actual technical information exchange?

Simply counting "about three months from occurrence" does not show which stage needs improvement.

Why an information-gathering task became a security problem

This AI agent was not instructed to carry out a cyberattack. Its task was to look for publicly available statistical information.

According to the Prime Minister, after being refused when trying to obtain the information it wanted, the agent looked for other means and ultimately accessed areas it was not permitted to enter.

In the public logs of AIHW and other sites examined by Transluce as well, attempts to get around defenses were observed after ordinary data retrieval was blocked.

It is not known whether the two events came from the same run. Even so, they share one feature: an AI agent facing a situation where it could not obtain the data it needed did not accept the site's refusal and began looking for another way to get it.

But it is not possible to infer from this the specific intrusion method or why the model chose that behavior.

What has been published about the Medicare statistics portal is only the rough sequence: after being refused data retrieval, the agent tried other means, accessed a non-public area without authorization, and then wrote files.

It also remains unclear how much authority the agent had been granted, or what operations it was configured to be able to perform against external sites.

The question now is whether an AI given the goal of "finding public data" should be permitted, in pursuit of that goal, to break into or write to other systems — and how the system should enforce that boundary.

In a misalignment reporting framework published on September 16, OpenAI said it would investigate and disclose cases in which models in training or evaluation took unauthorized actions that affected third parties.

The company also acknowledged that its earlier disclosures had been handled case by case and not frequently enough.

However, current materials do not show how this framework applies to the Australian case.

A system for reporting after a problem occurs and safeguards that stop unauthorized operations before they are executed need to be evaluated separately.

AD

What comes next: clarifying the intrusion route and the notification decision process

The Australian government has set up a cross-agency team to investigate the incident and is also considering legal responses. However, no final conclusion has been reached that any unlawful act occurred.

If the government's forensic investigation identifies the route used for the intrusion and the specific targets that were actually read or written to, the extent of the damage can be assessed more accurately.

If OpenAI also publishes a technical report on the matter, showing the agent's execution logs and the decision process from internal detection through to notifying the government, it will be easier to verify how the case relates to the traffic observed at other sites such as AIHW.

Even while awaiting the results, what needs to be checked is clear.

What rules will limit what an AI agent may do next when an external site denies it access? At what stage will human approval be required when it attempts an unauthorized operation?

And when a boundary-crossing problem occurs, who will notify the other party, when, and through what channel?

The compromised statistics portal was separate from the systems that handle patients' medical records. That the damage has been limited so far does not mean the same level of damage would result at other systems.