IndiaFocal.

India, in focus.

National

Australia Weighs Tougher AI Laws After OpenAI Bot Hits Medicare Database

Australia is weighing tougher AI rules after an OpenAI bot breached the Medicare database in June, with the PM calling the incident unacceptable.

Australia is moving toward a firmer regulatory posture on artificial intelligence after an OpenAI bot accessed the database of the country's health system, an intrusion that Prime Minister Anthony Albanese has called "unacceptable".

The breach occurred in June and was disclosed by OpenAI in September. According to the company, it learned of the incident only in August and says the access was not intentional and did not expose private information. The Medicare system is one of Australia's most heavily used government services, and the episode is among at least four involving Australian government websites.

Albanese said he conveyed "extreme concern" to OpenAI chief executive Sam Altman and that the government is considering "possible law-enforcement and legislative responses". An OpenAI spokesperson did not immediately respond to a question about his comments.

The fallout lands as Canberra prepares AI-specific legislation from 2027. Policy experts suggest the Medicare case could harden the government's approach, potentially adding mandatory reporting requirements for AI firms whose products are involved in security breaches — mirroring existing rules that require companies to disclose intrusions within 72 hours. Officials may also update privacy laws and require AI companies to help test public-facing websites to protect national security.

Australia has already declined to let OpenAI and rival Anthropic bypass copyright law for model training, requiring them instead to negotiate licensing deals with Australian rights-holders. Experts expect that stance to hold.

The incident has also sharpened scrutiny of the country's data centre buildout, which economists estimate will be worth A$150 billion by 2030. OpenAI partnered with NextDC in December for a 612-megawatt facility in Sydney, while Anthropic has a local partner for a 2.16-gigawatt data centre in Queensland. Both projects are awaiting government clearances, and the question of "social licence" — whether a company benefits the community hosting it — is gaining weight in planning decisions.

After Albanese's disclosure, New South Wales Premier Chris Minns said an OpenAI bot had accessed a research database of the state's Bureau of Crime Statistics and Research. Abigail Boyd, a state Greens lawmaker who chairs an inquiry into data centres, said the state must consider the social harms of such technologies when weighing approvals for hyperscale facilities.

Toby Walsh, chief scientist at the University of New South Wales' AI Institute, said the episode should push the government toward greater oversight of an industry that "needs to grow up fast", adding that humans who carried out such hacking would face prosecution.

The breach adds strain to Australia-US relations, already tested by Canberra's ban on social media for under-16s, levies on platforms that post Australian news, and plans to require companies to take responsibility for user safety, including letting users opt out of algorithms. Washington has criticised those measures as censorship. Johanna Weaver, executive director of the Tech Policy Design Institute and a former Australian chief cyber negotiator at the United Nations, said Australia's record of regulating tech in the face of US resistance positions it to lead a push for stronger AI guardrails. Henry Fraser, a technology law researcher at Queensland University of Technology, said Canberra appears willing to accept any US backlash given domestic concern about such risks.