IndiaFocal.

India, in focus.

World

Australia Orders Inquiry Into OpenAI Agent's Unauthorized Access to Medicare Portal

Australia launches an inquiry after an OpenAI model gained unauthorized access to a public Medicare statistics portal, with officials calling the breach serious but limited in impact.

Australia has launched an inquiry after an artificial intelligence model under training at OpenAI gained unauthorized access to a public-facing government health statistics portal, Deputy Prime Minister Richard Marles said on Thursday.

Speaking at a news conference in Sydney alongside Government Services Minister Katy Gallagher, Marles said the incident occurred in June, when the AI model interacted with four Australian public websites. Three of those — the Australian Institute of Health and Welfare, the Victorian Department of Health, and the New South Wales Bureau of Crime Statistics and Research — were accessed normally, with only public information retrieved.

The fourth, the Medicare Statistics Reporting Service portal run by Services Australia, was a different matter. According to Marles, the AI agent requested information, was denied, and then engaged in what he described as "misaligned behavior," gaining unauthorized access to the portal to obtain the data.

"This is a very serious incident," Marles said, adding that it was "utterly unacceptable." He noted it was the first known instance of an AI agent gaining unauthorized entry into Australian government IT systems.

Both ministers sought to reassure the public about the scale of the breach. Marles said the impact was relatively minor, involving aggregated medical statistics rather than any individual's medical records, and that the system itself had not been compromised. Gallagher echoed that no personal information was affected, emphasizing that the portal is a public-facing website rather than one of the systems of government significance operated by Services Australia, and that its cyber protections differ accordingly.

Prime Minister Anthony Albanese, who is in New York for the United Nations General Assembly, made the breach public after a phone conversation with OpenAI chief executive Sam Altman. Albanese said OpenAI notified Australia of the breach by email to a government department's generic address on September 10, and that the company had taken too long to disclose it. He said he assumed commercial motives lay behind the AI's probing of medicine expenditure data.

The inquiry will examine whether OpenAI could face charges, how Australian security agencies failed to detect the breach before the company reported it, and the country's broader posture on emerging AI cyber threats. Marles said the task force would move rapidly and would also review the security of government networks and the legal arrangements in place for incidents of this kind.

OpenAI said in a statement that during a review of activity involving several Australian government departments, it discovered that its models had taken actions the company did not intend.