An OpenAI research model got around access blocks on a Services Australia Medicare statistics portal in June and opened files that were not meant to be public, Prime Minister Anthony Albanese said on Thursday. The company told the government almost three months later, by email to a public mailbox.
Albanese disclosed the incident at a press conference in New York, where he is attending the United Nations General Assembly. He said the agent "accessed both public and non-public files" on the public-facing Medicare Statistics Reporting Portal. Services Australia advises that it also wrote files to an internal server. The Australian Signals Directorate is assisting a forensic investigation.
The portal publishes aggregate statistics on Medicare, the PBS and related programs as downloadable files for researchers, health professionals and the public. Albanese said no personal information is believed to have been accessed "at this stage", and that the evidence so far shows no broader compromise of the Services Australia network.
The Prime Minister gave the sequence. On 18 June, OpenAI's research team used an internal model to research public medicine spending. After "encountering repeated blocks", he said, the model tried other ways to get the data and reached areas it was not authorised to see. "The AI agent found a way around those blocks. Didn't accept no for an answer, if you like."
OpenAI's first notice came on 10 September. Services Australia reported it to ASD's Australian Cyber Security Centre on 15 September. Minister for the Public Service Katy Gallagher was told at the end of last week, and the Prime Minister's office over the weekend.
Albanese said he told OpenAI chief executive Sam Altman in a phone call that "it took the company way too long to inform the Government what had occurred and the nature of the way that that notification occurred as well was unacceptable." Asked whether Altman apologised, he said Altman "clearly accepted that the company had not done good enough."
The delay is only half of it. The Commonwealth did not find the access itself. "We became aware of this when OpenAI raised the issue with us," Acting Prime Minister Richard Marles told ABC Radio National. He said the portal "would have had relatively low levels of security, which befitted the fact that the information that it contained was not particularly sensitive." In his words: "This was really kept behind a fence that the AI agent effectively climbed over."
Three more systems are being checked: the Australian Institute of Health and Welfare, the NSW Bureau of Crime Statistics and Research, and the Victorian Department of Health. Albanese said they "may be impacted" but added "we're not confirming that that occurred." Marles was firmer. He said the model interacted with those three "in a way that a member of the public might, so it only acted in an authorised way."
OpenAI has not named Australia on its own incident page. That page says a review of its models' activity on the internet during training and evaluation has so far led it to notify "dozens of third parties". Marles called this "the first time that's occurred in respect of the Australian government's IT systems". Albanese said the government could not find a precedent, but was "not asserting" it was a world first.
A taskforce led by the Department of the Prime Minister and Cabinet, with the National Cybersecurity Coordinator, the Office of AI, ASD, the Australian AI Safety Institute and Services Australia, will review whether existing processes are adequate for AI-related cyber incidents. The government will seek advice on whether any offences occurred and whether the matter should go to the Australian Federal Police. It is also referring the incident to Parliament's Joint Select Committee on Artificial Intelligence.
Albanese said lessons from the incident would feed into the government's AI standards legislation. The consultation paper for those standards, released last Friday, proposes that frontier AI companies report "defined reportable AI incidents" to Australian authorities. It does not yet define a reportable incident, and it does not set a deadline for reporting one.
Still unknown: how much data the model took, what it wrote to the server, and when OpenAI itself found out. Marles said he did not think it was "a lot of data" but that the investigation was continuing. Marles and Gallagher were due to release the taskforce's terms of reference on Thursday.




