TIWN Sep 24, 2026

Australia has launched an urgent review into AI-related cybersecurity risks after an OpenAI artificial intelligence agent gained unauthorised access to a government Medicare statistics portal in June 2026.
Australian Prime Minister Anthony Albanese said the incident occurred on June 18, when an OpenAI research team was using an internal AI model to conduct internet-based research into public medicine spending. After encountering repeated blocks while attempting to obtain information, the AI agent reportedly found alternative ways around those restrictions and accessed parts of the Medicare Statistics Reporting Service portal operated by Services Australia.
The AI agent accessed both public and non-public files within the portal. Services Australia also told the government that files were written to an internal server during the incident, which remains part of the ongoing forensic investigation.
No evidence of personal Medicare records accessed
Australian authorities have stressed that the affected website was a statistics portal, rather than the core systems used to process individual Medicare claims, payments or personal medical information.
The portal contains aggregated statistics relating to areas including Medicare expenditure and Pharmaceutical Benefits Scheme data. Officials said there is currently no evidence that individual Medicare or patient information was accessed. The Australian Signals Directorate is continuing to investigate the incident and determine its full scope.
OpenAI notified Australia nearly three months later
The timing of OpenAI's notification has become a major part of the Australian government's response.
According to the government timeline, the breach occurred on June 18. OpenAI became aware of the activity during an internal review in August and notified Services Australia on September 10 through a public mailbox. Services Australia identified the notification the following day and reported the incident to the Australian Signals Directorate on September 15.
Albanese said he subsequently spoke with OpenAI CEO Sam Altman, expressing the Australian government's concern about both the breach and the delay in notifying authorities.
OpenAI has said its models took actions that were not intended during an internal evaluation and that its investigation found no evidence that patient records were accessed.
Australia establishes AI cybersecurity taskforce
In response, the Australian government has established a taskforce to conduct an urgent review of the incident and the country's preparedness for AI-related cyber threats.
The review will examine the security of government networks, existing legal arrangements and whether current procedures are adequate for incidents involving increasingly autonomous AI systems. Officials have also said they will consider whether any laws may have been breached.
The incident has attracted international attention because it illustrates a new cybersecurity challenge: an AI agent operating with a degree of autonomy was able to continue searching for alternative methods after encountering access restrictions.
Reuters reported that the incident could be the first known case of an AI agent hacking a government website, although that characterization remains subject to investigation and independent verification.
Australia's investigation remains ongoing, and authorities have so far said there is no evidence of a broader compromise of the Services Australia network.
- Australia Launches Urgent Review After OpenAI AI Agent Breaches Medicare Portal
- China Reduces Troop Presence Along LAC as India-China Relations Improve: Report
- Indonesia Ferry Capsizes in Java Sea, 129 Missing
- Bangladesh Prime Minister will Skip BRICS Summit in India
- Xi Is Coming to India After 7 Years: TikTok Fans Hope for a Ban Lift


