The AI hack governments didn't see coming, and what it means for your business

Australia's government is demanding answers after an artificial intelligence agent built by OpenAI broke into a Medicare data portal, in what's being described as one of the first known cases of an…

Yajush Gupta
Yajush Gupta
News · 25 Sept 2026 · 2 min read
Above The AI hack governments didn't see coming, and what it means for your business. Dynamic Business

Australia's government is demanding answers after an artificial intelligence agent built by OpenAI broke into a Medicare data portal, in what's being described as one of the first known cases of an AI agent hacking a government website anywhere in the world.

Prime Minister Anthony Albanese confirmed the breach occurred in June, but said OpenAI didn't tell the government about it until 10 September, more than a week later than officials would have expected. When OpenAI finally did flag the incident, it sent an email to a general public mailbox managed by Services Australia rather than escalating it directly. It then took another five days before that message was passed on to the Australian Signals Directorate, the country's cybersecurity agency.

What actually happened

According to the government's account, an OpenAI agent had been given a fairly ordinary task, researching public spending on medicines. In the course of that research, the model searched broadly online and came across a Services Australia portal containing Medicare statistics. When the portal didn't hand over the information being asked for, the AI agent found a way around that and accessed some non-public files anyway.

Acting Prime Minister Richard Marles described the incident in fairly plain terms: "We keep our most important national security information behind a fortress. This was really kept behind a fence that the AI agent effectively climbed over."

The government has been at pains to stress the damage was limited. No individual Medicare records were accessed, officials say, only aggregate data such as bulk billing statistics, immunisation figures, Pharmaceutical Benefits Scheme numbers, organ donor register information and annual reports, the kind of collated, de-identified statistics used for broad policy analysis rather than anything tied to a specific person.

Some of what was accessed wasn't public at the time of the breach, though the government says none of it was especially sensitive, and it has since been made public anyway. Other sites, including the Australian Institute of Health and Welfare, Victoria's Health Department, and the NSW Bureau of Crime Statistics and Research, may also have been targeted.

A slow and awkward disclosure

What's drawn the most criticism isn't necessarily the breach itself, it's how long it took to come to light, and how it was disclosed once OpenAI knew.

Finance Minister Katy Gallagher said the alert "should not have gone to an email address, it should have been escalated." Albanese was similarly blunt in his assessment, calling the delay "obviously unacceptable."

There's an added wrinkle in the timeline. OpenAI's vice president of global policy, Ann O'Leary, was in Canberra on 14 September, the day before Services Australia referred the matter to the Australian Signals Directorate, attending an event on AI policy and meeting with senior Australian officials. She doesn't appear to have raised the breach with anyone in government while she was there. OpenAI chief executive Sam Altman also met with Marles in San Francisco on 1 September, after OpenAI had already become aware of what it called "misaligned model activity" targeting Australian websites, but before the government had been formally told anything.

Marles has since described OpenAI as "cooperative" in the aftermath, saying the company has been transparent since the issue came to light.

What OpenAI has said

OpenAI's own explanation is that the company came across the activity while conducting "an extensive review" of its models. "During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers and available statistics for questions about Australia during an internal evaluation," the company said. "In the course of that, our models took actions we did not intend."

A company spokesperson separately described it as a case where "an AI model was looking for answers and took action we did not intend."

Why this matters beyond one government portal

The Australian government isn't treating this as a one-off. A taskforce is being set up, led by the Department of the Prime Minister and Cabinet, and involving the Australian Signals Directorate, the AI Safety Institute and the Office of AI, to investigate exactly what happened, how the government found out, and whether any laws were broken. It'll also look more broadly at how government systems interact with external AI tools.

Maurice Chiodo, an Australian mathematician at Cambridge University's Centre for the Study of Existential Risk, said the breach appeared to be "a significant escalation in seriousness from similar incidents we have seen in recent months." He added that while there's plenty of talk about new AI laws, policymakers first need to look at enforcing the rules already in place.

OpenAI isn't alone here, either. Rivals including Anthropic, Google's Gemini and Meta have all disclosed similar incidents of their own AI agents accessing external systems they weren't meant to.

For a government portal, the fallout looks contained. But for any business, small or large, increasingly connecting AI tools to their own systems, customer databases, invoicing platforms, websites, the underlying lesson is hard to ignore: an AI agent given an ordinary task went looking for information on its own, found a locked door, and let itself in anyway.

That's not a hypothetical risk anymore. It happened to a national government with dedicated cybersecurity infrastructure. Worth remembering next time an AI tool is granted access to anything you'd rather keep behind a proper fence.

YG
Yajush Gupta
Yajush Gupta reports for Dynamic Business — covering the founders, money and policy shaping Australia's economy.
From the floor
Closer to this story than we are?
If you're building in this space — or watching it reshape your market — pitch us. We edit it; you get the byline.
More from the desk

Keep reading.

News ◆

New report benchmarks earnings across 116 sole trader occupations

Hnry's new report breaks down what sole traders are really earning across trades, health and freelance work.

Yajush Gupta · 2 min
Founder Friday ◆

This skincare founder runs a $1.3 million business with a team of three

Jacqui Vidal runs a $1.3 million forecast skincare business with just two casual staff. Here's the deliberate model behind the lean approach.

Yajush Gupta · 2 min
News ◆

How one Australian business lifted email ROI 13% by sending less

Nearly 69% of email orders in Australia came from first-time buyers this Black Friday. Here's how to turn them into repeat customers.

Yajush Gupta · 2 min
0 people like this

Comments

Loading comments…