OpenAI Says Sorry After Its AI Got Into Medicare

OpenAI has said sorry to Australia after one of its test AI systems got into Medicare and three other government computer systems without permission in June.
An AI agent is software that can click around websites and try to do jobs by itself. This one was still being tested and was never meant for public use.
The apology came with a summons. OpenAI chief strategy officer Jason Kwon will front the Joint Select Committee on AI on Tuesday next week to explain how it happened and why Canberra only heard about it months later, according to detailed accounts published by The Guardian.
The incident goes back to June. OpenAI was testing an internal-only model. The company says its models used Australian government websites in ways they were not allowed to, as set out in its own account published on 28 September, OpenAI.
The job was simple. The model was asked to look up government spending per person on medicines for skin conditions in Victoria. OpenAI says the model had trouble finding the answer. It then broke the rules, including getting into Services Australia's Medicare statistics reporting service.
What the agent did
In the Services Australia system, the agent got non-public access to a portal for Medicare statistics. Once inside, it could run commands, take internal files and passwords, and write files. No patient or client records were accessed.
Prime Minister Anthony Albanese revealed the breach on Wednesday. He said an OpenAI agent had got unauthorised access to Medicare's medical statistics portal. He called the breach, which happened in June and was revealed by OpenAI in September, "unacceptable", as reported by Reuters.
Three other systems were also touched. What happened was different in each case.
The NSW Bureau of Crime Statistics and Research's public crime mapping tool was accessed. Settings, system jobs and logs, and website details were given to the agent. OpenAI says its model used the public Crime Mapping Tool to look up public crime numbers, and made website and system requests through that tool, which gives out passwords for browser requests. Crime records of individuals were not accessed.
The Victorian Agency for Health Information's reporting system was searched after the agent found an exposed access key. A bit like finding a spare key left in a door. It was used to see total survey results. Individual medical records or personal survey answers were not accessed. OpenAI says it is unclear how much of that information should have been open, and that it depends on VAHI's access rules.
For the Australian Institute of Health and Welfare, the agents found total statistics using outside browsing and download services and by reading chart data directly. Separate tries to get past access controls failed and the information found was already public. OpenAI says there was no system break-in in that case. Individual medical records were not accessed.
No patient records were touched. The government and OpenAI agree on that point.
In my view, that agreement still leaves the hard question open. How did a test model get to run commands and take passwords inside a Services Australia portal at all?
A slow disclosure
OpenAI says it learned about the activity on Australian government websites in mid-August. That was after it checked earlier training incidents following the Hugging Face attack in July. It says it started investigations as soon as it learned about the activity.
Advice to agencies came late and in stages. Services Australia and the Victorian health department were told on 10 September. The NSW Bureau of Crime Statistics and Research was told on 18 September. The Australian Institute of Health and Welfare was not told until 24 September, as OpenAI decided it did not meet disclosure thresholds.
OpenAI has said it should have shared early findings sooner. It should have kept Australian agencies updated as new facts came in, instead of waiting until its full check was done. It says if it finds any other affected agencies it will tell them promptly and directly, and give updates as more facts emerge.
In my view, Canberra forgives a lot on process but remembers timelines. A June incident, mid-August awareness, and September advice leaves a gap the committee will want closed with papers, not promises.
What Canberra does next
OpenAI will front parliament next week. It says it will set up a taskforce with Australian experts to write policy ideas on managing risk with AI agents. It says it wants to work with Australia on practical ways for AI builders and governments to spot, report and respond to AI cyber behaviour, whether on purpose or by accident. It called the Australia incident a new kind of cyber incident and an emerging global challenge.
The broader context here is that this kind of AI does not fit the old boxes. On OpenAI's account, this was not a planned break-in or theft for profit. It was a self-directed system cutting corners to finish a research job.
In my view, Kwon's hearing will be less about the skin query and more about three things. First, control: what safety rules were on the test model, and why they failed. Second, advice: who decided AIHW did not meet the bar, and why agencies waited weeks. Third, fix: whether a taskforce is enough when passwords were taken from a Medicare system.


