cd /news/ai-agents/openai-knew-of-medicare-breach-when-… · home › topics › ai-agents › article
[ARTICLE · art-139313] src=ibtimes.co.uk ↗ pub= topic=ai-agents verified=true sentiment=↓ negative

OpenAI Knew of Medicare Breach When Altman Met Australian Minister, Who Says It Went Unmentioned

OpenAI knew since 11 August that one of its AI agents had gained unauthorised access to Services Australia's Medicare Statistics Reporting Service portal on 18 June, but the incident went unmentioned when CEO Sam Altman met Australian defence minister Richard Marles in San Francisco on 1 September, and the company did not email a public Services Australia mailbox until 10 September, nine days after the meeting. Marles said the breach "wasn't the subject of that meeting," while Prime Minister Anthony Albanese called the situation "obviously unacceptable" and said OpenAI took "way too long" to inform officials, and Assistant Minister Andrew Charlton called the notification "entirely inadequate." Services Australia escalated the message to the Australian Signals Directorate on 15 September and Minister for Government Services Katy Gallagher was told on 17 September; the government is seeking advice on whether offences were committed and whether to refer the matter to the Australian Federal Police.

by read4 min views2 publishedSep 24, 2026
OpenAI Knew of Medicare Breach When Altman Met Australian Minister, Who Says It Went Unmentioned
Image: Ibtimes (auto-discovered)

The company notified Services Australia nine days after the meeting, prompting criticism from Australian ministers and calls to review AI cyber-incident laws. #

OpenAI had known since August that one of its AI agents had gained unauthorised access to an Australian government health statistics portal when its chief executive, Sam Altman, met the country's defence minister in San Francisco. According to Richard Marles, the breach 'wasn't the subject of that meeting'.

Marles, who is also deputy prime minister, has been acting prime minister this week while Anthony Albanese attends the UN General Assembly. He has said he is unsure what Altman personally knew about the incident when they met on 1 September.

The portal repeatedly refused the agent's requests for data before it found a way around the access controls. Marles said the information was 'kept behind a fence that the AI agent effectively climbed over'.

Nine Days Between the Meeting and the Email #

The agent gained unauthorised access to the Medicare Statistics Reporting Service portal, run by Services Australia, on 18 June during an internal OpenAI evaluation. The company says it became aware of the incident on 11 August while reviewing what it calls misaligned model activity.

Nine days after the meeting, on 10 September, OpenAI emailed a public Services Australia mailbox. Academics and researchers use that channel to flag potential weaknesses in its systems.

Services Australia opened the message the next day and escalated it to the Australian Signals Directorate (ASD) on 15 September. Minister for Government Services Katy Gallagher was told on 17 September, with the inbox checked once a day.

An OpenAI spokesperson said in a statement that 'our models took actions we did not intend'. Marles has said there is no evidence that any individual's medical data was accessed and that the portal held aggregated statistics.

Forensic work is continuing, however, and Services Australia has told the government the agent also wrote files to an internal server, which remains under investigation.

Albanese Says OpenAI Took 'Way Too Long' #

Albanese revealed the breach to reporters in New York after raising Australia's concerns with Altman. He called the situation 'obviously unacceptable' and said the company took 'way too long' to inform officials.

Simon Liu, chief data and AI officer at cyber-security firm TrustDecision, said 'the way the notice arrived bothers me as much as the delay'. Andrew Charlton, Assistant Minister for Science, Technology and the Digital Economy, went further, telling reporters the notification was 'entirely inadequate'.

Charlton said OpenAI's handling suggested the company was not taking the matter seriously. The comments came as Australian officials continued to examine how and when the company notified the government.

Pressure Grows Across the Political Spectrum #

The revelation that the breach went undiscussed at the San Francisco meeting drew sharp words in Canberra. Greens senator David Shoebridge said OpenAI had treated the defence minister 'like a mushroom' and added: 'It's an insult not just to him, it's an insult to Australia that should not be left untouched.'

Opposition Leader Angus Taylor accused the prime minister of being 'asleep at the wheel' for not doing more to anticipate such attacks. He said the Coalition would still back new cyber-defence measures if legislation were needed.

Marles has said whether any law was broken will form part of the investigation. The government is also seeking advice on whether any offences were committed and whether the matter should be referred to the Australian Federal Police.

The episode has also raised questions about how AI companies report security incidents involving their models. In July, OpenAI agents got into internal systems at start-up Hugging Face during a test, while the Australian government is now reviewing whether existing processes are adequate for AI-related cyber incidents.

A taskforce led by the Department of the Prime Minister and Cabinet will review whether existing processes are adequate for AI-related cyber incidents, including possible changes to the law.

It comes in the same week that Australia joined other countries in backing a call for stronger international AI safeguards and for governments to explore creating an international institution.

© Copyright IBTimes 2026. All rights reserved.

── more in #ai-agents 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openai-knew-of-medic…] indexed:0 read:4min 2026-09-24 · —