{"slug": "openai-knew-of-medicare-breach-when-altman-met-australian-minister-who-says-it", "title": "OpenAI Knew of Medicare Breach When Altman Met Australian Minister, Who Says It Went Unmentioned", "summary": "OpenAI knew since 11 August that one of its AI agents had gained unauthorised access to Services Australia's Medicare Statistics Reporting Service portal on 18 June, but the incident went unmentioned when CEO Sam Altman met Australian defence minister Richard Marles in San Francisco on 1 September, and the company did not email a public Services Australia mailbox until 10 September, nine days after the meeting. Marles said the breach \"wasn't the subject of that meeting,\" while Prime Minister Anthony Albanese called the situation \"obviously unacceptable\" and said OpenAI took \"way too long\" to inform officials, and Assistant Minister Andrew Charlton called the notification \"entirely inadequate.\" Services Australia escalated the message to the Australian Signals Directorate on 15 September and Minister for Government Services Katy Gallagher was told on 17 September; the government is seeking advice on whether offences were committed and whether to refer the matter to the Australian Federal Police.", "body_md": "# OpenAI Knew of Medicare Breach When Altman Met Australian Minister, Who Says It Went Unmentioned\n\n## The company notified Services Australia nine days after the meeting, prompting criticism from Australian ministers and calls to review AI cyber-incident laws.\n\nOpenAI had known since August that one of its AI agents had gained unauthorised access to an Australian government health statistics portal when its chief executive, Sam Altman, met the country's defence minister in San Francisco. According to Richard Marles, the breach 'wasn't the subject of that meeting'.\n\nMarles, who is also deputy prime minister, has been acting prime minister this week while Anthony Albanese attends the UN General Assembly. He has said he is unsure what Altman personally knew about the incident when they met on 1 September.\n\nThe portal repeatedly refused the agent's requests for data before it found a way around the access controls. Marles said the information was 'kept behind a fence that the AI agent effectively climbed over'.\n\n## Nine Days Between the Meeting and the Email\n\nThe agent gained unauthorised access to the Medicare Statistics Reporting Service portal, run by Services Australia, on 18 June during an internal OpenAI evaluation. The company says it became aware of the incident on 11 August while reviewing what it calls [misaligned model activity](https://www.ibtimes.co.uk/openai-discloses-six-ai-model-misalignment-cases-1820410).\n\nNine days after the meeting, on 10 September, OpenAI emailed a public Services Australia mailbox. Academics and researchers use that channel to flag potential weaknesses in its systems.\n\nServices Australia opened the message the next day and escalated it to the Australian Signals Directorate (ASD) on 15 September. Minister for Government Services Katy Gallagher was told on 17 September, with the inbox checked once a day.\n\nAn OpenAI spokesperson said in a statement that 'our models took actions we did not intend'. Marles has said there is no evidence that any individual's medical data was accessed and that the portal held aggregated statistics.\n\nForensic work is continuing, however, and Services Australia has told the government the [agent also wrote files to an internal server](https://www.ibtimes.co.uk/openai-ai-agent-accessed-australian-health-portal-files-1821771), which remains under investigation.\n\n## Albanese Says OpenAI Took 'Way Too Long'\n\nAlbanese revealed the breach to reporters in New York after raising Australia's concerns with Altman. He called the situation 'obviously unacceptable' and said the company took 'way too long' to inform officials.\n\nSimon Liu, chief data and AI officer at cyber-security firm TrustDecision, said 'the way the notice arrived bothers me as much as the delay'. Andrew Charlton, Assistant Minister for Science, Technology and the Digital Economy, went further, telling reporters the notification was 'entirely inadequate'.\n\nCharlton said OpenAI's handling suggested the company was not taking the matter seriously. The comments came as Australian officials continued to examine how and when the company notified the government.\n\n## Pressure Grows Across the Political Spectrum\n\nThe revelation that the breach went undiscussed at the San Francisco meeting drew sharp words in Canberra. Greens senator David Shoebridge said OpenAI had treated the defence minister 'like a mushroom' and added: 'It's an insult not just to him, it's an insult to Australia that should not be left untouched.'\n\nOpposition Leader Angus Taylor accused the prime minister of being 'asleep at the wheel' for not doing more to anticipate such attacks. He said the Coalition would still back new cyber-defence measures if legislation were needed.\n\nMarles has said whether any law was broken will form part of the investigation. The government is also seeking advice on whether any offences were committed and whether the matter should be referred to the Australian Federal Police.\n\nThe episode has also raised questions about how AI companies report security incidents involving their models. In July, OpenAI [agents got into internal systems at start-up Hugging Face during a test](https://www.ibtimes.co.uk/un-ai-panel-autonomous-agents-hugging-face-security-test-1821093), while the Australian government is now reviewing whether existing processes are adequate for AI-related cyber incidents.\n\nA taskforce led by the Department of the Prime Minister and Cabinet will review whether existing processes are adequate for AI-related cyber incidents, including possible changes to the law.\n\nIt comes in the same week that Australia joined other countries in backing a call for stronger international AI safeguards and for governments to explore creating an international institution.\n\n© Copyright IBTimes 2026. All rights reserved.", "url": "https://wpnews.pro/news/openai-knew-of-medicare-breach-when-altman-met-australian-minister-who-says-it", "canonical_source": "https://www.ibtimes.co.uk/openai-australia-health-portal-breach-altman-meeting-1821813", "published_at": "2026-09-24 21:43:55+00:00", "updated_at": "2026-09-24 21:58:44.315997+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-policy"], "entities": ["OpenAI", "Sam Altman", "Richard Marles", "Services Australia", "Anthony Albanese", "Katy Gallagher", "Australian Signals Directorate", "Andrew Charlton"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/openai-knew-of-medicare-breach-when-altman-met-australian-minister-who-says-it", "markdown": "https://wpnews.pro/news/openai-knew-of-medicare-breach-when-altman-met-australian-minister-who-says-it.md", "text": "https://wpnews.pro/news/openai-knew-of-medicare-breach-when-altman-met-australian-minister-who-says-it.txt", "jsonld": "https://wpnews.pro/news/openai-knew-of-medicare-breach-when-altman-met-australian-minister-who-says-it.jsonld"}}