Skip to content
Australia sets up taskforce after OpenAI agent breaches statistics portal

Australia sets up taskforce after OpenAI agent breaches statistics portal

www.computerweekly.com • September 29, 2026

The Australian government has set up a taskforce to review how it responds to artificial intelligence (AI)-related cyber incidents , after an OpenAI agent gained unauthorised access to a Medicare website run by Services Australia.

Speaking to reporters in New York on Wednesday local time, prime minister Anthony Albanese said the incident took place on 18 June, when OpenAI’s research team used an internal model to the internet for information on public spending on medicines.

“There were blocks clearly which were coming back telling the AI agent, ‘no’,” he said. “The AI agent found a way around those blocks. Didn’t accept ‘no’ for an answer, if you like.”

The agent went on to reach public and non-public files on the Medicare Statistics Reporting Service portal. Services Australia has also noted that the agent wrote files to an internal server.

No personal information is believed to have been accessed, and the evidence so far points to no broader compromise of the Services Australia network, Albanese said. The public-facing portal held non-sensitive Medicare data, such as spending statistics.

Albanese said he called OpenAI CEO Sam Altman on Wednesday to convey Australia’s “extreme concern” and his disappointment that “it took the company way too long to inform the government what had occurred”.

The first notification did not arrive until 10 September, 84 days after the incident. “The notification was an email sent to just the public mailbox,” he said.

OpenAI became aware of the incident on 11 August, during a review of misaligned model activity in training, according to a timeline published by ABC News . Altman met deputy prime minister Richard Marles in San Francisco on 1 September, but Marles has said the breach was not disclosed.

The email went to an address researchers use to report weaknesses in Services Australia’s systems. The agency passed it to the Australian Cyber Security Centre, part of the Australian Signals Directorate (ASD), on 15 September and told Katy Gallagher, minister for government services, two days later.

In a statement, OpenAI said its models “took actions we did not intend” while looking up statistics Australia during an internal evaluation. The company said its review found no sign of patient records being accessed. What the models did reach included aggregate health statistics and internal file names.

“I think OpenAI know that they need to have better protocols in place,” Albanese said when asked whether the company could still be trusted as a partner, including on datacentres.

The taskforce, led by the Department of the Prime Minister and Cabinet, will draw on the National Cyber Security Coordinator, the Office of AI , ASD, the Australian AI Safety Institute and Services Australia.

In the terms of reference released on Thursday, the taskforce is expected to recommend reporting requirements for AI-driven cyber incidents and obligations on AI companies to notify and cooperate, and to consider whether current offences and penalties are an adequate deterrent.

The incident will also go to parliament’s Joint Select Committee on Artificial Intelligence. The government is seeking advice on whether any offences were committed and whether to refer the matter to the Australian Federal Police (AFP).

A forensic investigation supported by ASD is also examining whether other systems were hit. Albanese named three that may have been: the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research and the Victorian Department of Health.

Marles later confirmed the agent had interacted with all three sites in June, but said those interactions were “entirely normal and public information was accessed”.

Pressed on whether Australia’s security agencies had missed the intrusion, Albanese noted the portal was “not a security website”. Earlier in the press conference, he said the government “could not find precedent” for the incident.

‘It scaled the fence’

Speaking in Sydney on Thursday, Marles, who is acting prime minister while Albanese is abroad, said the agent had engaged in “misaligned behaviour”, noting that “it asked a question, the information was not given and rather than leaving at that point, it scaled the fence”.

He put the impact at “relatively minor” but called the incident “a salutary warning” the technology being developed without safeguards in place.

He also defended the government’s timing, saying that going public without all the facts at hand would have been reckless.

Gallagher, whose portfolio covers Services Australia, was also questioned over the agency’s handling of OpenAI’s email. “That email address is looked at once a day,” she said of the inbox that received it, adding that it “sometimes gets a number of notifications, sometimes many of them are hoaxes”.

OpenAI did not provide a technical briefing on the agent’s activity until 22 September, she said.

Gallagher said the portal had been protected by anti-bot measures and that OpenAI’s email had flagged a vulnerability in it. “It is a legacy system… and it is being moved to data.gov.au, so we won’t be reactivating it,” she said.

She is also considering whether to bring forward cyber security upgrades at Services Australia, funded with A$160m over four years in the May budget, and said other legacy public-facing government websites could be shut down.

David Rajkovic, regional vice-president for Australia and New Zealand at data security company Rubrik, said the breach against Medicare is just the latest example of AI agents going rogue.

He noted that the latest incident, along with the Hugging Face breach earlier this year, shows that frontier models can sustain complex cyber operations, discover novel attack paths and move across real-world systems in pursuit of a narrow objective.

“The genie is out of the bottle when it comes to AI agents and, the truth is, Australia is not fully prepared to deal with the risk agents pose. Our readiness posture is lagging. Far too many organisations are relying on prevention strategies and legacy data protection systems to solve for a very modern problem,” he added.

In July, OpenAI admitted that a combination of its models, including GPT-5.6 Sol and a more capable pre-release model, had breached Hugging Face’s systems during an internal cyber security test. With some safeguards switched off, the models broke out of their test environment to hunt for benchmark answers in Hugging Face’s production database.

Anthropic and Meta have since said their own models hacked real-world systems during pre-deployment testing. OpenAI has not said whether the same models were involved in the Hugging Face and Medicare incidents.

Albanese called the Medicare incident “a clear illustration of why we are moving to establish Australian standards for AI”.

Asked how much of a shock the breach had been, Albanese said: “It was a shock that it occurred, because it was real and serious. But it also, I think, was something that had been predicted, including by the AI companies themselves.”

Lendi Group has built its own orchestration platform to run the specialised agents that now guide customers through the early stages of a loan application.

Gartner calls for IT leaders to prioritise foundational investments in governance, change management and talent to realise the benefits of AI during its Data and Analytics Summit in Sydney.

Australia’s prime minister, Anthony Albanese, establishes an Office of AI to coordinate binding standards for the technology, promising the world’s first single national AI framework.

AWS is embedding cross-functional teams of engineers , scientists and strategists with customers, with Commonwealth Bank of Australia among those already seeing results.

AI agents can act. It's unclear if enterprises can stop them. By: Liz Hughes

CDC chief backs datacentre standards as social licence runs short By: Stephen Withers

ANZ firms put data foundations before agentic AI By: Stephen Withers

Lendi Group taps agent swarm to reshape mortgage broking By: Stephen Withers

CIOs looking for ways to say yes to the iPad in the enterprise CIOs are looking for ways to say yes to the iPad in the enterprise, despite the technological and cultural challenges associated ...

CIOs are looking for ways to say yes to the iPad in the enterprise, despite the technological and cultural challenges associated ...

What CISOs should take from the Hugging Face-OpenAI incident Security experts say the lesson isn't to abandon sandboxing, but to strengthen the security controls around surrounding systems ...

Security experts say the lesson isn't to abandon sandboxing, but to strengthen the security controls around surrounding systems ...

Red agents vs. blue agents: How to make AI better at defense The agentic AI playing field was heavily tilted toward offense, so researchers began using red team agents to help teach their ...

The agentic AI playing field was heavily tilted toward offense, so researchers began using red team agents to help teach their ...

When AppSec scanners become a supply chain attack vector New research shows how security scanners embedded in the software supply chain can be attacked to serve as a foothold for ...

New research shows how security scanners embedded in the software supply chain can be attacked to serve as a foothold for ...

5G Quiz - Can you speak 5G? -generation 5G wireless technology will offer faster speeds and increased capacity. Do you speak the language well enough to ...

-generation 5G wireless technology will offer faster speeds and increased capacity. Do you speak the language well enough to ...

5G expansion is coming, but where will operators reap profits? In this recap of industry blogs, networking pundits examine the profit potential of 5G expansion, responsible use of AI and some ...

In this recap of industry blogs, networking pundits examine the profit potential of 5G expansion, responsible use of AI and some ...

5G, cloud embolden network outsourcing and ultimate virtualization Could the cloud, 5G, small cell technology, BYOD and carrier-provisioned networks completely virtualize network infrastructure? ...

Could the cloud, 5G, small cell technology, BYOD and carrier-provisioned networks completely virtualize network infrastructure? ...

Distributed computing: The infrastructure shift AI demands The hyperscale era is ending. AI's energy and latency demands are driving infrastructure toward the edge -- closer to users, ...

The hyperscale era is ending. AI's energy and latency demands are driving infrastructure toward the edge -- closer to users, ...

Why and the NSA love graph databases Graph databases play six degrees of separation to find real connections. See how IT teams can use the database approach for ...

Graph databases play six degrees of separation to find real connections. See how IT teams can use the database approach for ...

DevOps and Agile IT save mainframe training from skills quagmire The problem isn't that new hires aren't familiar with the complex, custom daily tasks of mainframe ops. The problem is that ...

The problem isn't that new hires aren't familiar with the complex, custom daily tasks of mainframe ops. The problem is that ...

HR makes major strides toward improving employee engagement

Cloud vs. legacy ERP systems: Tug of war intensifies for SMBs Aging legacy ERP systems at SMBs seem to be getting plenty of scrutiny these days. Heightened consumer demands, shifting ...

Aging legacy ERP systems at SMBs seem to be getting plenty of scrutiny these days. Heightened consumer demands, shifting ...

Develop smart AI in CRM strategies to win and keep customers Of the three words that comprise customer relationship management , one word binds the other two. As necessity and ...

Of the three words that comprise customer relationship management , one word binds the other two. As necessity and ...

Extracted Entities

Attack Types (1)

Companies (1)

Countries (1)

Domains (1)

Tools (1)