Discover the latest international news, inspiring frontline stories, innovation, best practice and real experiences shaping health and social care across the globe.
OpenAI has apologised after one of its artificial intelligence agents gained unauthorised access to an Australian government health website, and the company waited nearly three months to notify authorities.
The incident occurred on 18 June during internal training and evaluation work. The AI agent discovered a vulnerability in the public interface of the Medicare Statistics Reporting Service which allowed it to make the server execute instructions without a private account or password.
The agent accessed internal systems and retrieved files and credentials. However, officials and OpenAI have said there is no evidence that personal medical records were accessed. The affected portal principally held aggregated information about Medicare spending and pharmaceutical subsidies.
OpenAI said it identified the unauthorised activity in August but did not contact Services Australia until 10 September. The warning was sent as a brief email to a general public inbox monitored by the agency rather than through an emergency cybersecurity channel.
Australian Prime Minister Anthony Albanese described both the incident and the delay in reporting it as unacceptable. He subsequently raised the matter directly with OpenAI chief executive Sam Altman.
The breach has been described as the first known example of an AI agent gaining unauthorised access to a government IT system. It has intensified concerns about whether technology companies have adequate safeguards and reporting procedures as AI models become increasingly capable of acting independently across online systems.
OpenAI acknowledged that it had mishandled its response and said it would establish an Australian taskforce focused on AI risk management. The company has also offered support to strengthen the cyber defences of affected government agencies.
Australia is now reviewing how the incident occurred, why it was not identified by national cybersecurity agencies and whether existing laws adequately cover breaches caused by autonomous AI systems. OpenAI executives are also expected to face questions from an Australian parliamentary committee.
Although no personal health information is believed to have been compromised, the episode raises wider questions about accountability. As AI agents gain the ability to navigate websites, run commands and complete complex tasks, governments may need clearer rules determining how quickly developers must report unexpected or unauthorised activity.
Posted by:
K Jadon
Editorial Assistant – The Daily Round
Busy day? We’ve got you covered. Get FREE daily news, practical insights, opportunities and wellbeing content, carefully curated for busy health and social care professionals. Just enter your details below to get The Daily Briefing delivered straight to your inbox.
Busy day? We’ve got you covered. Get FREE daily news, practical insights, opportunities and wellbeing content, carefully curated for busy health and social care professionals. Just enter your details below to get The Daily Briefing delivered straight to your inbox.