Anthony Albanese says an artificial intelligence agent developed by OpenAI hacked Medicare in June and the tech giant notified the government earlier this month using an email sent to a “public mailbox”.
Australia’s prime minister made the comments at the UN summit in New York, saying it appeared no personal information had been accessed in the AI breach.
Investigations assisted by the Australian Signals Directorate were ongoing into how the agent had infiltrated Australia’s government-run universal health care system, as well as three others.
They were the Australian Institute of Health and Welfare, the Victorian Department of Health, the New South Wales Bureau of Crime Statistics and Research, and the Medicare statistics reporting service portal of Services Australia.
“This situation is obviously unacceptable,” Albanese said.
“Today, I spoke with the CEO of OpenAI, Sam Altman, to express Australia’s extreme concern about this incident and I also expressed my disappointment that it took the company way too long to inform the government what had occurred.”
Albanese said both the delay and the manner in which OpenAI notified the government was disappointing.
“It took until 10 September before there was any notification at all. And the notification was an email sent to just the public mailbox,” Albanese said.
The email was sent to the public-facing email address publicdisclosures@servicesaustralia.gov.au. That inbox is checked once a day: the email was not read until 11 September.
Services Australia then reported the notification to the Australian Cyber Security Centre on 15 September.
A taskforce has been launched to explore the “legal situation” of the breach.
The NSW premier, Chris Minns, and the Victorian premier, Ben Carroll, on Thursday both said Albanese had informed them the OpenAI breach had affected state websites – NSW’s crime agency and Victoria’s health department.
Minns and Carroll said it did not appear any personal information had been shared in the breach, though investigations were ongoing.
“New South Wales will be working with commonwealth intelligence agencies to get to the bottom of it,” Minns said.
How the hack happened
Albanese said the OpenAI agent had gained unauthorised access into the public-facing Medicare statistics reporting service portal, which is administered by Services Australia.
The portal contains non-sensitive Medicare information relating to data and statistics, such as spending.
Albanese said the agent had accessed “public and non-public files within the portal” and, in order to do this, “engaged in writing files as well to the internal server”.
The deputy prime minister, Richard Marles, said the government learned of the June breach “a couple of weeks ago” and ministers were informed last week.
Marles said the agent was non-human and he called the breach a “very serious incident”.
“What we have seen is unauthorised access in to an Australian government website and that is completely unacceptable and we have made that clear to OpenAI,” he said.
The AI agent had been given “a benign task” of researching health and medical statistics and, in doing so, had approached, as well as the Medicare portal, the three other Australian websites.
“In relation to those three, it interacted in a way that a member of the public might, so it only acted in an authorised way,” Marles told ABC radio on Thursday.
“But in relation to the medical portal of Services Australia, it sought information, information was not given, and then it effectively hacked into that medical portal and got that information anyway.
“It’s that unauthorised access which we are very concerned about. The impact is relatively minor, but the incident is very serious.”
‘Legal situation’ under investigation
Marles said the government had established a taskforce led by the Department of Prime Minister and Cabinet that was working with the Australian Signals Directorate and the AI Safety Institute.
after newsletter promotion
“We will look at what is the legal situation in respect of this and what it means to have gained an unauthorised access, albeit in an unintended way,” the acting prime minister said.
“This is a warning about the fact that artificial intelligence, which is a technology that has huge opportunity to benefit humanity, has to be developed with enormous care. There have to be guardrails and safety measures in place which are way ahead of the capability which is being developed.”
The OpenAI spokesperson Drew Pusateri said the company was conducting an extensive review of “misaligned model activity during training and evaluation” and was “notifying third parties when our review identifies potential impacts to their systems”.
“During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation,” Pusateri said in a statement.
“In the course of that, our models took actions we did not intend.”
He said the review had found aggregate health statistics and internal file names had been accessed but there was “no evidence of patient records being accessed”.
Pusateri said OpenAI was supporting investigations and that its review was ongoing, adding it was committed “sharing what we learn as that work continues”.
Australians should be ‘worried’
Lizzie O’Shea, spokesperson for Digital Rights Watch, said the fact it took three months for OpenAI to tell the government showed that there needed to be “basic rules and standards for tech companies”.
“Artificial intelligence has potential to do some things well, but it also poses huge risks – like hacking systems that store Australians’ sensitive personal data,” O’Shea said on Thursday.
“The question is whether governments are going to let AI and tech companies run wild or whether they, on behalf of ordinary people, will put rules in place for tech companies that will promote accountability and trust.”
The independent senator David Pocock said the OpenAI hack highlighted how slow the government had been to implement AI safeguards in high-risk settings.
Pocock criticised the government’s decision to shelve plans for a National AI Safety Act, and its dilatory approach to legislating new standards.
“We have these companies warning of existential threat and hacking critical government infrastructure and the Labor government’s response is ‘We’ll get to that next year’.
“There is also a big question here around why we aren’t holding these big tech companies liable for this kind of data breach. If it was an Australian who hacked the system they’d likely be heading for jail, yet there’s no accountability for AI companies developing this technology.”
Ed Santo, former human rights commissioner and co-founder of the Human Technology Institute, told ABC radio that Australians ought to “be worried”.
“This is the first time that this has happened in any major way to an Australian database, and it’s one of the most sensitive databases that we have in government.”
OpenAI had “instructed their AI agents to go looking for information about the public health system in Australia. When the AI agents couldn’t easily find that information, they decided to break the law,” Santo said.
Describing the behaviour as “misaligned model activity” was using “a very euphemistic term”, he said.
“If we were in the bricks and mortar world, if an employee of a company went and broke the law, particularly if it broke the criminal law, then that individual would suffer serious legal consequences, but so would their company. And so we need to make sure that that is true also in this era of AI.”

