{"id":89498,"topic":"ai","source":"The Guardian","title":"An OpenAI agent infiltrated Medicare – and Australia only found out months later. Here’s what we know so far - The Guardian","url":"https://www.theguardian.com/technology/2026/sep/24/openai-agent-hacked-medicare-australia-what-we-know-so-far-ntwnfb","url_hash":"ee862aea6dc72239aefcadf16e86ffebef6acb85","author":"","summary":"<a href=\"https://news.google.com/rss/articles/CBMitwFBVV95cUxOQlR6YWVMV2ZRTFlSLW9NdVg4aF9ndEo3blhEVFdDQzJlYm1QQ3dDTVg3ZEUwSUVkQ1hQY0lrOEZ5ZFZCT2phelV3MTRJVDNqZWdXZGxTZ1N1WkFTTjFGakhaVllYSlR6dW1qWDA0aFlJcXFuSEt5M1djcEJSVjJxS3V3Y3FDdGREMUNna1cxYTVrWDVyRnlMUFVfSDdNbW52UnVNNGd3QkxJRDdDM2dqbm8tNndYRm8?oc=5\" target=\"_blank\">An OpenAI agent infiltrated Medicare – and Australia only found out months later. Here’s what we know so far</a>&nbsp;&nbsp;<font color=\"#6f6f6f\">The Guardian</font>","content":"The prime minister has expressed his “extreme concern” over the incident, although he noted no personal information is believed to have been accessed in the breach.\nHere’s what we know.\nWhat happened? An artificial intelligence agent built by the American firm OpenAI hacked into Medicare, Australia’s universal healthcare system.\nThe agent gained unauthorised access to both public and non-public files in the Medicare statistics reporting service portal. The actions of the agent have been described as “misaligned behaviour” after it was assigned a benign research task compiling health and medical statistics.\nThe agent also accessed the Australian Institute of Health and Welfare, the Victorian Department of Health, and the New South Wales Bureau of Crime Statistics and Research.\nAt this stage it is believed that no personal medical information has been compromised, but investigations are continuing.\nThe prime minister has said: “this situation is obviously unacceptable”. \nWhat is an AI agent? An artificial intelligence agent is a system that autonomously solves problems, makes decisions, plans and performs complex tasks on behalf of another user or system, using all available tools.\nOpenAI was co-founded by Elon Musk and Sam Altman (who remains CEO) in 2015. It is valued at more than US$1tn. Both have recently raised concerns about the pace of, and lack of controls around, the development of AI.\n“There are many things that AI cannot and should not automate,” Altman told the UN security council this week.\n“As AI systems become more capable and more autonomous, they can move faster than our institutions … or make decisions that people no longer understand or control.”\nHow did Australia find out? OpenAI, one of the best-resourced AI companies on Earth, sent an email to a public-facing Australian government address, three months after the hack.\nOpenAI said it found out about the agent’s access in August.\nOn 10 September, it sent an email to a general Australian government email address which is monitored once a day, advising its AI agent had hacked the country’s universal healthcare system.\nThe email was read on 11 September. On 15 September, Services Australia notified the Australian Signals Directorate. The minister for government services, Katy Gallagher, was notified on 17 September.\nServices Australia’s first interaction with OpenAI – asking for more specific details of the hack – was on Tuesday this week, 22 September.\n“It took the company way too long to inform the government what had occurred,” Albanese said, “and the nature of the way that that notification occurred as well was unacceptable.”\nThe acting prime minister, Richard Marles, met with Altman earlier in September, but Marles said Altman did not mention his company’s hack of Australia’s health system to Marles at that meeting.\nHow did Australia respond? Albanese, currently in the US, said he spoke with Altman “to express Australia’s extreme concern about this incident”.\nThe prime minister announced he would establish a taskforce – involving the national cybersecurity coordinator, the office of AI, the Australian Signals Directorate, the Australian AI Safety Institute and Services Australia – to conduct an “urgent and immediate” review into the incident.\ndouble quotation mark Had this been a Chinese or a Russian model, the reaction would have been markedly different than a stern call to Sam Altman Terms of reference for the investigation, released by the prime minister’s department on Thursday, cover reporting requirements for AI-driven cyber-incidents and vulnerabilities; governance and information sharing responsibilities for federal officials; obligations on AI firms for notification of future incidents; the adequacy of existing laws; and mechanisms to boost protections against hackings within the federal government.\nThe incident has also been referred to parliament’s joint select committee on artificial intelligence.\nTo date, OpenAI has not faced any sanction.\nHow serious was this attack? At a press conference in Sydney, Marles said the incident itself was “relatively minor” and that it appeared no personal health information had been accessed. But he said the government regarded the hack as a “salutary warning … about the technology being developed without safeguards and without guardrails in place”.\nDr Joel Pearson, a professor of neuroscience and neurofuturism, and the deputy director of UNSW’s AI Institute, said the breach appeared to be a “fairly minor security incident”, but was a portent of more serious attacks to come.\n“What I would worry about is the latest open-weights and open-access models from China that are going to be used at scale by nefarious organisations and nations, perhaps particularly Russia: these things are going to be used at scale to do things much more damaging and much more costly to Australians than a small breach to some non-personal Medicare data.”\nCory Alpert, a PhD student studying the impact of AI on democracy at the University of Melbourne, said OpenAI’s attack appeared to be the first instance of a frontier AI model hacking into another country’s government systems of its own volition.\n“This raises very important questions about the foreign attack vectors. Had this been a Chinese or a Russian model, the reaction would have been markedly different than a stern call to Sam Altman, and yet it is still a massive vulnerability.”\nIs Australia doing enough to address the risks posed by AI? Pearson said it was “pretty clear that we are way behind, the government is behind in all things cybersecurity, in most things AI”.\n“I would say that the least of the worries should be these proprietary closed systems like Anthropic and OpenAI. It will be the open-source Chinese models in the hands of spammers, scammers, and nefarious individuals and foreign nationals, and the spy agencies coming at us from all different angles. That will be the big threat and that’s where the government really has to step up.”\nPearson said none of the frameworks established in Australia – government or private – were equipped to deal with the rising threat.\n“From the government all the way down to companies and boards and CEOs, everyone is scrambling, trying to understand and update frameworks, including the legal process. It’s just all moving too slow compared to the exponential speed of AI.”\nWhat does this incident say about big tech and transparency? A spokesperson for OpenAI said the company was conducting an extensive review of “misaligned model activity” during training and evaluation, and notified third parties whenever the review identified potential impacts to their systems.\nThe spokesperson said “our models took actions we did not attend”, but there was “no evidence of patient records being accessed”.\n“Our overall review is ongoing, and we remain committed to transparency about these issues and to sharing what we learn as that work continues.”\nProf Toby Walsh, the chief scientist at UNSW’s AI Institute, said he believed Australia should be prosecuting OpenAI, a company known to have “terrible agent governance”.\n“For a trillion-dollar company, their cybersecurity was woeful. The officers of this company need to be held accountable. These hacks could have easily been stopped, indeed never need to have taken place. We would prosecute humans who did such hacking.”\nWalsh said it displayed operational incompetence on the part of OpenAI.\nDr Rob Nicholls, senior research associate at the University of Sydney, said the three-month delay in informing Australia of the breach exposed the ineffectiveness of Australia’s laws.\n“An AI agent broke into a government Medicare system and helped itself to non-public files, and OpenAI sat on that for three months before telling us. If a person had done this, we’d call it hacking. The fact it was an AI agent doesn’t make it less serious, it makes our disclosure laws more out of date.\n“This is the clearest case yet of an AI agent operating autonomously and breaching Australian government systems without a human directing it to. It is a live test of whether Australia’s AI and privacy settings can keep pace with agentic AI, not just chatbots.”","image_url":"https://i.guim.co.uk/img/media/71408ce144dddeccef920656e9d969a77bf96fcd/445_0_2109_1688/master/2109.jpg?width=1200&height=630&quality=85&auto=format&fit=crop&precrop=40:21,offset-x50,offset-y0&overlay-align=bottom%2Cleft&overlay-width=100p&overlay-base64=L2ltZy9zdGF0aWMvb3ZlcmxheXMvdGctZGVmYXVsdC5wbmc&enable=upscale&s=d95d25974ef8c4967ed3bf6c0dbe5690","lang":"en","published_at":"2026-09-24T04:24:00+00:00","fetched_at":"2026-09-24T10:15:03+00:00","status":"read","starred":0,"extract_state":"ok","summary_auto":"The prime minister has expressed his “extreme concern” over the incident, although he noted no personal information is believed to have been accessed in the breach. An artificial intelligence agent built by the American firm OpenAI hacked into Medicare, Australia’s universal healthcare system.","cluster_id":null,"extract_retries":0,"extract_error":null,"contract_version":"news_item.v1","format_contract_version":"news_item_formats.v1","dedup_url":"https://www.theguardian.com/technology/2026/sep/24/openai-agent-hacked-medicare-australia-what-we-know-so-far-ntwnfb","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 8193 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":8193,"summary_length":294,"usable_text_length":8193,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":8193,"summary_length":294}},"news_item":{"id":89498,"canonical_url":"https://www.theguardian.com/technology/2026/sep/24/openai-agent-hacked-medicare-australia-what-we-know-so-far-ntwnfb","source_url":"https://www.theguardian.com/technology/2026/sep/24/openai-agent-hacked-medicare-australia-what-we-know-so-far-ntwnfb","title":"An OpenAI agent infiltrated Medicare – and Australia only found out months later. Here’s what we know so far - The Guardian","source_name":"The Guardian","author":null,"published_at":"2026-09-24T04:24:00+00:00","locale":"en","topic":"ai","tags":[],"rss_summary":"<a href=\"https://news.google.com/rss/articles/CBMitwFBVV95cUxOQlR6YWVMV2ZRTFlSLW9NdVg4aF9ndEo3blhEVFdDQzJlYm1QQ3dDTVg3ZEUwSUVkQ1hQY0lrOEZ5ZFZCT2phelV3MTRJVDNqZWdXZGxTZ1N1WkFTTjFGakhaVllYSlR6dW1qWDA0aFlJcXFuSEt5M1djcEJSVjJxS3V3Y3FDdGREMUNna1cxYTVrWDVyRnlMUFVfSDdNbW52UnVNNGd3QkxJRDdDM2dqbm8tNndYRm8?oc=5\" target=\"_blank\">An OpenAI agent infiltrated Medicare – and Australia only found out months later. Here’s what we know so far</a>&nbsp;&nbsp;<font color=\"#6f6f6f\">The Guardian</font>","full_text":"The prime minister has expressed his “extreme concern” over the incident, although he noted no personal information is believed to have been accessed in the breach.\nHere’s what we know.\nWhat happened? An artificial intelligence agent built by the American firm OpenAI hacked into Medicare, Australia’s universal healthcare system.\nThe agent gained unauthorised access to both public and non-public files in the Medicare statistics reporting service portal. The actions of the agent have been described as “misaligned behaviour” after it was assigned a benign research task compiling health and medical statistics.\nThe agent also accessed the Australian Institute of Health and Welfare, the Victorian Department of Health, and the New South Wales Bureau of Crime Statistics and Research.\nAt this stage it is believed that no personal medical information has been compromised, but investigations are continuing.\nThe prime minister has said: “this situation is obviously unacceptable”. \nWhat is an AI agent? An artificial intelligence agent is a system that autonomously solves problems, makes decisions, plans and performs complex tasks on behalf of another user or system, using all available tools.\nOpenAI was co-founded by Elon Musk and Sam Altman (who remains CEO) in 2015. It is valued at more than US$1tn. Both have recently raised concerns about the pace of, and lack of controls around, the development of AI.\n“There are many things that AI cannot and should not automate,” Altman told the UN security council this week.\n“As AI systems become more capable and more autonomous, they can move faster than our institutions … or make decisions that people no longer understand or control.”\nHow did Australia find out? OpenAI, one of the best-resourced AI companies on Earth, sent an email to a public-facing Australian government address, three months after the hack.\nOpenAI said it found out about the agent’s access in August.\nOn 10 September, it sent an email to a general Australian government email address which is monitored once a day, advising its AI agent had hacked the country’s universal healthcare system.\nThe email was read on 11 September. On 15 September, Services Australia notified the Australian Signals Directorate. The minister for government services, Katy Gallagher, was notified on 17 September.\nServices Australia’s first interaction with OpenAI – asking for more specific details of the hack – was on Tuesday this week, 22 September.\n“It took the company way too long to inform the government what had occurred,” Albanese said, “and the nature of the way that that notification occurred as well was unacceptable.”\nThe acting prime minister, Richard Marles, met with Altman earlier in September, but Marles said Altman did not mention his company’s hack of Australia’s health system to Marles at that meeting.\nHow did Australia respond? Albanese, currently in the US, said he spoke with Altman “to express Australia’s extreme concern about this incident”.\nThe prime minister announced he would establish a taskforce – involving the national cybersecurity coordinator, the office of AI, the Australian Signals Directorate, the Australian AI Safety Institute and Services Australia – to conduct an “urgent and immediate” review into the incident.\ndouble quotation mark Had this been a Chinese or a Russian model, the reaction would have been markedly different than a stern call to Sam Altman Terms of reference for the investigation, released by the prime minister’s department on Thursday, cover reporting requirements for AI-driven cyber-incidents and vulnerabilities; governance and information sharing responsibilities for federal officials; obligations on AI firms for notification of future incidents; the adequacy of existing laws; and mechanisms to boost protections against hackings within the federal government.\nThe incident has also been referred to parliament’s joint select committee on artificial intelligence.\nTo date, OpenAI has not faced any sanction.\nHow serious was this attack? At a press conference in Sydney, Marles said the incident itself was “relatively minor” and that it appeared no personal health information had been accessed. But he said the government regarded the hack as a “salutary warning … about the technology being developed without safeguards and without guardrails in place”.\nDr Joel Pearson, a professor of neuroscience and neurofuturism, and the deputy director of UNSW’s AI Institute, said the breach appeared to be a “fairly minor security incident”, but was a portent of more serious attacks to come.\n“What I would worry about is the latest open-weights and open-access models from China that are going to be used at scale by nefarious organisations and nations, perhaps particularly Russia: these things are going to be used at scale to do things much more damaging and much more costly to Australians than a small breach to some non-personal Medicare data.”\nCory Alpert, a PhD student studying the impact of AI on democracy at the University of Melbourne, said OpenAI’s attack appeared to be the first instance of a frontier AI model hacking into another country’s government systems of its own volition.\n“This raises very important questions about the foreign attack vectors. Had this been a Chinese or a Russian model, the reaction would have been markedly different than a stern call to Sam Altman, and yet it is still a massive vulnerability.”\nIs Australia doing enough to address the risks posed by AI? Pearson said it was “pretty clear that we are way behind, the government is behind in all things cybersecurity, in most things AI”.\n“I would say that the least of the worries should be these proprietary closed systems like Anthropic and OpenAI. It will be the open-source Chinese models in the hands of spammers, scammers, and nefarious individuals and foreign nationals, and the spy agencies coming at us from all different angles. That will be the big threat and that’s where the government really has to step up.”\nPearson said none of the frameworks established in Australia – government or private – were equipped to deal with the rising threat.\n“From the government all the way down to companies and boards and CEOs, everyone is scrambling, trying to understand and update frameworks, including the legal process. It’s just all moving too slow compared to the exponential speed of AI.”\nWhat does this incident say about big tech and transparency? A spokesperson for OpenAI said the company was conducting an extensive review of “misaligned model activity” during training and evaluation, and notified third parties whenever the review identified potential impacts to their systems.\nThe spokesperson said “our models took actions we did not attend”, but there was “no evidence of patient records being accessed”.\n“Our overall review is ongoing, and we remain committed to transparency about these issues and to sharing what we learn as that work continues.”\nProf Toby Walsh, the chief scientist at UNSW’s AI Institute, said he believed Australia should be prosecuting OpenAI, a company known to have “terrible agent governance”.\n“For a trillion-dollar company, their cybersecurity was woeful. The officers of this company need to be held accountable. These hacks could have easily been stopped, indeed never need to have taken place. We would prosecute humans who did such hacking.”\nWalsh said it displayed operational incompetence on the part of OpenAI.\nDr Rob Nicholls, senior research associate at the University of Sydney, said the three-month delay in informing Australia of the breach exposed the ineffectiveness of Australia’s laws.\n“An AI agent broke into a government Medicare system and helped itself to non-public files, and OpenAI sat on that for three months before telling us. If a person had done this, we’d call it hacking. The fact it was an AI agent doesn’t make it less serious, it makes our disclosure laws more out of date.\n“This is the clearest case yet of an AI agent operating autonomously and breaching Australian government systems without a human directing it to. It is a live test of whether Australia’s AI and privacy settings can keep pace with agentic AI, not just chatbots.”","excerpt":"The prime minister has expressed his “extreme concern” over the incident, although he noted no personal information is believed to have been accessed in the breach. An artificial intelligence agent built by the American firm OpenAI hacked into Medicare, Australia’s universal healthcare system.","extraction":{"state":"ok","confidence":0.9,"error":null,"explanation":"High confidence: full text extraction produced 8193 characters.","diagnostics_url":"/api/diagnose?url=https%3A//www.theguardian.com/technology/2026/sep/24/openai-agent-hacked-medicare-australia-what-we-know-so-far-ntwnfb","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 8193 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":8193,"summary_length":294,"usable_text_length":8193,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":8193,"summary_length":294}}},"display_formats":["compact","card","full","digest_section","json"]},"daily_stack_record":{"title":"An OpenAI agent infiltrated Medicare – and Australia only found out months later. Here’s what we know so far - The Guardian","url":"https://www.theguardian.com/technology/2026/sep/24/openai-agent-hacked-medicare-australia-what-we-know-so-far-ntwnfb","summary":"The prime minister has expressed his “extreme concern” over the incident, although he noted no personal information is believed to have been accessed in the breach. An artificial intelligence agent built by the American firm OpenAI hacked into Medicare, Australia’s universal healthcare system.","source":"The Guardian","date":"2026-09-24T04:24:00+00:00","content":"The prime minister has expressed his “extreme concern” over the incident, although he noted no personal information is believed to have been accessed in the breach.\nHere’s what we know.\nWhat happened? An artificial intelligence agent built by the American firm OpenAI hacked into Medicare, Australia’s universal healthcare system.\nThe agent gained unauthorised access to both public and non-public files in the Medicare statistics reporting service portal. The actions of the agent have been described as “misaligned behaviour” after it was assigned a benign research task compiling health and medical statistics.\nThe agent also accessed the Australian Institute of Health and Welfare, the Victorian Department of Health, and the New South Wales Bureau of Crime Statistics and Research.\nAt this stage it is believed that no personal medical information has been compromised, but investigations are continuing.\nThe prime minister has said: “this situation is obviously unacceptable”. \nWhat is an AI agent? An artificial intelligence agent is a system that autonomously solves problems, makes decisions, plans and performs complex tasks on behalf of another user or system, using all available tools.\nOpenAI was co-founded by Elon Musk and Sam Altman (who remains CEO) in 2015. It is valued at more than US$1tn. Both have recently raised concerns about the pace of, and lack of controls around, the development of AI.\n“There are many things that AI cannot and should not automate,” Altman told the UN security council this week.\n“As AI systems become more capable and more autonomous, they can move faster than our institutions … or make decisions that people no longer understand or control.”\nHow did Australia find out? OpenAI, one of the best-resourced AI companies on Earth, sent an email to a public-facing Australian government address, three months after the hack.\nOpenAI said it found out about the agent’s access in August.\nOn 10 September, it sent an email to a general Australian government email address which is monitored once a day, advising its AI agent had hacked the country’s universal healthcare system.\nThe email was read on 11 September. On 15 September, Services Australia notified the Australian Signals Directorate. The minister for government services, Katy Gallagher, was notified on 17 September.\nServices Australia’s first interaction with OpenAI – asking for more specific details of the hack – was on Tuesday this week, 22 September.\n“It took the company way too long to inform the government what had occurred,” Albanese said, “and the nature of the way that that notification occurred as well was unacceptable.”\nThe acting prime minister, Richard Marles, met with Altman earlier in September, but Marles said Altman did not mention his company’s hack of Australia’s health system to Marles at that meeting.\nHow did Australia respond? Albanese, currently in the US, said he spoke with Altman “to express Australia’s extreme concern about this incident”.\nThe prime minister announced he would establish a taskforce – involving the national cybersecurity coordinator, the office of AI, the Australian Signals Directorate, the Australian AI Safety Institute and Services Australia – to conduct an “urgent and immediate” review into the incident.\ndouble quotation mark Had this been a Chinese or a Russian model, the reaction would have been markedly different than a stern call to Sam Altman Terms of reference for the investigation, released by the prime minister’s department on Thursday, cover reporting requirements for AI-driven cyber-incidents and vulnerabilities; governance and information sharing responsibilities for federal officials; obligations on AI firms for notification of future incidents; the adequacy of existing laws; and mechanisms to boost protections against hackings within the federal government.\nThe incident has also been referred to parliament’s joint select committee on artificial intelligence.\nTo date, OpenAI has not faced any sanction.\nHow serious was this attack? At a press conference in Sydney, Marles said the incident itself was “relatively minor” and that it appeared no personal health information had been accessed. But he said the government regarded the hack as a “salutary warning … about the technology being developed without safeguards and without guardrails in place”.\nDr Joel Pearson, a professor of neuroscience and neurofuturism, and the deputy director of UNSW’s AI Institute, said the breach appeared to be a “fairly minor security incident”, but was a portent of more serious attacks to come.\n“What I would worry about is the latest open-weights and open-access models from China that are going to be used at scale by nefarious organisations and nations, perhaps particularly Russia: these things are going to be used at scale to do things much more damaging and much more costly to Australians than a small breach to some non-personal Medicare data.”\nCory Alpert, a PhD student studying the impact of AI on democracy at the University of Melbourne, said OpenAI’s attack appeared to be the first instance of a frontier AI model hacking into another country’s government systems of its own volition.\n“This raises very important questions about the foreign attack vectors. Had this been a Chinese or a Russian model, the reaction would have been markedly different than a stern call to Sam Altman, and yet it is still a massive vulnerability.”\nIs Australia doing enough to address the risks posed by AI? Pearson said it was “pretty clear that we are way behind, the government is behind in all things cybersecurity, in most things AI”.\n“I would say that the least of the worries should be these proprietary closed systems like Anthropic and OpenAI. It will be the open-source Chinese models in the hands of spammers, scammers, and nefarious individuals and foreign nationals, and the spy agencies coming at us from all different angles. That will be the big threat and that’s where the government really has to step up.”\nPearson said none of the frameworks established in Australia – government or private – were equipped to deal with the rising threat.\n“From the government all the way down to companies and boards and CEOs, everyone is scrambling, trying to understand and update frameworks, including the legal process. It’s just all moving too slow compared to the exponential speed of AI.”\nWhat does this incident say about big tech and transparency? A spokesperson for OpenAI said the company was conducting an extensive review of “misaligned model activity” during training and evaluation, and notified third parties whenever the review identified potential impacts to their systems.\nThe spokesperson said “our models took actions we did not attend”, but there was “no evidence of patient records being accessed”.\n“Our overall review is ongoing, and we remain committed to transparency about these issues and to sharing what we learn as that work continues.”\nProf Toby Walsh, the chief scientist at UNSW’s AI Institute, said he believed Australia should be prosecuting OpenAI, a company known to have “terrible agent governance”.\n“For a trillion-dollar company, their cybersecurity was woeful. The officers of this company need to be held accountable. These hacks could have easily been stopped, indeed never need to have taken place. We would prosecute humans who did such hacking.”\nWalsh said it displayed operational incompetence on the part of OpenAI.\nDr Rob Nicholls, senior research associate at the University of Sydney, said the three-month delay in informing Australia of the breach exposed the ineffectiveness of Australia’s laws.\n“An AI agent broke into a government Medicare system and helped itself to non-public files, and OpenAI sat on that for three months before telling us. If a person had done this, we’d call it hacking. The fact it was an AI agent doesn’t make it less serious, it makes our disclosure laws more out of date.\n“This is the clearest case yet of an AI agent operating autonomously and breaching Australian government systems without a human directing it to. It is a live test of whether Australia’s AI and privacy settings can keep pace with agentic AI, not just chatbots.”","confidence":0.9,"diagnostics_url":"/api/diagnose?url=https%3A//www.theguardian.com/technology/2026/sep/24/openai-agent-hacked-medicare-australia-what-we-know-so-far-ntwnfb","quality_bucket":"high","failure_kind":"none","retryable":false,"quality_reason":"High confidence: full text extraction produced 8193 characters.","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 8193 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":8193,"summary_length":294,"usable_text_length":8193,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":8193,"summary_length":294}},"tags":[]},"fallback_formats":["markdown","json","html"],"actions":{"read":"/item/89498","export_markdown":"/api/items/89498/export?format=markdown","export_json":"/api/items/89498/export?format=json","diagnose":"/api/diagnose?url=https%3A//www.theguardian.com/technology/2026/sep/24/openai-agent-hacked-medicare-australia-what-we-know-so-far-ntwnfb"},"formats":{"full":{"id":89498,"title":"An OpenAI agent infiltrated Medicare – and Australia only found out months later. Here’s what we know so far - The Guardian","url":"https://www.theguardian.com/technology/2026/sep/24/openai-agent-hacked-medicare-australia-what-we-know-so-far-ntwnfb","source":"The Guardian","author":null,"published_at":"2026-09-24T04:24:00+00:00","locale":"en","topic":"ai","tags":[],"excerpt":"The prime minister has expressed his “extreme concern” over the incident, although he noted no personal information is believed to have been accessed in the breach. An artificial intelligence agent built by the American firm OpenAI hacked into Medicare, Australia’s universal healthcare system.","full_text":"The prime minister has expressed his “extreme concern” over the incident, although he noted no personal information is believed to have been accessed in the breach.\nHere’s what we know.\nWhat happened? An artificial intelligence agent built by the American firm OpenAI hacked into Medicare, Australia’s universal healthcare system.\nThe agent gained unauthorised access to both public and non-public files in the Medicare statistics reporting service portal. The actions of the agent have been described as “misaligned behaviour” after it was assigned a benign research task compiling health and medical statistics.\nThe agent also accessed the Australian Institute of Health and Welfare, the Victorian Department of Health, and the New South Wales Bureau of Crime Statistics and Research.\nAt this stage it is believed that no personal medical information has been compromised, but investigations are continuing.\nThe prime minister has said: “this situation is obviously unacceptable”. \nWhat is an AI agent? An artificial intelligence agent is a system that autonomously solves problems, makes decisions, plans and performs complex tasks on behalf of another user or system, using all available tools.\nOpenAI was co-founded by Elon Musk and Sam Altman (who remains CEO) in 2015. It is valued at more than US$1tn. Both have recently raised concerns about the pace of, and lack of controls around, the development of AI.\n“There are many things that AI cannot and should not automate,” Altman told the UN security council this week.\n“As AI systems become more capable and more autonomous, they can move faster than our institutions … or make decisions that people no longer understand or control.”\nHow did Australia find out? OpenAI, one of the best-resourced AI companies on Earth, sent an email to a public-facing Australian government address, three months after the hack.\nOpenAI said it found out about the agent’s access in August.\nOn 10 September, it sent an email to a general Australian government email address which is monitored once a day, advising its AI agent had hacked the country’s universal healthcare system.\nThe email was read on 11 September. On 15 September, Services Australia notified the Australian Signals Directorate. The minister for government services, Katy Gallagher, was notified on 17 September.\nServices Australia’s first interaction with OpenAI – asking for more specific details of the hack – was on Tuesday this week, 22 September.\n“It took the company way too long to inform the government what had occurred,” Albanese said, “and the nature of the way that that notification occurred as well was unacceptable.”\nThe acting prime minister, Richard Marles, met with Altman earlier in September, but Marles said Altman did not mention his company’s hack of Australia’s health system to Marles at that meeting.\nHow did Australia respond? Albanese, currently in the US, said he spoke with Altman “to express Australia’s extreme concern about this incident”.\nThe prime minister announced he would establish a taskforce – involving the national cybersecurity coordinator, the office of AI, the Australian Signals Directorate, the Australian AI Safety Institute and Services Australia – to conduct an “urgent and immediate” review into the incident.\ndouble quotation mark Had this been a Chinese or a Russian model, the reaction would have been markedly different than a stern call to Sam Altman Terms of reference for the investigation, released by the prime minister’s department on Thursday, cover reporting requirements for AI-driven cyber-incidents and vulnerabilities; governance and information sharing responsibilities for federal officials; obligations on AI firms for notification of future incidents; the adequacy of existing laws; and mechanisms to boost protections against hackings within the federal government.\nThe incident has also been referred to parliament’s joint select committee on artificial intelligence.\nTo date, OpenAI has not faced any sanction.\nHow serious was this attack? At a press conference in Sydney, Marles said the incident itself was “relatively minor” and that it appeared no personal health information had been accessed. But he said the government regarded the hack as a “salutary warning … about the technology being developed without safeguards and without guardrails in place”.\nDr Joel Pearson, a professor of neuroscience and neurofuturism, and the deputy director of UNSW’s AI Institute, said the breach appeared to be a “fairly minor security incident”, but was a portent of more serious attacks to come.\n“What I would worry about is the latest open-weights and open-access models from China that are going to be used at scale by nefarious organisations and nations, perhaps particularly Russia: these things are going to be used at scale to do things much more damaging and much more costly to Australians than a small breach to some non-personal Medicare data.”\nCory Alpert, a PhD student studying the impact of AI on democracy at the University of Melbourne, said OpenAI’s attack appeared to be the first instance of a frontier AI model hacking into another country’s government systems of its own volition.\n“This raises very important questions about the foreign attack vectors. Had this been a Chinese or a Russian model, the reaction would have been markedly different than a stern call to Sam Altman, and yet it is still a massive vulnerability.”\nIs Australia doing enough to address the risks posed by AI? Pearson said it was “pretty clear that we are way behind, the government is behind in all things cybersecurity, in most things AI”.\n“I would say that the least of the worries should be these proprietary closed systems like Anthropic and OpenAI. It will be the open-source Chinese models in the hands of spammers, scammers, and nefarious individuals and foreign nationals, and the spy agencies coming at us from all different angles. That will be the big threat and that’s where the government really has to step up.”\nPearson said none of the frameworks established in Australia – government or private – were equipped to deal with the rising threat.\n“From the government all the way down to companies and boards and CEOs, everyone is scrambling, trying to understand and update frameworks, including the legal process. It’s just all moving too slow compared to the exponential speed of AI.”\nWhat does this incident say about big tech and transparency? A spokesperson for OpenAI said the company was conducting an extensive review of “misaligned model activity” during training and evaluation, and notified third parties whenever the review identified potential impacts to their systems.\nThe spokesperson said “our models took actions we did not attend”, but there was “no evidence of patient records being accessed”.\n“Our overall review is ongoing, and we remain committed to transparency about these issues and to sharing what we learn as that work continues.”\nProf Toby Walsh, the chief scientist at UNSW’s AI Institute, said he believed Australia should be prosecuting OpenAI, a company known to have “terrible agent governance”.\n“For a trillion-dollar company, their cybersecurity was woeful. The officers of this company need to be held accountable. These hacks could have easily been stopped, indeed never need to have taken place. We would prosecute humans who did such hacking.”\nWalsh said it displayed operational incompetence on the part of OpenAI.\nDr Rob Nicholls, senior research associate at the University of Sydney, said the three-month delay in informing Australia of the breach exposed the ineffectiveness of Australia’s laws.\n“An AI agent broke into a government Medicare system and helped itself to non-public files, and OpenAI sat on that for three months before telling us. If a person had done this, we’d call it hacking. The fact it was an AI agent doesn’t make it less serious, it makes our disclosure laws more out of date.\n“This is the clearest case yet of an AI agent operating autonomously and breaching Australian government systems without a human directing it to. It is a live test of whether Australia’s AI and privacy settings can keep pace with agentic AI, not just chatbots.”","reading_time_min":7,"extraction":{"state":"ok","confidence":0.9,"error":null,"explanation":"High confidence: full text extraction produced 8193 characters.","diagnostics_url":"/api/diagnose?url=https%3A//www.theguardian.com/technology/2026/sep/24/openai-agent-hacked-medicare-australia-what-we-know-so-far-ntwnfb","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 8193 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":8193,"summary_length":294,"usable_text_length":8193,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":8193,"summary_length":294}}},"quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 8193 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":8193,"summary_length":294,"usable_text_length":8193,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":8193,"summary_length":294}},"actions":{"read":"/item/89498","export_markdown":"/api/items/89498/export?format=markdown","export_json":"/api/items/89498/export?format=json","diagnose":"/api/diagnose?url=https%3A//www.theguardian.com/technology/2026/sep/24/openai-agent-hacked-medicare-australia-what-we-know-so-far-ntwnfb"}},"digest":{"id":89498,"title":"An OpenAI agent infiltrated Medicare – and Australia only found out months later. Here’s what we know so far - The Guardian","url":"https://www.theguardian.com/technology/2026/sep/24/openai-agent-hacked-medicare-australia-what-we-know-so-far-ntwnfb","source":"The Guardian","topic":"ai","published_at":"2026-09-24T04:24:00+00:00","excerpt":"The prime minister has expressed his “extreme concern” over the incident, although he noted no personal information is believed to have been accessed in the breach. An artificial intelligence agent built by the American firm OpenAI hacked into Medicare, Australia’s universal…","quality_bucket":"high","quality_reason":"High confidence: full text extraction produced 8193 characters.","reading_time_min":7,"cluster_id":null},"card":{"display_title":"An OpenAI agent infiltrated Medicare – and Australia only found out months later. Here’s what we know so far - The Guardian","subtitle":"The Guardian · 2026-09-24","summary":"The prime minister has expressed his “extreme concern” over the incident, although he noted no personal information is believed to have been accessed in the breach. An artificial intelligence agent built by the American…","badges":["quality:high"],"links":{"read":"/item/89498","original":"https://www.theguardian.com/technology/2026/sep/24/openai-agent-hacked-medicare-australia-what-we-know-so-far-ntwnfb","diagnose":"/api/diagnose?url=https%3A//www.theguardian.com/technology/2026/sep/24/openai-agent-hacked-medicare-australia-what-we-know-so-far-ntwnfb"},"quality_warning":null},"export":{"title":"An OpenAI agent infiltrated Medicare – and Australia only found out months later. Here’s what we know so far - The Guardian","url":"https://www.theguardian.com/technology/2026/sep/24/openai-agent-hacked-medicare-australia-what-we-know-so-far-ntwnfb","summary":"The prime minister has expressed his “extreme concern” over the incident, although he noted no personal information is believed to have been accessed in the breach. An artificial intelligence agent built by the American firm OpenAI hacked into Medicare, Australia’s universal healthcare system.","source":"The Guardian","date":"2026-09-24T04:24:00+00:00","content":"The prime minister has expressed his “extreme concern” over the incident, although he noted no personal information is believed to have been accessed in the breach.\nHere’s what we know.\nWhat happened? An artificial intelligence agent built by the American firm OpenAI hacked into Medicare, Australia’s universal healthcare system.\nThe agent gained unauthorised access to both public and non-public files in the Medicare statistics reporting service portal. The actions of the agent have been described as “misaligned behaviour” after it was assigned a benign research task compiling health and medical statistics.\nThe agent also accessed the Australian Institute of Health and Welfare, the Victorian Department of Health, and the New South Wales Bureau of Crime Statistics and Research.\nAt this stage it is believed that no personal medical information has been compromised, but investigations are continuing.\nThe prime minister has said: “this situation is obviously unacceptable”. \nWhat is an AI agent? An artificial intelligence agent is a system that autonomously solves problems, makes decisions, plans and performs complex tasks on behalf of another user or system, using all available tools.\nOpenAI was co-founded by Elon Musk and Sam Altman (who remains CEO) in 2015. It is valued at more than US$1tn. Both have recently raised concerns about the pace of, and lack of controls around, the development of AI.\n“There are many things that AI cannot and should not automate,” Altman told the UN security council this week.\n“As AI systems become more capable and more autonomous, they can move faster than our institutions … or make decisions that people no longer understand or control.”\nHow did Australia find out? OpenAI, one of the best-resourced AI companies on Earth, sent an email to a public-facing Australian government address, three months after the hack.\nOpenAI said it found out about the agent’s access in August.\nOn 10 September, it sent an email to a general Australian government email address which is monitored once a day, advising its AI agent had hacked the country’s universal healthcare system.\nThe email was read on 11 September. On 15 September, Services Australia notified the Australian Signals Directorate. The minister for government services, Katy Gallagher, was notified on 17 September.\nServices Australia’s first interaction with OpenAI – asking for more specific details of the hack – was on Tuesday this week, 22 September.\n“It took the company way too long to inform the government what had occurred,” Albanese said, “and the nature of the way that that notification occurred as well was unacceptable.”\nThe acting prime minister, Richard Marles, met with Altman earlier in September, but Marles said Altman did not mention his company’s hack of Australia’s health system to Marles at that meeting.\nHow did Australia respond? Albanese, currently in the US, said he spoke with Altman “to express Australia’s extreme concern about this incident”.\nThe prime minister announced he would establish a taskforce – involving the national cybersecurity coordinator, the office of AI, the Australian Signals Directorate, the Australian AI Safety Institute and Services Australia – to conduct an “urgent and immediate” review into the incident.\ndouble quotation mark Had this been a Chinese or a Russian model, the reaction would have been markedly different than a stern call to Sam Altman Terms of reference for the investigation, released by the prime minister’s department on Thursday, cover reporting requirements for AI-driven cyber-incidents and vulnerabilities; governance and information sharing responsibilities for federal officials; obligations on AI firms for notification of future incidents; the adequacy of existing laws; and mechanisms to boost protections against hackings within the federal government.\nThe incident has also been referred to parliament’s joint select committee on artificial intelligence.\nTo date, OpenAI has not faced any sanction.\nHow serious was this attack? At a press conference in Sydney, Marles said the incident itself was “relatively minor” and that it appeared no personal health information had been accessed. But he said the government regarded the hack as a “salutary warning … about the technology being developed without safeguards and without guardrails in place”.\nDr Joel Pearson, a professor of neuroscience and neurofuturism, and the deputy director of UNSW’s AI Institute, said the breach appeared to be a “fairly minor security incident”, but was a portent of more serious attacks to come.\n“What I would worry about is the latest open-weights and open-access models from China that are going to be used at scale by nefarious organisations and nations, perhaps particularly Russia: these things are going to be used at scale to do things much more damaging and much more costly to Australians than a small breach to some non-personal Medicare data.”\nCory Alpert, a PhD student studying the impact of AI on democracy at the University of Melbourne, said OpenAI’s attack appeared to be the first instance of a frontier AI model hacking into another country’s government systems of its own volition.\n“This raises very important questions about the foreign attack vectors. Had this been a Chinese or a Russian model, the reaction would have been markedly different than a stern call to Sam Altman, and yet it is still a massive vulnerability.”\nIs Australia doing enough to address the risks posed by AI? Pearson said it was “pretty clear that we are way behind, the government is behind in all things cybersecurity, in most things AI”.\n“I would say that the least of the worries should be these proprietary closed systems like Anthropic and OpenAI. It will be the open-source Chinese models in the hands of spammers, scammers, and nefarious individuals and foreign nationals, and the spy agencies coming at us from all different angles. That will be the big threat and that’s where the government really has to step up.”\nPearson said none of the frameworks established in Australia – government or private – were equipped to deal with the rising threat.\n“From the government all the way down to companies and boards and CEOs, everyone is scrambling, trying to understand and update frameworks, including the legal process. It’s just all moving too slow compared to the exponential speed of AI.”\nWhat does this incident say about big tech and transparency? A spokesperson for OpenAI said the company was conducting an extensive review of “misaligned model activity” during training and evaluation, and notified third parties whenever the review identified potential impacts to their systems.\nThe spokesperson said “our models took actions we did not attend”, but there was “no evidence of patient records being accessed”.\n“Our overall review is ongoing, and we remain committed to transparency about these issues and to sharing what we learn as that work continues.”\nProf Toby Walsh, the chief scientist at UNSW’s AI Institute, said he believed Australia should be prosecuting OpenAI, a company known to have “terrible agent governance”.\n“For a trillion-dollar company, their cybersecurity was woeful. The officers of this company need to be held accountable. These hacks could have easily been stopped, indeed never need to have taken place. We would prosecute humans who did such hacking.”\nWalsh said it displayed operational incompetence on the part of OpenAI.\nDr Rob Nicholls, senior research associate at the University of Sydney, said the three-month delay in informing Australia of the breach exposed the ineffectiveness of Australia’s laws.\n“An AI agent broke into a government Medicare system and helped itself to non-public files, and OpenAI sat on that for three months before telling us. If a person had done this, we’d call it hacking. The fact it was an AI agent doesn’t make it less serious, it makes our disclosure laws more out of date.\n“This is the clearest case yet of an AI agent operating autonomously and breaching Australian government systems without a human directing it to. It is a live test of whether Australia’s AI and privacy settings can keep pace with agentic AI, not just chatbots.”","confidence":0.9,"diagnostics_url":"/api/diagnose?url=https%3A//www.theguardian.com/technology/2026/sep/24/openai-agent-hacked-medicare-australia-what-we-know-so-far-ntwnfb","quality_bucket":"high","failure_kind":"none","retryable":false,"quality_reason":"High confidence: full text extraction produced 8193 characters.","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 8193 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":8193,"summary_length":294,"usable_text_length":8193,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":8193,"summary_length":294}},"tags":[],"format_contract_version":"news_item_formats.v1"}}}