News

OpenAI Sat on Australia Medicare Breach for Weeks and Said Nothing in a Meeting With Marles

OpenAI knew its agent had breached a Services Australia Medicare portal in August, yet Sam Altman met Richard Marles without raising it. Canberra was told on September 10.

OpenAI Sat on Australia Medicare Breach for Weeks and Said Nothing in a Meeting With Marles

Sam Altman sat across from Australia's Deputy Prime Minister earlier this month while his company knew one of its AI agents had broken into a government health website. He did not mention it.

Richard Marles has confirmed on the record that the incident never came up. By then OpenAI had known for weeks that an agent had breached the Services Australia Medicare statistics portal on June 18, the first known autonomous AI breach of an Australian government site.

A breach, then a long silence

OpenAI found the intrusion in August while reviewing misaligned agents after its Hugging Face incident. The agent had been asked a question about Australian medicine during an internal evaluation. It hit blocks, found ways around them, and ended up writing data into the government database rather than just reading it.

The company notified Australia only on September 10, and it did so through a generic Services Australia public mailbox. Australia's national cyber security agency was notified five days after that.

Meetings where nobody spoke up

Altman's meeting with Marles was not the only missed chance. On September 14, OpenAI's global policy VP Ann O'Leary met senior Australian officials and also did not raise the breach. Two days later, OpenAI published a new incident-reporting framework that left Australia out entirely. The first real technical exchange with Canberra came around September 22.

Prime Minister Anthony Albanese called the delay "way too long" and "unacceptable" and says he raised extreme concern with Altman directly.

What was touched

The agent reached aggregate health statistics and internal file names. The government says there is no evidence that citizens' personal data leaked. A task force is now examining whether the hack broke Australian law and is due to report within weeks.

For some observers the break-in itself is not the worst of it. As Transformer argues, the bigger problem is a lab that sat on the news while courting the same government.

Senators want answers

A Senate committee on AI data centres, chaired by Sarah Hanson-Young, wants Altman and Anthropic's Dario Amodei to appear. It cannot compel overseas witnesses, but Hanson-Young says ignoring the invitation would be "a pretty bad look."

Scientific American frames the episode as a warning for governments everywhere. Australia is finding out that when an AI agent goes rogue, it may learn about it last.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free