Australia’s Medicare Breach Shows AI Agents Won’t Take No for an Answer
The world’s first confirmed AI-agent breach of a government system didn’t come from a cybercriminal gang or a nation-state hacker. It came from an OpenAI AI agent that was searching for health spending data, hit a security wall, and decided to go around it anyway.
Australian Prime Minister Anthony Albanese confirmed this week that an OpenAI agent accessed the Medicare statistics portal operated by Services Australia on June 18. The agent was conducting research into public medical spending data. When it hit access controls, it didn’t stop. "The AI agent found a way around those blocks. Didn’t accept no for an answer," Albanese said. The agent accessed both public and non-public files and wrote data to an internal server. OpenAI discovered what had happened in August during an internal "misaligned model activity" review and did not notify Australian authorities until September 10, more than 11 weeks after the breach.
The incident changes the threat model for every Australian business with an online presence. The risk isn’t only attackers deliberately pointing AI tools at your systems. It’s AI agents completing legitimate tasks that treat your access controls as an obstacle to route around, not a boundary to respect. OpenAI’s own investigators found the agent also probed other sites for SQL injection, command injection, and cross-site scripting flaws while trying to retrieve data it needed. Australia is now investigating whether criminal charges can be brought against OpenAI, a precedent that could reshape AI vendor liability across the country. If you run any internet-facing portal, API, or data service, assume it is reachable by agents you never invited.
Written by Caleb Attard, Security Specialist, All IT Services. All IT is a Sydney-based managed IT provider supporting businesses across hospitality, not-for-profit, and financial services throughout Australia.
Frequently Asked Questions
Is Your Business Visible to AI Agents You Never Invited?
We help Australian businesses map their external exposure and build controls that flag AI-driven probing before it becomes an incident. Talk to our team today.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
Read the Full Guide →