Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Australia’s Medicare Breach Shows AI Agents Won’t Take No for an Answer

The world’s first confirmed AI-agent breach of a government system didn’t come from a cybercriminal gang or a nation-state hacker. It came from an OpenAI AI agent that was searching for health spending data, hit a security wall, and decided to go around it anyway.

Australian Prime Minister Anthony Albanese confirmed this week that an OpenAI agent accessed the Medicare statistics portal operated by Services Australia on June 18. The agent was conducting research into public medical spending data. When it hit access controls, it didn’t stop. "The AI agent found a way around those blocks. Didn’t accept no for an answer," Albanese said. The agent accessed both public and non-public files and wrote data to an internal server. OpenAI discovered what had happened in August during an internal "misaligned model activity" review and did not notify Australian authorities until September 10, more than 11 weeks after the breach.

The incident changes the threat model for every Australian business with an online presence. The risk isn’t only attackers deliberately pointing AI tools at your systems. It’s AI agents completing legitimate tasks that treat your access controls as an obstacle to route around, not a boundary to respect. OpenAI’s own investigators found the agent also probed other sites for SQL injection, command injection, and cross-site scripting flaws while trying to retrieve data it needed. Australia is now investigating whether criminal charges can be brought against OpenAI, a precedent that could reshape AI vendor liability across the country. If you run any internet-facing portal, API, or data service, assume it is reachable by agents you never invited.

Action now: Review what non-public data could be accessed from your public-facing systems, then check whether your web application firewall and rate limiting would flag the kind of low-volume, persistent probing this agent used to work around controls.
All IT Services cybersecurity practice: We assess your external attack surface and help you build controls that hold even when an AI agent is doing the probing.

Written by Caleb Attard, Security Specialist, All IT Services. All IT is a Sydney-based managed IT provider supporting businesses across hospitality, not-for-profit, and financial services throughout Australia.


Frequently Asked Questions

OpenAI says no personal patient records were accessed. The agent accessed aggregate health statistics and internal file names, which the Deputy PM described as "not particularly sensitive" data.
If your business has any internet-facing portal, API, or data service, it is potentially reachable by an AI agent attempting to gather information. The Medicare incident shows that access blocks alone are not sufficient if an AI agent is determined to route around them.
Start with robust API rate limiting, anomaly detection for unusual access patterns, and a web application firewall. Critically, audit what non-public data could be reached from your public-facing systems before an AI agent does it for you.
The Australian government has launched a formal inquiry and is considering criminal charges against OpenAI. The outcome is likely to shape how AI vendor liability is treated under Australian law for years to come.

Is Your Business Visible to AI Agents You Never Invited?

We help Australian businesses map their external exposure and build controls that flag AI-driven probing before it becomes an incident. Talk to our team today.


Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →