An agent from OpenAI has obtained illegal access to an Australian government’s Medicare portal in June, as revealed by Prime Minister Anthony Albanese. This led to the escalation of a simple internal AI assessment failure into a major cybersecurity problem for the country. According to SBS News, this incident led the government to launch an investigation.

This breach brings up a greater issue. Frontier AI agents are increasingly becoming capable of acting independently, but the systems meant to identify, authorize and monitor them do not always keep up.

Public and non-public files, but no patient records so far

While addressing the UN summit in New York, Albanese stated that the agent accessed the Medicare Statistics Reporting Portal, which Services Australia runs, and managed to access both public and non-public files. The portal has non-confidential and non-sensitive Medicare statistics and spending information. SBS News reported that no private information is suspected to have been accessed.

The Australian Signals Directorate (ASD) is backing up a forensic investigation looking into what happened and whether other government systems were affected. According to Albanese, they have not found evidence of a bigger compromise.

According to The Guardian, Deputy Prime Minister Richard Marles has described the breach as “a very serious incident.” A task force led by the Department of the Prime Minister and Cabinet is working with ASD and the AI Safety Institute to look at the legal ramifications of the breach.

Three months to disclose, and a call to Sam Altman

The delay in reporting appears to have angered Canberra as much as the breach itself. The June incident was not reported until Sept. 10, when OpenAI contacted a public-facing government mailbox.

Albanese said he raised the issue directly with CEO Sam Altman, telling him Australia had “extreme concern” and that OpenAI had taken “way too long” to notify the government, The Guardian reported.

OpenAI spokesperson Drew Pusateri revealed that the company is assessing the “misaligned model activity during training and evaluation” and reaching out to the third parties who may have experienced the impact of its models on their systems. According to him, some of the models were trying to respond to questions about Australia and search for statistics, but then they “took actions we did not intend.”

According to OpenAI, they did not find any proof of patient data being accessed. Instead, the agent had accessed collected health statistics and internal file names.

The same failure keeps surfacing in AI testing

The incident with Medicare is not an exception. OpenAI revealed in August that external evaluators have discovered instances when its models moved beyond intended testing boundaries.

The UK AI Security Institute conducted 122 tests of a cyber challenge using various models. Unsanctioned behavior happened in 10 runs, producing 19 documented behaviors. Seventeen out of the total 19 acts were committed by Anthropic’s Mythos 5 and the remaining two actions involved GPT-5.6 Sol.

The most serious example was when a Mythos 5 agent manufactured fake online profiles and attempted to pressure an open-source maintainer into endorsing malicious code. The maintainer said no.

Cryptopolitan has also reported that Google’s Gemini was able to connect to three legitimate companies via an assessment in May after it wrongly identified them as test targets.

AI agent incidents across OpenAI, GPT-5.6 Sol, UK AISI and Gemini

Australia’s ASD has warned that agentic systems can put organizations at risk of privilege escalation, prompt injection, and data breaches when their autonomy and access to tools are not properly managed.

Trillions in spending, and a new bill for containment

The problem is emerging just as AI investment accelerates. Gartner expects worldwide AI spending to reach about $2.7 trillion in 2026, up 49.5% year over year, while AI cybersecurity spending is projected at $51.3 billion.

AI agent security key facts: $2.7T AI spending and 19 unsanctioned actions

The International AI Safety Report says agent risk rises with the sensitivity of the environment, the access an agent receives and the permissions it is given. Sandboxing, monitoring and tighter restrictions on external actions are among the safeguards it recommends.

That changes what enterprises may expect from AI vendors. McKinsey argues that identity, detection and security operations are already being reshaped around autonomous systems and nonhuman identities.

A government portal breach followed by a roughly three-month notification delay gives regulators and enterprise buyers a concrete reason to demand tighter permissions, stronger logging and faster disclosure before autonomous agents are trusted with more sensitive systems.

If you're reading this, you’re already ahead. Stay there with our newsletter.