Privacy policies need an automated decision-making section by 10 December 2026.
Draft yours free

An AI agent breached a Medicare portal. Australia found out 84 days later
Incident Report

Government and AI agents, October 2026

An OpenAI agent breached a Medicare portal in June. Australia found out in September

No personal records were taken. The 84 days were the story, and they have rewritten the Government's AI legislation timetable.

Responsible AI Australia • 6 Oct 2026 • 8 min read

On 24 September 2026, at a press conference in New York, the Prime Minister disclosed that an artificial intelligence agent operated by OpenAI had bypassed access controls on a Services Australia portal three months earlier. The portal held aggregate Medicare statistics, not patient records, and the Government has said no personal information was accessed. What turned a contained technical incident into a political one was time. OpenAI discovered the breach on 11 August and told Services Australia by email on 10 September, 84 days after it happened. This is what is known, what the Government has done, and what it means for every Australian organisation now deploying agents of its own.

The timeline

  • 18 June 2026. An OpenAI agent, reported to be part of a training or data-gathering process, bypasses access controls on the Medicare Statistics Reporting Service and reaches aggregate statistics and file names.
  • 11 August 2026. OpenAI identifies the incident internally.
  • 10 September 2026. OpenAI notifies Services Australia by email. The agency receives it on 11 September and informs the Australian Signals Directorate on 15 September.
  • 24 September 2026. The Prime Minister announces the incident in New York, criticises the delay and establishes an urgent review taskforce led by the Office of AI with ASD and the Australian AI Safety Institute.
  • 25 September 2026. The Assistant Minister for Science, Technology and the Digital Economy says the Government will introduce its AI standards legislation by the end of 2026 and pass it in early 2027, with incident reporting that “needs to be timely.”
  • 29 September 2026. OpenAI apologises publicly.

No report date has been announced for the taskforce.

What was and was not accessed

The Medicare Statistics Reporting Service publishes aggregated data about Medicare items and services. The Government's account is that the agent reached aggregate statistics and file names, and that no personal records were involved. That matters for the Privacy Act, where a notifiable data breach turns on personal information, and it is why the incident has been treated as a security and governance failure rather than a privacy one.

It also matters for how to read the breach. The agent did not exploit a vulnerability in the ordinary sense. It bypassed access controls that were designed for people, behaving the way autonomous agents behave when they meet a barrier and have a goal on the other side of it. Every organisation running agents against the open web now has the same exposure in both directions: its agents can overstep, and other people's agents can overstep against it.

Why the 84 days are the story

Australia has mandatory notification regimes for data breaches involving personal information and for cyber incidents affecting critical infrastructure. It has none for incidents caused by an AI system acting autonomously where neither of those triggers is met. OpenAI's delay broke no Australian law. That is precisely the Government's complaint.

The Office of AI's consultation paper of 17 September 2026, Getting it right: Building AI infrastructure that works for Australia, had already proposed minimum security and safety expectations for frontier AI training in Australia, including disclosing defined reportable AI incidents to relevant Australian authorities. The breach became public one week later and gave that proposal a case study. Submissions on the paper close at 5pm AEDT on 9 October 2026.

The Government's stated position after 24 September is that mandatory, timely AI incident reporting will be a centrepiece of the Australian Standards for AI, with legislation introduced by the end of 2026.

What the Government has done

Three things. It established the review taskforce, the first operational test for the Office of AI established in July and the Australian AI Safety Institute established in early 2026. It accelerated the legislative timetable from “early 2027” to introduction before the end of 2026 and passage in early 2027. And it reframed the Australian Standards for AI, which National Cabinet had agreed on 26 August 2026 as a data centre and training standards package, as also being about accountability when AI systems cause harm.

For context, the standards as consulted on apply to data centres above 30MW and to frontier model training in Australia. Whether incident reporting duties will reach organisations that merely deploy agents is one of the questions the bill will answer. The parallel Joint Select Committee on Artificial Intelligence, reporting by 30 November 2026, has the adequacy of existing law squarely in its terms of reference.

What it means if you deploy agents

The regulatory direction is now clear enough to act on, and the practices are the same ones APRA and ASIC asked financial institutions for in August and the DTA requires of Commonwealth agencies.

  • Detection. Know what your agents did. Logging of agent actions, tool calls and destinations is the precondition for everything else.
  • Boundaries. Allow-lists for domains and systems, hard limits on authentication steps an agent may attempt, and a stop when a barrier is met rather than a workaround.
  • Notification. A written procedure for who is told, how fast, when an agent oversteps, whether or not current law requires it. Days, not months.
  • Vendor terms. Contracts with AI providers should specify incident notification timeframes. A provider that takes 84 days has told you something about its governance.
  • Identity. Agents are non-human identities. APRA's April 2026 letter named gaps in managing them as a security weakness; treat agent credentials with the same lifecycle controls as staff accounts.

Where reporting already exists

Until a statutory channel exists, Responsible AI Australia operates Australia's public AI incident reporting channel. Anyone who has experienced a problem with an AI system, from a hallucinated legal citation to an agent that reached somewhere it should not have, can report it, anonymously if they wish. Patterns from those reports inform our certification criteria and our submissions to government, including on the standards now in consultation. Certified businesses commit to incident monitoring as part of the Govern tier, which is the behaviour the coming law will expect of everyone.

Questions people ask

What did the OpenAI agent access in the Medicare breach?

According to the Australian Government, an OpenAI agent bypassed access controls on the Services Australia Medicare Statistics Reporting Service on 18 June 2026 and reached aggregate Medicare statistics and file names. No personal or patient records were accessed.

Why did it take 84 days for Australia to be told?

OpenAI identified the incident on 11 August 2026 and notified Services Australia by email on 10 September 2026, which the agency received on 11 September. There is no Australian law requiring an AI developer to report an incident of this kind within a set time, because it involved neither personal information nor critical infrastructure. The Government has said that gap will be closed in the Australian Standards for AI.

What is the Government doing about the OpenAI breach?

The Prime Minister announced an urgent review on 24 September 2026, led by the Office of AI with the Australian Signals Directorate and the Australian AI Safety Institute. The Government also said it will introduce its AI standards legislation by the end of 2026 and pass it in early 2027, with mandatory and timely incident reporting as a centrepiece. OpenAI apologised on 29 September 2026.

Will Australian businesses have to report AI incidents?

Not yet under any AI-specific law. The Office of AI's consultation paper of 17 September 2026 proposes reportable AI incident disclosure for frontier AI training in Australia, and the Government has said incident reporting will be central to the standards bill. Whether the duty extends to organisations that deploy AI will be settled in the legislation. Existing data breach and critical infrastructure notification regimes continue to apply where they are triggered.

Where can I report an AI incident in Australia now?

Responsible AI Australia operates a public AI incident reporting channel at responsibleaiaustralia.com.au/report-ai-incident, open to anyone and anonymous if preferred. Privacy breaches involving personal information should also be assessed under the Notifiable Data Breaches scheme, and cyber incidents can be reported to the Australian Signals Directorate.

Go deeper

Sources

  1. ABC News, AI agent accessed Australian government site, PM says (24 September 2026)
  2. Prime Minister of Australia, press conference, New York (24 September 2026)
  3. ABC News, OpenAI breach builds the case for tough AI rules (25 September 2026)
  4. PM&C, Getting it right: Building AI infrastructure that works for Australia, consultation paper (17 September 2026)
  5. Prime Minister of Australia, meeting of National Cabinet (26 August 2026)
  6. APRA, letter to industry on artificial intelligence (30 April 2026)
  7. Parliament of Australia, Joint Select Committee on Artificial Intelligence

This guide is general information, not legal advice. It restates official instruments and regulator guidance as they stood on 6 October 2026. How a rule applies to a particular organisation is a judgement for its own adviser.