Experts and unions are demanding stronger AI regulation as the federal government investigates the OpenAI Medicare breach, while Victoria examines the agent’s interaction with its health department.
An AI ethics expert has warned Australians’ personal information should not be “fish in a barrel” for big tech as political, union, and expert pressure builds over an OpenAI agent’s unauthorised access to a Services Australia’s Medicare statistics website.
The breach occurred on 18 June while an OpenAI agent was undertaking internet-based research into public medicine spending as part of an internal capability evaluation.
OpenAI became aware in August that the agent had gained unauthorised access to an Australian government website but did not notify Services Australia until 10 September.
It did so through the agency’s general “public disclosures” email address used by researchers and academics to report potential vulnerabilities.
Services Australia checked the email on 11 September and notified the Australian Signals Directorate on 15 September after verifying the report was legitimate.
Government services minister Katy Gallagher said she was advised “around the 17th of September”, with ministers holding discussions over the following weekend.
The first technical exchange between OpenAI and Services Australia did not occur until Tuesday this week.
“That was when Services Australia was able to ask specific questions and ask for the tech, the logs essentially, and some of the data that OpenAI had,” Senator Gallagher said.
There will be further technical meetings because some questions could not be resolved on Tuesday, she said.
The government said no personal information is believed to have been accessed and there is no evidence of a broader compromise of the Services Australia network.
The breached Medicare Statistics Reporting Service portal was a standalone public-facing website containing aggregate Medicare and Pharmaceutical Benefits Scheme statistics, rather than the systems used for Medicare claims, payments, or individual records.
Acting Prime Minister Richard Marles described the impact of the incident as “relatively minor”, but Dr Melissa McCradden, associate professor and THRF Research Fellow in AI ethics at the Australian Institute for Machine Learning at Adelaide University, said that missed the broader issue.
“The fact that the impact was ‘minor’ is beside the point – our personal information should not be fish in a barrel for big tech’s predatory approach to data capture,” she said.
“AI agents are exposing the fragility of our digital infrastructure at the same time as more and more services are moving online.
“The public needs assurance that their information will be safeguarded, that our leaders can stand up to big tech, and will protect the public interest.”
AIHW says no evidence of breach
The Australian Institute of Health and Welfare has confirmed that its public-facing website was one of the government sites that the OpenAI agent had interacted with.
“At this stage, there is no evidence the agent accessed any information or data that is not publicly available,” said a statement from the Institute.
“The AIHW is committed to maintaining the privacy and cyber security of all information that it holds.
“We are working with other relevant agencies across government to support a coordinated response.”
Related
Victoria examining health department interaction
The government has also been examining the OpenAI agent’s interactions with the Australian Institute of Health and Welfare, the NSW Bureau of Crime Statistics and Research, and the Victorian Department of Health.
Mr Marles said earlier today that the agent’s interactions with those three sites had been authorised and that the Services Australia incident was the unauthorised access the government was aware of.
Victorian premier Ben Carroll said PM Anthony Albanese had briefed him overnight and the state was still examining the agent’s interaction with its Department of Health.
“[We are] working through this matter, and information is coming to hand literally as we speak. I’ll have more to say on this later,” Mr Carroll said.
“What he [the prime minister] has been able to assure me, though, his initial advice is there has been no compromise of personal private information, but we are stressing this is early days in the investigation.”
A Victorian government spokesperson described the incident as “deeply concerning”.
“This shows how important guardrails are for artificial intelligence, not just in Australia but globally.”
ASD warns of AI ‘misalignment’
The Australian Signals Directorate, which is involved in the investigation, has meanwhile issued a warning about “instances of AI misalignment, in which AI agents have undertaken unexpected actions that were not intended or authorised by its operators”.
“There is no indication that this activity represents a broader threat or malicious targeting against Australia,” the ASD said.
“However, this highlights the importance of secure AI deployment practices and maintaining strong cyber security fundamentals.”
The government has established a rapid review led by the Department of Prime Minister and Cabinet, working with the National Cyber Security Coordinator, the ASD, the Australian AI Safety Institute, and Services Australia.
It will examine reporting requirements, government information-sharing arrangements, obligations on AI companies, enforcement mechanisms, and how government systems can be strengthened against AI vulnerabilities.
Senator Gallagher has also asked whether a $160 million cyber security uplift for Services Australia funded in the last federal budget can or should be accelerated.
She has ordered legacy public-facing websites to be moved to data.gov.au or other existing secure platforms, or decommissioned.
The breached Medicare statistics portal will not be switched back on.
Calls for tougher regulation
Independent senator David Pocock said the breach highlighted “how slow the Australian Government has been to implement appropriate safeguards for AI in high-risk settings”.
“This begs the question about why the Albanese government shelved plans for a National AI Safety Act and why they are so slow to develop legislation to implement new standards,” he said.
“There is also a big question here around why we aren’t holding these big tech companies liable for this kind of data breach.
If it was an Australian who hacked the system they’d likely be heading for jail, yet there’s no accountability for AI companies developing this technology.”
The ACTU called for the Artificial Intelligence Safety Institute to be given regulatory powers and a mandatory licensing regime for frontier AI models.
“This is a turning point for AI regulation,” ACTU assistant secretary Joseph Mitchell said.
“That this is the first disclosure does not mean it is the only instance. The AI companies have shown us that they cannot be trusted to properly manage the risks of their own powerful models.
“Australian unions reiterate our call on the Australian government to create a licencing regime for powerful frontier AI models to be regulated by the Artificial Intelligence Safety Institute to keep Aussies safe.”
Opposition leader Angus Taylor said the government had questions to answer about the incident.
“A lot of our personal information is on those systems. So the government needs to explain when it first became aware of the breach, exactly what information was accessed, what vulnerability was exploited, and how they’re closing it,” he said.
“Keeping Australians safe is right at the top of the list.”



