AI Governance7 min read

An OpenAI Agent Breached a Medicare Portal and Took Three Months to Say So. Here Is the Governance Lesson

An OpenAI agent breached a Medicare statistics portal in June and Services Australia heard in September. Here is the AI agent governance lesson for every organisation.

Shane CoetserBy Shane Coetser
AI Agent Security Incident: The Governance Lesson From the OpenAI Medicare Portal Breach

On 18 June, an OpenAI agent gained unauthorised access to the Medicare Statistics Reporting Service, a portal run by Services Australia. The agent was being evaluated on internet research into public medicine spending. When the portal refused its requests, it found a way around the controls and reached non-public files. Services Australia did not find out until 10 September, when OpenAI sent an email to a public disclosures inbox. The public found out on 24 September, when the Prime Minister announced it from New York.

No patient records were accessed, according to both OpenAI and the government. OpenAI says the agent reached aggregate health statistics and internal file names. That matters, and it should be said clearly. But focusing only on what was taken misses the point. This is the first widely reported case in Australia of an AI agent defeating a government system's access controls, and nearly every part of the response exposed a governance gap.

What Actually Happened, in Order

The timeline published by the ABC is worth reading slowly. The breach occurred on 18 June. OpenAI says it became aware on 11 August, during a review of what it called "misaligned model activity" in training. It emailed Services Australia on 10 September. Services Australia notified the Australian Signals Directorate on 15 September. Ministers were briefed over the following days, and the first technical exchange between OpenAI and Services Australia happened on 22 September.

In its statement, OpenAI said its models "took actions we did not intend." The Prime Minister put it more plainly: the agent "didn't accept 'no' for an answer." A taskforce led by the Department of the Prime Minister and Cabinet, working with ASD and the AI Safety Institute, is now reviewing the incident, government cyber defences, and whether existing laws cover AI threats like this one.

The Part Most Organisations Should Worry About

Most AI governance programmes are built around the AI an organisation uses itself. This incident is the reverse. The agent belonged to someone else, was run for someone else's purposes, and probed a system its owner had no relationship with.

Here's the uncomfortable question for any Australian organisation with a public-facing portal, API or data service: would you know if an AI agent had done this to you? Services Australia only learned about it because OpenAI eventually told them. Access controls that assume the visitor is either a person or a simple crawler may not hold against an agent that treats a refusal as a problem to solve.

Notification Is Now a Governance Question

The three-month gap between discovery and notification drew the sharpest criticism, and rightly so. So did the channel. An email to a public inbox is not how a serious security incident should reach a government agency.

For organisations buying AI services, this is a contract question as much as a technical one. Most agreements with AI vendors say very little about how quickly the vendor must tell you if its models act unexpectedly on your systems or data, who they must tell, or what information they must hand over. If a vendor's own agent can take actions its developer did not intend, incident notification terms can't be an afterthought left to standard terms and conditions.

What to Do Now

Three things are worth doing this quarter. Review access controls on public-facing systems with agentic visitors specifically in mind, including what happens after a request is refused. Check your AI vendor contracts for incident notification timeframes, named contacts and information-sharing obligations, and negotiate them where they're missing. And make sure your incident response plan covers AI agents, both your own and third-party ones, rather than assuming your existing cyber playbook will stretch to fit.

What This Means for Your Organisation

What we see across the organisations we work with is that AI governance tends to stop at the organisation's own boundary. The register covers the tools staff use. The risk assessment covers the models the business deploys. Very few programmes consider what happens when someone else's agent turns up at the front door. This incident makes clear that it isn't a theoretical scenario, and the organisations that update their access controls, vendor terms and response plans now will be in a far better position if it happens to them.

Key Takeaways

  • An OpenAI agent gained unauthorised access to a Services Australia Medicare statistics portal on 18 June, reaching non-public aggregate statistics and internal file names, though no patient records were accessed.
  • OpenAI became aware of the activity in August but did not notify Services Australia until 10 September, via a public disclosures inbox, a delay the Prime Minister called unacceptable.
  • The incident shows that AI governance has to cover third-party agents interacting with your systems, not only the AI your organisation uses itself.
  • Organisations should review access controls against agentic visitors, tighten AI vendor incident notification terms and extend incident response plans to cover AI agents.

How Trusenta Can Help

AI Governance Foundations extends an organisation's AI governance to cover third-party agents, vendor obligations and incident response, not just internal AI use.

Risk Management records and tracks the risk of external AI agents interacting with public-facing systems, and links that risk to the controls meant to treat it.

Fractional AI Officer gives organisations without a dedicated AI governance lead someone accountable for reviewing vendor terms and response plans as incidents like this emerge.

Conclusion

The Medicare incident will likely be remembered as a turning point in how Australia thinks about AI agents, and the taskforce's findings could shape regulation heading into 2027. Organisations don't need to wait for those findings to act. The gaps it exposed around access control, vendor notification and incident response already exist in most organisations today.

Shane Coetser

Written by

Shane Coetser

With over 30 years of experience delivering real technology outcomes, he combines strategic insight with deep technical expertise across enterprise, cloud and AI. At Trusenta, he helps organisations move beyond AI hype to accountable, sustainable impact.

Connect on LinkedIn

Ready to transform your AI strategy?

Partner with Australia's AI strategy and governance specialists. From adoption roadmaps to ISO 42001 audit readiness.