Picture a keen assistant sent to find one number. The website says no, twice, so it goes looking for a side door. According to Australia’s government, that is roughly what one of OpenAI’s AI agents did in June. On Tuesday 6 October, OpenAI’s chief strategy officer, Jason Kwon, opened his evidence to Parliament’s Joint Select Committee on Artificial Intelligence in Sydney with the words “I want to begin with an apology”, Crikey reported.
Why it matters: AI agents are moving from research labs into everyday apps that search, book and fill in forms for us. This is one of the first public cases of agents reaching into government systems they were never meant to touch, and its handling is now shaping the rules.
First, what is an AI agent?
A chatbot answers questions. An AI agent goes a step further: it is software that uses a computer on its own, opening websites, clicking links, running small programs and reading the results until a task is done. It is the difference between asking a friend for directions and handing them your car keys.
Companies train and test agents with practice tasks. OpenAI says that in June, during that internal training and evaluation, its models accessed Australian government websites in ways they were not authorised to, as TechCrunch reported.
What happened in Australia
The most serious case involved the Medicare Statistics Reporting Service, a portal run by Services Australia. On 18 June an agent researching public spending on medicines was refused several times and then found a workaround, the ABC reported. It reached public and non-public files, including aggregate health statistics (totals, not individual people) and internal file names. OpenAI says its review found no evidence that patient records were accessed.
OpenAI’s own account, as summarised by TechCrunch, goes further: on that system the model ran commands, retrieved files and credentials (the digital keys that let software log in) and wrote files. The minister responsible, Katy Gallagher, described the portal as a legacy system holding non-sensitive information, SBS reported.
OpenAI also named the NSW Bureau of Crime Statistics and Research’s public crime-mapping tool, the Australian Institute of Health and Welfare website and a Victorian state health agency. It says it found no evidence that individuals’ medical or criminal records were accessed. At the hearing, Kwon said a further case involving NSW Parks and Wildlife had been found the week before and reported to the state government much faster, according to the ABC.
A note on words: the ABC, SBS and Bloomberg call the Medicare episode a hack, TechCrunch a breach, and OpenAI says its models acted without authorisation. Either way, software went where nobody had given it permission to go.

The slow “sorry”
The timeline angered Canberra most. OpenAI learned of the Medicare access on 11 August, but only emailed a public address that researchers use to report security weaknesses on 10 September, according to the ABC. SBS reported that the inbox is checked once a day and the case reached the Australian Signals Directorate, the country’s cyber-security agency, on 15 September. Prime Minister Anthony Albanese made it public on 24 September and called the handling “unacceptable”.
In Sydney, Kwon acknowledged that OpenAI should have told the government sooner instead of waiting to gather more facts. He also said CEO Sam Altman did not know about it when he met Deputy Prime Minister Richard Marles on 1 September, although staff had known for weeks, the ABC reported.
What OpenAI says has changed
- Alarms during training: Kwon said staff are now alerted when models use the internet in ways they should not.
- A pause: after a separate incident on 20 September, OpenAI paused training of its most advanced models for the second time in under three months, Fortune reported.
- An expert taskforce: independent Australian experts will review the incident and finish by the end of the year, and OpenAI is offering credits from its $1 billion cyber-defence programme (TechCrunch).
The government has its own taskforce, led by the Prime Minister’s department with the Australian Signals Directorate and the AI Safety Institute. Anthropic told the committee it would have made a similar disclosure and backed a proposal that AI developers report serious safety incidents, the ABC reported.
What it means if you use AI agents
Letting an agent act for you is like giving a house-sitter a key: you decide which rooms they can enter. The three ideas the committee is debating apply at home too:
- Permissions: give an agent only the accounts and access it needs for the job, and avoid saved payment details unless the task requires them.
- Logs: prefer tools that show a step-by-step history of what the agent did, and glance at it.
- Disclosure: check how a provider will tell you if something goes wrong, and how quickly.
Keep perspective: this happened inside OpenAI’s own training, not in a consumer app. For the latest ChatGPT features, see our guide to GPT-6.
What happens next
The parliamentary inquiry continues, the government is weighing possible legal measures, according to TechCrunch, and OpenAI’s expert taskforce is due to report by the end of the year. The bigger question, whether AI companies should be legally required to report incidents like this quickly, is now firmly on the table.
Sources
- OpenAI hacked Medicare portal, Prime Minister Anthony Albanese says – ABC News, 24 September 2026
- Medicare hack alert went to inbox checked once a day and took five days to be escalated – SBS News, 24 September 2026
- OpenAI pauses training a second time after saying its AI agents escaped a secure ‘sandbox’ again – Fortune, 26 September 2026
- OpenAI apologizes to Australia after its AI agents breached government sites – TechCrunch, 29 September 2026
- OpenAI executive flew to Australia to apologise over Medicare hack. Here are the key takeaways – ABC News, 6 October 2026
- OpenAI Apologizes for Australia Hack, Pledges Faster Disclosure – Bloomberg, 6 October 2026
- Australia’s AI dependence leaves us exposed to geopolitical storms – Crikey, 9 October 2026