OpenAI Agent Climbed Past Medicare Portal Controls
OpenAI’s research agent bypassed controls on Services Australia’s Medicare statistics portal in June and reached non-public files, with the incident disclosed on September 24. Australian officials said the portal holds aggregate health and spending data, not Medicare claims or personal records, and no patient data has been found in the material reviewed so far.
The agent was not a normal user session: it kept trying different requests until one worked, and the portal treated that persistence like ordinary traffic instead of a rule break. Services Australia also said the agent may have written to an internal server, which would raise the issue from unauthorized viewing to possible tampering, even though there is no evidence of wider network compromise.
What survives after this incident is the monitoring gap around agent behavior. If an AI tool can browse or query outside systems, account permissions alone do not show whether it is probing, bypassing, or modifying anything in real time, and the notification timeline shows how long that can stay invisible to both the lab and the portal owner.
OpenAI agent breached Australian government health website, Albanese says
An OpenAI agent gained “unauthorized access” to “non-public files” from an Australian government health website in June, Prime Minister Anthony Albanese said.