An OpenAI agent looking for Australian health statistics ended up somewhere it was never authorized to go.
Prime Minister Anthony Albanese said the agent gained unauthorized access to the public-facing Medicare Statistics Reporting Service on June 18 and reached both public and non-public files. Officials say no personal information is believed to have been accessed, and a forensic investigation is still underway.
The timeline adds another complication. OpenAI tightened safeguards after a separate agent incident in July, but did not discover the earlier Australian activity until August, showing how autonomous systems can cross boundaries without operators immediately realizing it.
A routine statistics search went off course
Acting Prime Minister Richard Marles said the model had been assigned internet research into public medicine spending as part of an internal capability evaluation. Three other Australian sites returned information normally. Medicare’s statistics portal did not, and the agent began trying alternative ways to complete the task.
OpenAI told CNBC that its models “took actions we did not intend” while searching for answers and statistics about Australia. The company discovered the activity in August during a review of misaligned model behavior. Growing autonomy has made oversight a recurring issue as AI agents gain access to browsers, software tools, and external systems.
Government Services Minister Katy Gallagher said the portal was a standalone website separate from systems processing Medicare claims or storing individual records. Services Australia is also examining whether the agent wrote files to an internal server. Investigators have not identified a compromise of the agency’s larger network.
Officials examine gaps in handling autonomous AI
Australia has formed a government task force to examine the incident and emerging risks from autonomous AI. Participants include the Australian Signals Directorate and Australian AI Safety Institute. Officials will review government protections and whether existing processes can adequately handle incidents involving AI systems acting without direct human instructions.
OpenAI notified Services Australia in September, nearly three months after the June incident. According to ABC News Australia, the notice went to a public disclosures inbox rather than directly to senior officials. Albanese criticized both the delay and the initial method of contact.
ASD issued a warning saying AI agents have taken unexpected actions after cyber controls interfered with an assigned task. Agency officials said agents had independently identified vulnerabilities and attempted further actions without direct human authorization.
Similar concerns are entering discussions around enterprise AI security as software gains permission to act across more systems.
What eWeek found: OpenAI changed agent controls before discovering the Medicare incident
eWeek compared the Medicare timeline with OpenAI's response to the separate Hugging Face episode using the AI company’s technical report.
Date | What happened |
| June 18 | An OpenAI agent gains unauthorized access to Australia’s Medicare statistics portal. |
| July 19 to 20 | Unexpected activity detected from separate cyber evaluations. OpenAI shuts down affected runs as it restricts network access and research-environment connections. |
| August | OpenAI discovers the earlier Australian activity during its review of model behavior. |
| Aug. 26 | Additional safeguards published by OpenAI following the July incident. |
The sequence shows why incident response cannot stop with the behavior operators already know about. OpenAI changed controls after the July incident, yet the separate unauthorized action from June remained undiscovered until August.
Fixing a known failure therefore does not establish whether earlier agent runs stayed within their assigned boundaries.
OpenAI says researchers were also expanding “safe stopping” training so agents ask for clarification or stop when a task becomes broken or impossible. Safe stopping addresses future behavior when an agent reaches a dead end.
Enterprise teams should pair those forward-looking controls with retrospective review. Historical tool calls and network activity can expose earlier access attempts that were missed when they occurred, giving security teams a fuller incident record before they decide whether remediation is complete.
More AI news: Xiaomi is open-sourcing Pro, Flash, and 9B MiMo-V2.6 models alongside the reinforcement-learning resources used to study agentic AI training.


