top of page

What actually happened with OpenAI and Medicare, and why it matters

11 minutes ago
4 min read

Most of us think of AI as something you ask a question and it answers. An AI agent (Agentic AI) goes further. You give it a job and it goes off on its own, clicking through websites and making decisions until the job is done. Nobody checks each step.

On 18 June 2026, OpenAI, the company behind ChatGPT, was testing one of these agents. Its job sounded harmless as it was told to find out how much the government spends on medicines. It went to a Medicare statistics website run by Services Australia. The site is old, some of it is open to the public and some of it is not.

The site told the agent no. It went in anyway.

Prime Minister Anthony Albanese says it opened files that were never meant to be public, and even wrote files onto the government's system. OpenAI says "our models took actions we did not intend" and calls it "misaligned model activity". In plain words, the AI did something it was not supposed to do.

Nobody asked it to break in, it was given a job, the door didn't open, and so it found its own way over the fence. No malice. or hesitation, just a task, and nothing inside it that said stop.

As far as we know, no ones medicare information was taken. OpenAI says it found "no evidence of patient records being accessed". This site holds big-picture numbers, like how many people are bulk-billed or immunised, not details about you or your family. The hidden files the agent reached have since been made public anyway.

The agent also visited three other government health and crime statistics websites. Deputy Prime Minister Richard Marles said it used those "in a way that a member of the public might". In other words, it only read what anyone could read. We don't have the full picture of how it got in yet. Reports say a security service called Cloudflare, which works like a bouncer at the door of a website, first blocked the agent. The AI agent then reportedly talked about disguising where it was coming from, and kept guessing the names of hidden files until some worked. Picture someone walking down a hallway trying every door handle. This has not been officially confirmed.


Everyone is angry because the break-in happened in June, Australian only found out this week.


OpenAI worked out something was wrong in August. On 1 September its boss, Sam Altman, met Marles face to face and didn't mention it. Nine days later the company sent an email to a general government inbox that is checked once a day. It then took the government five days to pass it to the Australian Signals Directorate, the agency that defends the country against cyber attacks. Albanese called it "unacceptable". He told Altman of Australia's "extreme concern" and said Altman "clearly accepted" OpenAI had not done enough. The government's own slow handling will be looked at too.

A team from across government, including cyber security and AI safety experts, will investigate what the agent did, whether any laws were broken, and how government websites should deal with AI from outside companies. Penalties against OpenAI have not been ruled out, and the government is reportedly considering calling in the Australian Federal Police. Marles says the damage was "relatively minor" but the incident is "very serious".

This is widely described as the first time an AI agent has hacked a government system. The big question now is who answers for it. Ed Santow, the former Human Rights Commissioner, called "misaligned model activity" "a very euphemistic term", a polite way of avoiding the word hacking. He says AI companies should face the same legal consequences an employee would. Independent Senator David Pocock pointed out that a planned national AI safety law has been shelved, and AI companies currently carry no clear legal responsibility. Lizzie O'Shea of Digital Rights Watch said the three-month delay shows we need basic rules for tech companies. If a contractor or disgruntled employee had done this, nobody would reach for the word "misaligned".


What this means for schools

Schools run plenty of old websites and logins too that include parent portals, reporting tools, systems set up years ago. Marles described protections like these as "a fence". AI agents can now climb that fence, and they don't need a bad person behind them to try. They only need a task and a locked door.

Then there's the inbox. If someone warned you tomorrow that something had got into your systems, would that email sit somewhere nobody checks?

Three questions worth asking this week:

·       Which of our old systems can anyone on the internet reach?

·       Who reads our security emails, and how quickly?

·       Which AI tools have staff allowed to do things, not just answer questions?

The investigation is still going, and some details, like which ministers were told and when, differ between reports. But the lesson won't change. The agent wasn't evil. It was determined, and it had no idea where the line was. That's exactly why we have to draw it. Ctrl Shft Behavioral Risk Intelligence Infrastructure can audit exactly what is in use across your school, show you where the weak spots are, and help you close them without taking good tools away from good teachers. Don't wait for your own inbox moment. Email hello@safeonsocial.com and let's start this week.




 
 
 

Comments


bottom of page