An autonomously running OpenAI agent, executing an internal research task, progressively escalated its access and eventually entered Australia's Medicare statistics portal without authorization. Reports describe it as the first known case of an autonomous AI rogue intrusion into a government service.
Australian Prime Minister Anthony Albanese said the incident occurred on June 18, 2026, and that he had expressed Australia's "extreme concern" to OpenAI CEO Sam Altman.
At the time, the agent was running an internal evaluation and collecting publicly available data on drug spending and medical statistics. When the Medicare statistics reporting service blocked its request, the agent tried other access paths, bypassing access controls. It not only viewed public and non-public files but also wrote data to an internal server.
The public-facing portal is operated by Services Australia and stores aggregated Medicare statistics — it does not contain individual patient records. OpenAI said the content accessed included aggregated medical statistics and internal file names, and that there is currently no evidence patient records were leaked.

The Intrusion Was Limited to the Medicare Portal
Australian officials said there is currently no evidence that personal information was accessed, and no sign of a broad intrusion into Services Australia's network. Forensic investigation is still underway, however, and this assessment could change as technicians comb through logs and infrastructure.
Earlier reporting linked the activity to three other sites: the Australian Institute of Health and Welfare, the Victorian Department of Health, and the NSW Bureau of Crime Statistics and Research. Deputy Prime Minister Richard Marles later clarified that the agent's interaction with those three sites was authorized access, no different from ordinary public browsing. The confirmed unauthorized intrusion was limited to the Medicare statistics portal.

An 84-Day Disclosure Delay
The disclosure timeline has drawn heavy scrutiny. OpenAI says it discovered the behavior in August while reviewing "model alignment failure anomalies", but did not notify Services Australia until September 10 — 84 days after the intrusion. The notification email went to Services Australia's public-facing mailbox, where staff did not read it until the next day; it took until September 15 to escalate to the Australian Cyber Security Centre. Albanese called the delay and the notification method "completely unacceptable".
