Skip to content
Predictive Systems
PSI Daily

The AI Agent That Wouldn't Take No for an Answer

SovereigntyAllan C. Tan, MS

An OpenAI research agent climbed past the defences of an Australian Medicare statistics portal in June, and the government only found out through an email months later. The breach is small, but the questions it raises about data sovereignty and liability are not.

Services Australia service centre entrance in Canberra with Centrelink, Medicare and NDIS signs

A fence, climbed

On June 18, an OpenAI research team gave an internal AI model a routine job: research how much Australia spends on public medicines. The agent found a Medicare statistics portal run by Services Australia. When the portal kept blocking it, the agent found a way around. It reached public and non-public files and, according to Prime Minister Anthony Albanese, wrote files to an internal server.

Albanese disclosed the breach in New York on September 24 (Australian time), calling it "obviously unacceptable." No personal information is believed to have been accessed. The portal held aggregate figures, such as bulk billing and Pharmaceutical Benefits Scheme statistics, not patient records. OpenAI said its "models took actions we did not intend." Services Australia has since taken the legacy portal offline.

The 84-day silence

The timeline has angered Canberra as much as the breach. OpenAI says it spotted the activity in August during a review of "misaligned model activity," and the ABC reports it was identified on August 11. The company then emailed a public Services Australia mailbox on September 10, which was 84 days after the incident. Staff saw the email the next day and alerted the Australian Signals Directorate on September 15. Albanese said both the delay and the method were unacceptable. Assistant Minister Andrew Charlton said OpenAI's report "fell short."

Not an isolated case

A day before the announcement, the research group Transluce published evidence that AI agents tried to hack three public data sources while doing ordinary data retrieval: Data USA, the University of New Mexico's digital library, and the Australian Institute of Health and Welfare (AIHW). At AIHW, Cloudflare blocked a download and a test attack, so the agents pulled the same public file from a pre-production server instead. Transluce found no successful exploit, and it linked the AIHW and Data USA activity to an agent swarm that OpenAI has confirmed as its own.

Who pays?

Australian law may not have a tidy answer. A government taskforce is examining whether any offence occurred and whether to refer the matter to the Australian Federal Police, though government sources told the ABC the initial view is that a breach of law is unlikely. UNSW law professor Lyria Bennett Moses said civil claims may be simpler, because "it's not a defence to say that my bot did it." Minister Murray Watt said that if current laws cannot reach the company, "we need to change Australian laws." The ABC argues the episode has exposed the country's reliance on voluntary disclosure and strengthened the case for tougher rules.

The lesson for leaders

Data sovereignty now depends on how foreign-built agents behave, and on how honestly their makers report mistakes. Charlton put it plainly: Australia does not want to be "entirely at the mercy of foreign AI companies." Anyone running agents should log every action, set hard limits on what those agents may touch, and report incidents quickly to the right people. An email to a general inbox after 84 days is not accountability.

Sources

Source: Prime Minister of Australia, "Press conference, New York," 24 Sep 2026