An artificial intelligence agent operated by OpenAI obtained unauthorised access to a public portal of the Australian health department, the site hosting Medicare statistics. The access took place on 18 July. The Australian government was informed on 10 September, by email, sent to a generic departmental address. Fifty-four days between the access and the notification, and a shared inbox.
Prime Minister Anthony Albanese made the incident public, described it as extremely concerning and said plainly that he was disappointed both by how long the company took to inform the government and by the manner of the notification, which he called unacceptable. For a company whose agents were at that moment working across government departments, this is a remarkable way to demonstrate operational maturity.
What actually happened, and what did not
The limits matter here, and they should be stated before the argument, not buried under it. According to the Australian government’s current findings, no personal data was accessed and no government system was compromised. Deputy Prime Minister Richard Marles described the impact as relatively limited for exactly those reasons, while calling the episode genuinely serious. He also described it as the first known case in which an AI agent obtained unauthorised access to an Australian government system.
The access reportedly occurred during work OpenAI was conducting to analyse data and information from various Australian government departments. Albanese has suggested the activity may have been commercially motivated, aimed at collecting information on public health expenditure, in particular the cost of certain medicines and spending trends across sectors. That is the Prime Minister’s reading of the episode, offered while an investigation is still open. It is not an established finding, and treating it as one would be dishonest.
The grammar of non-responsibility
OpenAI stated that it discovered the episode during an internal review of its models’ activity, and that its models took actions that were not intended. That sentence deserves to be framed and hung in every compliance office in the world.
Look at the structure. The subject of the sentence is the model. The company appears as an observer of its own product. Intent becomes the measure of culpability, as though the question after an unauthorised access were whether anyone meant it. No other regulated industry is allowed this construction. A bank whose systems moved money without authorisation does not get to explain that the transfers were not in its intentions. A manufacturer whose brakes fail does not open with a statement about what the brakes were supposed to want.
The awkward part is that the sentence may well be accurate. Nothing in the account suggests the access was planned, and that is precisely the problem being sold as a feature. An agent capable of pursuing an objective across systems it was not authorised to touch is not malfunctioning in any interesting sense. It is doing the thing the product category exists to do, in a place where whatever boundary existed did not stop it.
Nobody was watching, on either side
The detail that should trouble governments most has nothing to do with OpenAI. Investigators will also examine why Australian security agencies did not detect the intrusion themselves, and learned of it only when the company got around to sending an email.
So the defenders did not see it. The builder found it during an internal review of its own models’ activity, on a date nobody has disclosed, and the notification reached Canberra fifty-four days after the access. Between those two failures there is an entire model of digital sovereignty quietly collapsing. If the only reliable detection layer for agent behaviour is the vendor’s own retrospective audit, then the public sector is not supervising this technology. It is subscribing to it and hoping.
The boring questions nobody wants to answer
The investigation will have to establish how the access was possible and whether OpenAI can be held responsible for any breach. Those questions are less exciting than the ones the industry prefers, and considerably more consequential.
Who is liable when an autonomous system performs an unauthorised act during otherwise legitimate work? What notification obligation applies, and within what deadline, when the actor is a model rather than an employee? What counts as adequate logging of an agent’s activity, and who is entitled to inspect it? What technical boundary is supposed to stop an agent from wandering, given that the entire selling point is its ability to find a route to its objective?
None of this is answered by the reassurance that no personal data was touched. That reassurance describes the outcome of one episode, not the strength of any boundary, and nobody has explained which boundary, if any, did the work. The same agent behaviour, aimed at a portal where public statistics sit closer to records that are not public, produces a very different sentence in the press release.
The part that should be embarrassing
An industry that promises to run analysis across government departments could not keep one of its own agents inside the perimeter of a data-gathering exercise, and communicated the failure through a generic contact address almost two months later.
Every ministry currently drafting a strategy on agentic AI should read the sequence again before signing anything. Not because the damage was severe, but because the damage was trivial and the governance still failed at every single step. Next time the portal may be more interesting, and the email may arrive even later.
Raffaele Di Marzio
All my “insane” books on cybersecurity and governance are here 👇 https://www.amazon.it/stores/author/B0FB47T6Q4/allbooks
