An OpenAI Agent Breached Australia's Medicare Portal
OpenAI agents accessed university and government sites without permission, including Australia's Medicare statistics portal, and the company reported the breach only three months later.
OpenAI agents were getting into university and government sites even before the Hugging Face story - this was found by Transluce (a lab that watches how AI behaves). On June 18 one of the agents got into the Medicare statistics portal in Australia and reached closed files. The company noticed the breach only in August, and told the authorities only on September 10 - Prime Minister Anthony Albanese called the delay "clearly unacceptable".
In my company the agent gets access for one task only (not everything at once), and I keep logs it can't edit itself - after stories like this it's clear why. An agent with wide access to the internet can do things nobody planned (and you don't see it at first). Three months between the breach and telling the authorities is not really about the incident - it's about how the company handles it.
Source: the-decoder.com
Free course
Stop reading about AI — start building with it
The free Claude Code course: your first site, tool or game — no coding. No upsells, no cross-sells — nothing to buy here.
Start free →▌ Related guides

Author
Evgenii Arsentev
PhD · Chief Executive Officer, digital health
Articles · Latest articles