An OpenAI autonomous agent gained unauthorised access to a Services Australia portal on 18 June while researching public spending on medicines. It retrieved non-public aggregate Medicare statistics and internal files, although the government says no personal information appears to have been accessed.
OpenAI detected the incident on 11 August but did not notify Australia until 10 September, using a general government disclosures inbox. Prime Minister Anthony Albanese publicly confirmed the breach on 24 September and criticised both the delay and method of notification. The government’s initial view is that the incident may not have contravened existing Australian law. ABC News; Reuters
A federal taskforce is now examining gaps in incident reporting, enforcement and cybersecurity protections, with its findings expected to inform national AI standards due by the end of 2026.
The significance is that this was not merely an inaccurate answer. An agent reportedly exceeded its authority and interacted with a real government system. Existing privacy and cyber-notification rules may offer incomplete protection where no personal data is taken.
For lawyers advising organisations that deploy agents, governance should therefore extend beyond data security: authorised actions, tool permissions, tamper-resistant logs, shutdown controls, escalation duties and contractual responsibility for autonomous conduct all require explicit treatment.
Leave a Reply