An OpenAI agent accessed non-public government files, raising urgent questions for HR leaders about AI data breach response
An OpenAI agent breached an Australian government Medicare portal in June, prompting Prime Minister Anthony Albanese to demand answers and announce a federal taskforce.
Albanese confirmed in that the OpenAI agent gained unauthorised access on 18 June 2026 to the Medicare statistics reporting service portal, administered by Services Australia.
Non-public aggregate health statistics and internal file names were accessed in the AI data breach. No individual Medicare details appear to have been compromised.
How long did OpenAI take to report the breach?
What troubled the prime minister as much as the breach was the disclosure timeline. Services Australia was not notified until 10 September 2026 – nearly three months after the incident.
When the alert did arrive, it came as an email to the agency‘s public inbox.
“Today I spoke with the CEO of OpenAI, Sam Altman, to express Australia’s extreme concern about this incident,” Mr Albanese said. “And I also expressed my disappointment that it took the company way too long to inform the government what had occurred.”
On 15 September 2026, Services Australia escalated the matter to the Australian Signals Directorate (ASD) cybersecurity centre.
What caused the AI data breach?
An automated AI crawler found a workaround to bypass privacy protections while OpenAI conducted internal research into Australian public medical spending.
The crawler – a program that scans websites and collects data – is commonly used to train AI models or retrieve information for AI systems. “The AI agent found a way around those blocks, didn’t accept ‘no’ for an answer, if you like,” Mr Albanese said.
In a statement, an OpenAI spokesperson said the company was conducting “an extensive review of misaligned model activity” during training.
“During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation,” the spokesperson said. “In the course of that, our models took actions we did not intend.”
OpenAI said no patient records were accessed.
Who else was affected by the AI data breach?
Three other sites may also be caught up in the same incident: the Australian Institute of Health and Welfare, the New South Wales (NSW) Bureau of Crime Statistics and Research, and the Victorian Department of Health.
Mr Albanese said premiers of both states had been notified and would receive cybersecurity briefings.
NSW Health Minister Ryan Park told the Australian Broadcasting Corporation (ABC) it was a “significant concern”, and NSW Health would conduct its own review.
A federal investigation is now underway, led by the prime minister’s department alongside the ASD and the AI Safety Institute.
The AI data breach risk sitting inside your own organisation
This AI data breach carries a warning for HR and people leaders well beyond the government sector.
HR departments hold some of the most sensitive data in any organisation – payroll records, health information, performance files, and contracts. HR data appears in 82% of analysed data breaches, making it among the most targeted data categories in cyberattacks.
The OpenAI incident is a reminder that AI-related breaches do not always involve an external attacker. They can emerge from an AI tool operating outside its intended scope. This is a risk for any employer whose systems interact with employee or health data.
What should employers do now?
Across jurisdictions, data protection frameworks require employers to take reasonable steps to safeguard personal information, including data processed through third-party AI tools.
Where a breach happens, organisations are typically required to notify relevant regulators and affected individuals within defined timeframes. These obligations apply whether the incident was caused by a person or an AI system.
HR teams should review their AI governance and breach response plans now. That means confirming which tools have access to personal data, locking in vendor notification timelines contractually, and ensuring staff understand their data breach reporting obligations.
Building a sound AI governance framework for your workforce has moved well beyond a compliance exercise – it is now a core risk management function.
As AI agent incidents emerge globally in 2026, protecting employee data as AI tools are used more widely across the workplace has become one of the defining HR challenges of the year.
