Updated 9:25 AM EDT, September 25, 2026
On September 25, technology experts warned that the OpenAI agent hacking of an Australian website will not be the only dangerous breach of government data, and called for Australia to strengthen its protections against the growing risk, according to a<a href="https://www.theguardian.com/australia-news/2026/sep/25/ai-hack-medicare-australia-vulnerabilities” rel=”nofollow noopener” target=”_blank”>report byThe Guardian.
Anna-Maria Arabia, chief executive of the Australian Council on AI Strategy, toldGuardian Australia, “Frontier AI now has the capability to expose those vulnerabilities at a rate quicker than we can keep up, quicker than we can patch them.”
She said Australia needed to quickly improve its ability to detect and report incidents and should host AI training labs domestically.
Delayed Reporting of the Incident
Prime Minister Anthony Albanese met OpenAI chief Sam Altman on September 23, after anOpenAI agent gained unauthorized access to the Australian government systems, including the Medicare Statistics Reporting Service portal.
OpenAI alerted the government on September 10 about the breach, which occurred in June, sending notice Albanese described as unacceptable
The agent also interacted with websites operated by the Australian Institute of Health and Welfare, Victoria’s Department of Health, and the New South Wales Bureau of Crime Statistics and Research, according toThe Guardian.
Officials said there was no evidence that patient records had been accessed, but an investigation, assisted by the Australian Signals Directorate (ASD), was ongoing.
Experts demand mandatory incident reporting and clearer AI standards
Johanna Weaver, Australia’s former chief cyber negotiator at the United Nations, toldGuardian Australiathat governments must “draw a clear line: if companies cannot control their AI systems, they should not release them publicly.”
Olivia Shen of the US Studies Centre argued that AI companies should not be allowed to determine their own disclosure obligations for hacks and breaches. “We just don’t know how big the problem is. It could be the tip of the iceberg, but either way, we can’t be ignoring the risk,” Shen toldThe Guardian. She said the incident strengthened the case for clear national AI standards, including mandatory incident reporting.”
The ASD is reviewing the government’s preparedness against such AI attacks. They are also considering how AI companies should report such incidents and how cooperative they should be during and after an attack.
Detection gaps and governance must-haves
The timeline of the breach: unauthorized access in June, and the disclosure on September 10 know quickly when an AI system interacts with their data
Experts are using the incident to push for mandatory incident reporting and clearer AI safety standards in Australia’s national framework, arguing AI firms should not self‑determine disclosure obligations.
Chief data officers (CDOs) need to ensure thatAI governanceplans account for delayed discovery and disclosure as foreseeable scenarios, with explicit contractual and technical controls in place for any AI system accessing or processing organisational data.
Related Stories
Similar Topics
Artificial IntelligenceData ManagementDiversityTestimonials
Shape the Data Leadership Agenda
Exchange Knowledge & Experience
About
Community
Events
Partner with Us
Contact Us
Submit Content
Join Our CommunityPrivacy
