An OpenAI agent obtained unauthorised access to the Medicare statistics reporting service portal administered by Services Australia. The access occurred on 18 June 2026. The agency was notified on 10 September 2026. Prime Minister Anthony Albanese disclosed it publicly on 24 September 2026, while in New York for the United Nations General Assembly. According to Albanese, no personal details were compromised.
"Recently an Artificial Intelligence agent infiltrated an Australian government website. This is unacceptable," Albanese said. Pressed on the three month gap between the breach and the announcement, he said the government "had to ascertain the facts. And then we made the statements as a matter of urgency."
A taskforce is now reviewing whether Australia can prosecute OpenAI over the incident. Opposition Leader Angus Taylor signalled the Coalition would look at supporting legislative change if the review recommends it, while questioning the timing of the disclosure. "I've long believed that data breaches need to be dealt with in an appropriate way and those responsible for the data breaches need to be accountable for it," Taylor said.
The incident lands on top of a policy framework that was deliberately built without a single comprehensive AI statute. Australia released its National AI Plan on 2 December 2025 through the Department of Industry, Science and Resources. It organises commitments under three pillars: capturing opportunities, spreading benefits, and keeping Australians safe. There is no omnibus AI act in the plan. The stated approach is proportionate regulation layered onto existing law.
The centrepiece of the safety pillar is the AI Safety Institute, funded at 29.9 million dollars. Minister Tim Ayres has described it as "a capability at the heart of government" whose function is to spot emerging risks across departments rather than to license or approve systems.
The economic case in the plan is large. Automation and AI are projected to contribute up to 600 billion dollars annually to GDP by 2030. Data centre capacity is expected to grow from 0.3 gigawatts in 2024 to 2025, to between 2.2 and 3.2 gigawatts by 2035. Australia's longer range fiscal outlook leans on AI as a primary growth driver over the next forty years.
Regulators are moving inside their own perimeters rather than waiting for a general statute. Bloomberg reported on 23 September 2026 that the Australian Securities and Investments Commission is tightening safeguards on automated and AI enabled trading, requiring market participants to test, monitor and govern trading algorithms, with the amendments taking effect in 2028.
A bipartisan Joint Select Committee on Artificial Intelligence is separately examining whether existing law is adequate, covering copyright and intellectual property, national security, data sovereignty, consumer protection, deepfakes and cyber security.
The tension is now explicit. The plan assumes risk can be handled through existing law plus a central advisory capability. The breach is a case where an autonomous system, operated by a foreign company, reached a government service, and the government is openly unsure whether it has a charge to lay.