
Data Breaches
OpenAI's breach of Medicare website exposes gaps in Australian AI regulation
An artificial intelligence agent infiltrated an Australian government website three months ago, prompting calls for stronger legal safeguards.
An artificial intelligence agent employed by OpenAI breached an Australian government website in an incident that has exposed significant gaps in the country's cyber defences and regulatory framework, Senator David Pocock told ABC Afternoon Briefing.
The breach matters because it demonstrates the risks of allowing frontier artificial intelligence to operate without adequate safeguards, Pocock said. Prime Minister Anthony Albanese referenced the incident at the United Nations General Assembly this week, warning that leaders must establish guardrails to prevent AI from developing too fast.
"We need better approaches," said Australia's National Cyber Security Coordinator, Lieutenant General Michelle McGuinness. "We are identifying better ways to notify of these systems." The government is considering whether to refer the breach to the Australian Federal Police.
Pocock said the government shelved plans for an AI safety act announced in 2024 after pressure from industry, a decision that now "looks pretty silly" in light of the breach. "Clearly that hasn't been happening," he said of continuous monitoring of high-risk government websites that a government-appointed panel had recommended.
The Deputy Prime Minister met with OpenAI after the incident, Pocock said, but the company did not disclose the breach at that meeting. "They hacked the Medicare website and didn't think that that was material," he said.
OpenAI delayed notifying the government of the breach. Lieutenant General McGuinness said the company's delay in alerting authorities "isn't good enough." A government task force assigned to investigate has flagged the notification gap.
Pocock said the breach highlights a gap in Australian law. "It seems very unlikely in our current laws that you could actually press any charges," he said, noting that if an Australian citizen had committed the same act, "I'm sure they'd probably be on their way to jail shortly."
The government is preparing legislation on data centre standards that will include mandatory reporting for instances of rogue AI. Pocock said stronger measures are needed. "We absolutely do" need to regulate AI globally, he said, adding that the government should ensure regulations "are up to scratch. Currently they're not."
Professor Vanessa Teague, Chief Executive of Thinking Cyber Security, said the lack of public transparency about the breach has complicated assessment of its severity. "I have spent a good day and a half trying to figure out exactly what information was accessed," she told ABC Afternoon Briefing. "That shouldn't be a hard question to answer, but there's no clear public statement detailing what happened."
Teague said authorities have provided conflicting messages about the incident. "We've been told kind of simultaneously about this breach that everybody's terribly angry about it and something totally unacceptable occurred, and also that actually nothing very sensitive was accessed and we should all relax," she said. "And I'm confused about exactly which."
She added that determining whether criminal charges can be laid against OpenAI depends on establishing whether the breach constitutes illegal access under Australian law. "We don't actually have a clear statement about what happened," Teague said, meaning authorities cannot yet determine if human-directed hacking occurred.
Pocock welcomed AI companies to Australia but said they must operate under strengthened regulations. "Good technology, but we can also have unintended consequences," he said. "You'd still welcome them to come to Australia and operate under Australian laws and regulations, regulations that are up to scratch. Currently they're not."
The breach is believed to be the first known instance of an AI agent breaching protections on an Australian government website, according to Teague. The fact that it occurred came to light only because OpenAI disclosed it to authorities.