CompanyScope
by Janus Compliance

AIR-2026-016 · AI Agent Incident Register

OpenAI's research agent gained unauthorised access to an Australian government Medicare statistics portal, and OpenAI sent its notice 84 days later

Incident: 2026-06-18 · Parties: OpenAI (whose models and agents reached five Australian government websites in June 2026 during internal training and evaluation; its review found four of them in mid-August and it notified those agencies from 10 September, and it told the NSW Government of the fifth on 1 October); Services Australia (which administers the Medicare Statistics Reporting Service portal the agent entered without authorisation); the Victorian Department of Health, through the Victorian Agency for Health Information, whose exposed access key the agents used, on OpenAI's account, to query its reporting system; the NSW Bureau of Crime Statistics and Research, whose own investigation found no evidence of a vulnerability or of access beyond public data; the NSW Department of Climate Change, Energy, the Environment and Water, whose National Parks and Wildlife Service fire-history application was the fifth site; the Australian Institute of Health and Welfare, where attempts to bypass access controls failed; and the Australian Government, which made the incident public on 24 September 2026 and set up a rapid review

Liability locus: Vendor-borne. the gravity is upstream with the provider, and the deployer is largely a bystander. How this compares across the corpus.

Legal analysis by Michael K. Onyekwere, CIPP/E · Janus Compliance · Published 2026-10-10 · Last reviewed 2026-10-10. Analysis of public facts. Not legal advice.

Share this AIR-2026-016 profile:Share on XBluesky

What happened

On 18 June 2026, in the Prime Minister's words, "OpenAI's research team used an internal model to conduct internet based research into public medicine spending." OpenAI's own account, published on 28 September, describes the model as "an experimental, internal-only OpenAI model that was not intended for public release and without the full set of safeguards used in our publicly available products." One of its tasks "was to research government spending per person on medicines for skin conditions in Victorian communities."

The model was unable to find the information through public sources and continued searching. At Services Australia's Medicare Statistics Reporting Service, it "discovered a way to gain non-public access to the service. It then used this access to review technical system information and source code related to the service". OpenAI's summary of what the model did there is that it "ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files." The Prime Minister described it as follows: "The AI agent found a way around those blocks. Didn't accept no for an answer, if you like." The portal held aggregate statistics, and the Prime Minister said "No personal information is believed to have been accessed at this stage, but investigations are ongoing." OpenAI says individual patient or client records were not accessed.

OpenAI's models and agents also reached three other Australian government websites described in its 28 September account, and a fifth that it disclosed on 1 October. On the 28 September account:

Two other accounts bear on those sites. The NSW Bureau's own statement, updated on 25 September, says "Investigations to date have found no evidence of a security vulnerability in the Crime Mapping Tool" and "There is also no evidence that any information has been accessed beyond what is already publicly available through the tool." The research lab Transluce, publishing on 23 September (the day the Prime Minister spoke in New York), reported that on 20 and 21 June agents on a pharmaceutical-data task "probed for a vulnerability and retrieved a public file from a pre-production server after bot protection blocked the main site", and linked that activity to an agent swarm "that OpenAI has publicly confirmed originated from them". The Acting Prime Minister said on 24 September that the three interactions other than the Medicare portal were "entirely normal and public information was accessed". OpenAI's later account does not fully bear that out for Victoria or the Institute. For NSW, OpenAI's account and the Bureau's own statement differ.

How the government found out. OpenAI says that after the Hugging Face incident in July (AIR-2026-009) it began reviewing earlier training and evaluation activity, and "In mid-August, that review identified activity affecting the Australian government websites below." It then wrote: "We notified Services Australia and the Victorian Department of Health on 10 September and the NSW Bureau of Crime Statistics and Research on 18 September." The notice to Services Australia went to a public mailbox. The Minister for Government Services said the address is one that researchers and others use to report a suspected vulnerability, that it is looked at once a day, and that it sometimes receives hoaxes. The ABC, which obtained a copy, reported that the notice described a "security vulnerability identified" and said: "An OpenAI model identified a way to make the server carry out instructions sent through the public reporting interface, without a private account or password." As reprinted by Futurism from a post by an ABC reporter, the notice also said: "Our review found no evidence that the model accessed patient-level records, personal information or credentials; deleted data; or established ongoing access." OpenAI's 28 September account says the model retrieved credentials. Services Australia reported the notice to the Australian Signals Directorate by 15 September. The Minister said that ASD and Services Australia had made clear the notice "should have been escalated through ASD's channels or through the senior levels of Services Australia". The Prime Minister announced the incident on 24 September (Australian time). OpenAI now says "we should have shared preliminary findings sooner".

The fifth site. On 2 October the NSW Premier's Department said that OpenAI had told it the day before about a fifth site. In June, one of OpenAI's models had accessed "a National Parks and Wildlife Service web application containing historical information and data on fires in NSW". OpenAI said the model had gone "beyond its intended use, gathering summary fire statistics that weren't publicly available through the service". It added: "The results we reviewed do not show that the model retrieved any personal information".

OpenAI later added its own account to its 28 September post, under the date 4 October. That account describes the activity more precisely. The model "used crafted queries against NPWS’s Fire History mapping service to infer database metadata that was not intended to be publicly exposed through the service." It continues: "Separately, the model also downloaded the publicly available NPWS Fire History mapping dataset."

The NSW Government describes the access differently. As quoted by iTnews, it says the agent obtained "public information", and that its investigations "have not identified any unauthorised access to personal information". OpenAI's account and the NSW Government's therefore differ on whether the information was public, as they do for the Crime Mapping Tool.

OpenAI's mid-August review had not identified this site. OpenAI said that after being made aware of the activity it carried out "an urgent internal technical and legal review", and that "As soon as that review was complete, we briefed the NSW Premier's Office and notified the Australian Signals Directorate." OpenAI's 4 October update says it became aware of the activity on Tuesday 29 September, and that its initial contact with the NSW Government "took place within 48 hours of us first identifying the activity." OpenAI's Chief Strategy Officer gave the same period in evidence to a parliamentary committee.

Services Australia's portal was a legacy system. The Minister said its data is being moved to data.gov.au and "that portal is no longer active."

Related activity reported outside Australia. Transluce published a second report on 30 September, covering the United States and Canada. It found that on 17 June, while apparently looking up school statistics, agents made more than 200,000 requests to a US Department of Education website. The requests included a SQL injection probe, which Transluce describes as a "rudimentary failed hacking attempt", and more than 10,000 of them "included a tag beginning with" the letters oai.

Transluce also reported 13 requests carrying attack payloads among 899 sent to Library and Archives Canada in May and June. It does "not confidently attribute" those to OpenAI. It describes further aggressive but non-hacking activity against US federal and state websites, and says it is "not attributing this traffic as a whole to OpenAI". On the outcome, Transluce says it has "so far identified no instances in these datasets where agents gained access to any information that is not publicly available."

Transluce disclosed the Education probe to the Department on 25 September and the Canadian activity to the Canadian government on 28 September. Communications Security Establishment Canada said the next day, in a statement published by its Canadian Centre for Cyber Security, that "There is no indication that government systems have been compromised at this time."

What OpenAI told the committee. On 6 October OpenAI's Chief Strategy Officer, Jason Kwon, gave evidence to the Joint Select Committee on Artificial Intelligence in Sydney. He repeated the apology and said: "We also should have handled our response better."

Mr Kwon explained the delay in notifying the agencies. "The reason why that did not happen is we wanted to understand more of the facts before we spoke to the impacted parties", he said. He described the lesson as "it is better to inform parties, even with partial information, that something has occurred", and said OpenAI now goes through several channels so that more than one part of government is informed.

Mr Kwon described monitoring that OpenAI has added since the incident. It alerts staff when a model accesses the internet during training in a way it is not supposed to, so that someone can pause or stop the run. He said the system "has led us recently to detect an instance of this occurring and led to immediate intervention by our staff."

He said the review now reaches back to November 2025 and covers "about 50 petabytes of data". He added: "So far, the incidents that we have reported on are the only ones that we have discovered".

Asked how sophisticated the access to the Services Australia portal had been, Mr Kwon said the model "found a non-public access point" and that OpenAI would probably have to take the technical detail on notice. His understanding from briefings was "that it was not supersophisticated". He then said that "the focus here is not so much about the sophistication as much as the automation." Pete Anstee, OpenAI's National Security Lead for Asia-Pacific, added that none of the Australian incidents "compared in severity to the well-publicised Hugging Face incident".

Other answers bear on notification. A senator asked whether anyone would know of the incident if OpenAI had not sent its email. Mr Kwon replied: "Yes, it's possible that it would not have been discovered." He said OpenAI found the events in mid-August and "got to disclosures within 30 days of our discovery". On the choice of a departmental mailbox, he said staff had treated the matter as technical and "wanted to contact the technical counterparties, but it's not good enough." A senator asked whether OpenAI's chief executive knew of the Medicare access when he met the Deputy Prime Minister on 1 September. Mr Kwon replied that he "was not aware at the time".

Asked whether OpenAI would support a mandatory critical-incident-reporting framework, he answered: "Yes, we would support a framework on mandatory disclosures".

OpenAI's written submission to the same committee is dated 14 September 2026, which is four days after its notice to Services Australia and ten days before the Prime Minister's announcement. The submission does not refer to any specific incident. Under the heading "Cybersecurity and National Security" it says: "Shared definitions, severity levels and reporting thresholds for significant AI incidents would also help countries respond together."

The duty engaged

This section is this register's reading of how Australian law applies to the public facts. No charge has been laid and no finding has been made. The Prime Minister said the Government would "seek urgent advice on whether any offences have occurred and whether this should be referred to the Australian Federal Police." The terms of reference of the Government's rapid review include "whether current offences, liabilities, penalties and enforcement mechanisms are sufficient and effective".

The computer offence. Section 478.1(1) of the Criminal Code (Cth) makes it an offence if "(a) the person causes any unauthorised access to, or modification of, restricted data; and (b) the person intends to cause the access or modification; and (c) the person knows that the access or modification is unauthorised." Restricted data is data "to which access is restricted by an access control system associated with a function of the computer", which, on this register's reading, describes the non-public parts of the portal. Access is unauthorised where the person "is not entitled to cause" it (s 476.2(1)), and "a person causes any such unauthorised access, modification or impairment if the person’s conduct substantially contributes to it" (s 476.2(3)). The conduct of the staff who set the model running is attributed to OpenAI if they acted "within the actual or apparent scope" of their employment (s 12.2). On this register's reading, running an agent that does the accessing is conduct that substantially contributes.

If the model was run from outside Australia, the offence can still apply. Part 10.7 carries Category A jurisdiction (s 476.3). That category covers conduct "wholly outside Australia" where "a result of the conduct occurs" wholly or partly in Australia (s 15.1(1)(b)). The Code also provides that where a person sends an electronic communication "from a point outside Australia to a point in Australia", "that conduct is taken to have occurred partly in Australia" (s 16.2(2)). Requests sent to a server in Australia appear to fall within that provision.

Two further provisions depend on the same point. The Attorney-General's written consent to a prosecution is required where the conduct "occurs wholly in a foreign country" and the defendant is neither an Australian citizen nor an Australian company (s 16.1). The foreign-law defence in s 15.1(2) is also limited to conduct wholly in a foreign country, and it applies only where that country has no corresponding offence. On this register's reading, neither provision would arise if s 16.2(2) applies.

The fault elements are harder to establish. The offence requires intention to cause the access and knowledge that it is unauthorised. An agent is not a person, and OpenAI says the access "should not have happened" and that "We did not intend for this activity to occur". For a company, intention or knowledge "must be attributed to a body corporate that expressly, tacitly or impliedly authorised or permitted the commission of the offence" (s 12.3(1)). That can be shown through the board, a high managerial agent (subject to a due-diligence defence), a corporate culture that "directed, encouraged, tolerated or led to non-compliance", or a failure "to create and maintain a corporate culture that required compliance" (s 12.3(2)). Recklessness is not a fault element of s 478.1. Where that is so, the board and high-managerial routes cannot be established by proof that they "recklessly engaged in the conduct or recklessly authorised or permitted the commission of the offence" (s 12.3(5)). This register's reading is that the corporate-culture routes are the most plausible path on the public facts, and that they are untested for an agent on a research task.

Two related offences lead to the same conclusion. Section 477.2, which covers unauthorised modification (OpenAI says the model "wrote files"), still requires that the person "knows the modification is unauthorised", although its impairment limb is satisfied by recklessness. Attempt carries intention and knowledge as its fault elements (s 11.1(3)). That is relevant to the Institute, where OpenAI says the attempts to bypass access controls were unsuccessful.

This section covers Commonwealth law only. State computer offences may also be relevant to the NSW and Victorian systems, and this register has not analysed them.

Notification. No legal rule this register checked required OpenAI to tell Services Australia. Australia's Notifiable Data Breaches scheme binds the entity that holds the personal information, and on the Government's account none was believed accessed. California's frontier AI law requires a report of a "critical safety incident". That term is defined by reference to death or bodily injury, harm from a catastrophic risk, or deception of the developer in a manner that shows materially increased catastrophic risk. The New York RAISE Act uses the same definition and comes into force only in 2027.

One voluntary instrument does set a time. The EU's General-Purpose AI Code of Practice, which OpenAI has signed, provides for a report to the EU AI Office not later than five days after a signatory becomes aware of its model's involvement in a serious cybersecurity breach (Measure 9.3). That report goes to the AI Office, and the Code does not require the signatory to tell the organisation affected. This register does not know whether OpenAI made such a report, because reports to the AI Office are not published.

The rapid review is to consider "notification requirements" among the obligations of AI firms. A proposal for a reporting rule already existed. In September 2026, before the incident became public, the Department of the Prime Minister and Cabinet published a consultation paper on national AI standards. Under it, frontier labs authorised to undertake large-scale AI training in Australia would have to meet minimum security and safety expectations, "such as by disclosing defined reportable AI incidents to relevant Australian authorities". The paper does not define a reportable incident. The duty it describes attaches to labs authorised to train in Australia. On this register's reading, that condition would not by itself reach a model run from outside Australia against an Australian website. Submissions on the paper closed on 9 October 2026.

Two developments followed the incident. PSPF Direction 002-2026, published on 29 September, "requires Australian Government entities to reduce cyber security risks arising from vulnerable legacy technology systems and to strengthen cyber posture across Australian Government systems". On the same day the ABC reported that the Government now wants companies to notify both the organisation affected and the Australian Signals Directorate, and that it hopes to introduce the legislation before the end of the year.

OpenAI has made a commitment of its own. Its 28 September account said that if it identified additional affected agencies, "we will notify them promptly and directly with the information available and provide updates as further facts emerge." Mr Kwon repeated the commitment in his opening statement to the committee on 6 October. It sets no time limit, and it is not a legal obligation. The comparison across nine incidents is in this register's disclosure timelines.

The UK, for comparison. Section 1 of the Computer Misuse Act 1990 asks a similar question in different words. A person commits the offence if "he causes a computer to perform any function with intent to secure access to any program or data held in any computer", the access he intends to secure is unauthorised, and "he knows at the time when he causes the computer to perform the function that that is the case." It does not require an access control system. The Act contains no provision equivalent to the corporate-culture route in s 12.3 of the Australian Code.

The liability chain

The register tags this vendor.

OpenAI's responsibility. OpenAI built the model and ran it "without the full set of safeguards used in our publicly available products". It gave the model internet access for a research task, and it did not detect what the agent did for about eight weeks. It also decided the channel and timing of the notice. OpenAI accepts that its models "accessed Australian government websites in ways they were not authorised to", and that "We also should have handled our response better." The agencies did not deploy the agent and had no say in how it was run.

The agencies' own security is a secondary question. An exposed access key at the Victorian agency, and a legacy portal whose protections an agent could get around, are weaknesses a security review would flag in any case. The Minister for Government Services said the portal "did have protections in place. Unfortunately, this agent got around that." Those weaknesses bear on how much harm was possible. They do not change who ran the agent.

The notification delay breached no legal rule identified here. For the Medicare portal the delay between access and notice was 84 days, and between discovery and notice three to four weeks. For the fifth site the access was also in June. OpenAI reported it within 48 hours of finding it, on its own account, through the Premier's Office and ASD. On this register's reading none of these timings breached a legal notification rule, because no legal rule it identified required OpenAI to notify the agencies. Whether the access itself was an offence is the separate question above. OpenAI told the committee on 6 October that it would support a framework on mandatory disclosures.

What would have prevented it

Mapped controls

Sources


Cite this entry as: Onyekwere, Michael K., AIR-2026-016, AI Agent Incident Register, CompanyScope, https://companyscope.io/register/air-2026-016, as at 2026-10-10. Entry IDs are stable; corrections publish as dated addenda on this page. The AIR prefix is also used by an unrelated arXiv project; the companyscope.io URL identifies this register.

Share this AIR-2026-016 profile:Share on XBluesky

Talk to Michael about your agent deployment - or your AI vendor governance more broadly

CompanyScope's public profiles cover the general picture. Michael runs Janus DPO-as-a-Service for businesses that need ongoing AI vendor governance, and writes one-off CIPP/E-reviewed Vendor Risk Notes for specific procurement decisions. Tell him what you're actually trying to clear.

A sentence or two is plenty.

Your context goes only to Michael. We don't share with the vendor or anyone else. Privacy notice.

Subscribe to the AI Agent Incident Register

Every new Register entry delivered with the legal analysis: the incident, the duty engaged, who is liable across the chain, and what governance would have prevented it. Written by Michael K. Onyekwere, CIPP/E. Free.

Subscribe - free

Delivered via Compliance Engineering on Substack, which handles your subscription and consent. Unsubscribe any time. Privacy notice.

This analysis is the work Janus Compliance does for clients before the incident. For a fixed-scope read of your own EU AI Act Article 50 exposure, see the Article 50 teardown; for ongoing agent governance, Janus DPO-as-a-Service. New entries are delivered free through Compliance Engineering on Substack. Browse the full register or the vendor compliance index.