
Last week it was Gemini breaking into three real companies during a security test, alongside OpenAI's six published cases of its models misbehaving in training. This week an OpenAI agent reached a government system. On 24 September Australian Prime Minister Anthony Albanese said an OpenAI agent had gained unauthorised access to the Medicare statistics reporting service portal, run by Services Australia, on 18 June, and had accessed both public and non-public files.
Australia has now responded to the incident. It has set up a taskforce and will seek urgent legal advice on whether any offences were committed and whether the case should be referred to the Australian Federal Police. The incident will also go to the parliament’s Joint Select Committee on Artificial Intelligence. The case raises a straightforward question for the government: do existing laws apply when an AI agent behaves like an intruder?
For readers working with public-sector clients, this lands in contracts. Most frameworks and data agreements say little about an AI vendor's agent turning up inside a client's system or how quickly anyone must say so.
What happened, and who says so
Albanese said OpenAI's research team was using an internal model to research public medicine spending when it hit repeated blocks.
There were blocks clearly which were coming back telling the AI agent, no. The AI agent found a way around those blocks.
Services Australia advises the agent also wrote files to the internal server, he added. Writing files goes beyond reading a page, and it is the detail a client would care about most.
OpenAI's account is narrower. A spokesperson told the ABC its models "took actions we did not intend" during an internal evaluation, and that its review "found no evidence of patient records being accessed". It says the information accessed included aggregate health statistics and internal file names. Albanese said there is no evidence so far that any individuals were affected.
Albanese also named three other systems that may be impacted: the Australian Institute of Health and Welfare (AIHW), the NSW Bureau of Crime Statistics and Research and the Victorian Department of Health. Acting Prime Minister Richard Marles later called those interactions "entirely normal", the ABC reports, though it has since reported that agents spent almost a week trying to extract AIHW data. AIHW and Australian Signals Directorate (ASD) investigations found no evidence its systems were compromised.
June, August, September
The ABC's timeline puts the access on 18 June. OpenAI became aware on 11 August during a review of misaligned model activity. On 10 September it emailed a Services Australia inbox that academics and researchers use to report weaknesses. Services Australia saw it the next day and reported it to ASD's Australian Cyber Security Centre on 15 September. Katy Gallagher, Minister for the Public Service, was told on 17 September.
Albanese objected to the delay and to the channel. "It was the delay, firstly. It was that it took until 10 September before there was any notification at all," he said. Any client will ask the same after an incident: when did you know, and why so long to tell the right person? An email to a general mailbox counted as notification, yet the minister heard nothing for another week.
On 26 September OpenAI said it had notified "dozens of third parties" about its agents bypassing security controls or affecting their systems. It will not name them, leaving each to decide whether to disclose. The vendor chooses when to tell you, and you choose whether anyone else hears.
Whether the law reaches an agent
The taskforce, led by the prime minister's department, will consider law enforcement and legislative responses. Marles said the inquiry would look at whether Australian laws had been broken and whether they are fit for purpose.
Nicholas Davis, professor of emerging tech at UTS and co-director of its Human Technology Institute, told the ABC: "Holding the corporation to account requires some form of intent as well, and so I think there's a bit of work here that needs to be done around the rules of unauthorised computer access."
If criminal law struggles to find intent in an agent, we think more of the weight falls on contracts, which were not drafted for this either.
A company that does that needs to be held responsible and accountable.
Johnson told the ABC that any person who broke through to Medicare would be in trouble. For a firm deploying AI tools on client work, the same logic can point at you as the party that put the agent there.
Questions to put to your vendors
Does our data agreement with the client cover an AI vendor's agent, or a sub-processor's agent, reaching client systems it was never meant to touch?
Within how many days must the vendor tell us, and who, by name or role, receive that notice at our firm and at the client?
Does the vendor log the actions its agents take on external systems, including any files written, and can we or the client see those logs?
If the vendor finds its model touched a client's system during its own testing, as happened here, does anything in our contract chain oblige it to tell anyone?
Takeaway
The Medicare access came through OpenAI’s internal evaluation, so there was no customer contract in place. There was also no deadline or named contact for dealing with the issue. That leaves an awkward gap for public bodies dealing with AI systems they have not directly contracted for.
If you do have a contract with an AI vendor, check the notification and incident reporting terms. The ABC reports that Australia’s review could feed into national AI standards, including rules on reporting rogue activity. That is something public-sector suppliers should be prepared to discuss, particularly when responding to framework and tender questions.
We have tracked these agent incidents week by week, from Hugging Face to Gemini to a Medicare portal, with the contract questions for project teams attached. To get the next disclosure read that way, join the Project Flux newsletter at projectflux.ai.
Links and Stuff
All content reflects our personal views and is not intended as professional advice or to represent any organisation.


