Medicare breach reignites debate over AI safety and accountability
While authorities say no personal health records were accessed, the incident is set to become a test case for how Australia responds to increasingly sophisticated AI systems
Australia is launching a taskforce to counter “emerging (artificial intelligence) cyber threats” after a rogue OpenAI agent hacked into Medicare data, Deputy Prime Minister Richard Marles said.
Fronting press on Thursday, just hours after Prime Minister Anthony Albanese revealed the breach, Mr Marles said the taskforce would be led by the Department of Prime Minister and Cabinet, giving the Prime Minister direct visibility.
“This will be a task force that will be rapid,” he said.
“It will look at this incident thoroughly but it will also examine our posture in respect of emerging AI cyberthreats.”
The taskforce will review government network security, existing legal arrangements and whether current safeguards remain fit for purpose as AI technology evolves.
“All of this, I think, we can take as a warning in relation to the development of AI itself,” Mr Marles said.
“It is so important that this technology, which represents such an enormous opportunity for humanity, is nevertheless being developed in a way where the guardrails, the safeguards, are well ahead of the capability itself, and that’s why the Prime Minister, along with other world leaders in New York over the course of this week, has put out a call to ensure that AI is developed in a safe way with guardrails in place.”
According to Government Services Minister Katy Gallagher, Services Australia was notified by OpenAI on 10 September that an AI agent had accessed infrastructure behind the public-facing Medicare Statistics Reporting Service portal while conducting internet-based research as part of an internal OpenAI capability evaluation.
The portal contains publicly available Medicare and Pharmaceutical Benefits Scheme (PBS) statistical information. The government has stated that claims data, payment processing systems and individual records were not affected.
“Services Australia have a forensic investigation that’s been that’s underway and they will provide a final report to me,” she said.

Speaking in New York on Thursday (AEST), the Prime Minister confirmed a public-facing portal had been “infiltrated” by an AI agent in June this year, with OpenAI made aware in August.
The Australian government was only told of the breach in September.
“The AI agent accessed both public and non-public files,” Mr Albanese said.
“A forensic investigation, aided by the Australian Signals Directorate, is now underway to ascertain more information, including what other government systems were affected.
“The Medicare statistics Reporting portal is a public facing statistics portal that contains non-sensitive Medicare information relating to data and statistics, such as spending.”
He said no personal information was believed to have been accessed but stressed investigations were ongoing.
“Evidence currently available is there is no broader compromise to the Services Australia network,” he said.
“Nonetheless, this situation is obviously unacceptable.”
Mr Albanese said he was aware three other systems “may have been impacted”.
They included the Australian Institute of Health and Welfare, the NSW Bureau of Crime Statistics and Research, and Victoria’s Department of Health.
Independent Senator David Pocock said the breach highlighted gaps in Australia's regulatory framework.
“This is a very concerning but ultimately unsurprising breach of Australians’ data by an AI agent,” he said.
“It again highlights how slow the Australian Government has been to implement appropriate safeguards for AI in high risk settings.”

Senator Pocock questioned why the government had not progressed a National AI Safety Act and argued existing proposals did not place sufficient obligations on AI companies to report breaches or other high-risk incidents.
“There is also a big question here around why we aren’t holding these big tech companies liable for this kind of data breach,” he said.
“If it was an Australian who hacked the system they’d likely be heading for jail, yet there’s no accountability for AI companies developing this technology.”
The government has indicated legislative changes remain a possibility.
Cabinet Minister Murray Watt said authorities would examine whether criminal charges could be pursued and whether existing laws are adequate.
“If it is possible to press criminal charges, that will happen,” Senator Watt told Seven’s Sunrise.
“But what it also highlights is that we do need to ensure that Australian laws are keeping pace with this new and emerging technology.”
Email: rebecca.cox@news.com.au



