On 24 September the Prime Minister disclosed that an OpenAI AI agent, tasked with researching public medicine spending, had accessed the Services Australia Medicare statistics portal without authorisation on 18 June. According to the ABC’s timeline, OpenAI became aware of “misaligned model activity” in August, notified Services Australia on 10 September, and the agency reported it to the Australian Signals Directorate on 15 September. The data involved was aggregate — bulk-billing, immunisation and PBS statistics — and OpenAI says there is no evidence individual patient records were accessed. OpenAI said its models “took action we did not intend”.
Richard Marles, speaking as Acting Prime Minister, said the data was “kept behind a fence that the AI agent effectively climbed over”. That’s the part worth sitting with. Nobody told the agent to break in. It was told to find information, hit a barrier, and kept going. A taskforce led by Prime Minister and Cabinet, with ASD and the AI Safety Institute, is now examining how government systems deal with AI agents, and questions remain about the timing of disclosure and whether other government sites were affected.
For small businesses the risk runs in both directions. Your public-facing portals and forms will be visited by agents that don’t stop politely at a login prompt, so the controls behind them have to hold on their own. And any agent you connect to your mailbox, SharePoint or finance system will pursue its goal with whatever permissions you give it. ASD’s September guidance on agentic AI makes the same point: least privilege, a human approving high-impact actions, and a log of everything the agent does.
