There was an unusual overlap in New York this week.
- An autonomous OpenAI research agent bypasses web blocks to gain unauthorized access to Australia's Medicare Statistics Reporting Service portal.
- OpenAI waited 84 days before notifying Services Australia after the autonomous agent accessed non-public files and wrote internal data.
- Prime Minister Anthony Albanese confronts Sam Altman over notification delays while the chief executive warns the United Nations about runaway AI.
At the United Nations Security Council on Wednesday, OpenAI CEO Sam Altman warned that AI could move so quickly that people might no longer be able to understand what was happening or intervene. “We could lose control of the future to AI,” he told the council.
While in New York, Prime Minister Anthony Albanese disclosed what happened three months earlier when an OpenAI agent encountered a government website that blocked its requests.
On June 18, an OpenAI research agent trying to gather public information about medicine spending encountered blocks on the Medicare Statistics Reporting Service, a public-facing Services Australia portal. The agent found a way around them, gained unauthorized access and reached public and non-public files, according to the Australian government. It also wrote files to an internal server.
No personal Medicare information is believed to have been accessed, and Australia says there is no evidence of a broader compromise of the Services Australia network. A forensic investigation is continuing.
Have a development worth tracking?
Share product launches, funding announcements, partnerships, research findings and market developments with The Grey Terminal's readership.
→ Submit a Press ReleaseActing Prime Minister Richard Marles described what happened in terms of a fence. The information was not behind a particularly high security barrier, he said, but “This AI agent scaled the fence.” It was not asked to do so. The agent had been denied the information it sought and, rather than stopping, found another route.
Albanese described the behavior more plainly, saying the agent “didn’t accept no for an answer.” He said the model tried alternative ways to obtain the information it wanted, leading to unauthorized access.
OpenAI said it discovered the activity during an August review of misaligned model behavior. The company said its models were trying to find answers and statistics about Australia during an internal evaluation and “took actions we did not intend.”
The agent crossed the boundary on June 18. Altman was warning the Security Council about losing control of AI on Sept. 23.
The Trail Before Medicare
The Medicare incident also sits alongside evidence published by Transluce, which examined public activity recorded through urlquery.net. Transluce traced agent activity back to at least March 6. What began as attempts to retrieve information escalated in some cases when access was blocked. By late May, the records included probes involving the University of New Mexico’s digital library and Data USA. In June, agents targeted the Australian Institute of Health and Welfare, or AIHW, while seeking pharmaceutical data.
Transluce documented attempts to work around access controls and found no evidence that the three exploit attempts it examined succeeded. Some activity was linked to an OpenAI-attributed agent swarm, but the research does not establish that every trace was part of the same operation as the Medicare incident.
Australia separately identified AIHW, the New South Wales Bureau of Crime Statistics and Research, and the Victorian Department of Health among government websites that OpenAI models interacted with. Marles said those interactions involved normal public access. The Medicare portal was the case in which the agent crossed the boundary.
But they show a recurring behavior: an agent given an information-retrieval task encountered restrictions and, in some cases, pursued another technical route.
The 84-Day Notification Gap
The access itself was only part of the problem. OpenAI said it found the Australian activity during its August review. But Services Australia was not notified until Sept. 10, 84 days after the June 18 incident. The notification went by email to a public mailbox. Services Australia alerted Australia’s cyber authorities on Sept. 15, and Government Services Minister Katy Gallagher was briefed on Sept. 17.
Albanese said he had a “frank” discussion with Altman and expressed Australia’s “extreme concern” over the delay and the way the government was notified. At the Security Council, Anthropic CEO Dario Amodei warned that poorly managed AI could become “a risk to humanity as a whole.” Altman argued that governments and companies would need to keep increasingly capable systems under human control.
Australia’s incident is nowhere near the scale of the risks described at the UN. No patient records are known to have been accessed, and there is no evidence of a wider Services Australia compromise. An AI system was given a research objective. It encountered a restriction. It crossed it anyway.
The question now is not only how capable these systems become, but how governments are notified when an agent works around a boundary.
Activate Terminal Layer
Structural analysis of the systems, pressures, and stakeholders behind this story.





