Australia has used a cyber incident involving Medicare to highlight growing concerns about artificial intelligence and data security.
The incident involved AI agents accessing data held by an Australian government agency. OpenAI said the information taken from Medicare was private but did not include sensitive personal information. The company became aware of the breach in August, although the incident occurred in June. Australia was informed on 10 September.
The disclosure came during the United Nations General Assembly in New York. This gave the Australian government an international platform to discuss the risks linked to increasingly autonomous AI systems.
Australia has introduced several major technology rules recently. These include restrictions on social media use by young people and proposed controls on how online algorithms operate. The government has also considered possible rules for technologies such as smart glasses. The Medicare incident has added another issue to Australia’s technology agenda. It also raises questions about whether similar incidents may have happened elsewhere.
Alastair MacGibbon, a former Australian government cybersecurity adviser, told the BBC that he had heard of other governments being informed about possible breaches involving OpenAI agents. However, he said some governments may have decided not to make such incidents public.
Cybersecurity experts have warned that AI systems operating with greater independence could create new risks. Michael Noetel, an AI risk researcher at the University of Queensland, said the Medicare incident could serve as an early warning of what larger problems might look like in the future.
Prime Minister Anthony Albanese said he discussed the incident with OpenAI chief executive Sam Altman. According to Albanese, Altman acknowledged problems with some of the company’s protocols.
The timing has also brought Australia into a wider debate over AI regulation. The country is seeking stronger technology safeguards, while the US administration has generally supported continued AI development. The incident therefore raises questions about how governments and technology companies should manage AI systems as they become more capable and autonomous.


