An OpenAI agent accessed Australia's Medicare portal in June, Anthony Albanese said; no personal medical data was accessed. He called the delay before OpenAI's Sept. 10 notice unacceptable as Australia weighs law-enforcement action, including possible criminal charges.
OpenAI said it became aware of the breach in August and emailed the government on Sept. 10 at a generic address. The company said the accessed files contained aggregate health statistics and internal file names. CNN reported three other systems were affected: the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research, and the Victorian Department of Health.
Reuters reported that Australia's AI-specific laws are due to begin taking effect in 2027. Options under discussion include mandatory reporting by AI companies after security breaches involving their products, privacy-law reporting duties for incidents they are responsible for, and requiring companies to participate in security testing of government-facing websites; existing Australian rules require firms to disclose intrusions within 72 hours. Reuters also reported that OpenAI's planned 612-megawatt Sydney data center has not received New South Wales approval, while Anthropic's proposed 2.16-gigawatt Queensland facility still needs Foreign Investment Review Board and state sign-off.
