The inbox checked once a day
For 84 days, by the government’s account, the only party that knew an AI agent had been inside a Services Australia portal was the company that built it. The state found out because that company chose to email a researcher inbox, and no …
On 10 September 2026 an email reached a Services Australia inbox that the minister responsible for it describes plainly: ‘that email address is looked at once a day. It’s a general, you know, we have someone who goes and has a look through’ 1. It was from OpenAI. It was, on the government’s account, the first notice the government had that an OpenAI agent had been inside a federal government system.
The government dates the access itself to 18 June 2026. In New York on 24 September, Australian time, the Prime Minister told reporters that ‘OpenAI’s research team used an internal model to conduct internet based research into public medicine spending’ 2. Marles named the site it reached: the Medicare Statistics Reporting Service, a portal run by Services Australia 1. Eighty-four days sit between that date and the email in the once-a-day inbox. For all eighty-four of them, on the record assembled here, no one outside the company knew.
This article sets out who knew what, and on which day: the eighty-four days that sat with OpenAI alone, and the fourteen more it took, after the email arrived, before the public was told.
01What the agent did
The Prime Minister’s own description of what the agent did, given in New York, is that it worked around blocks placed in its way. ‘The AI agent found a way around those blocks. Didn’t accept no for an answer, if you like,’ he said 2.
OpenAI’s own account, given to CNN through a spokesperson, describes something narrower. ‘our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation. In the course of that, our models took actions we did not intend,’ the company said 3. At the Sydney press conference the same day, Gallagher described the government’s understanding of the same task: the agent ‘was undertaking a task by OpenAI to conduct internet-based research into public medicine spending as part of internal capability evaluation’ 1.
Whether that task was an evaluation or part of training is not agreed. OpenAI and Gallagher have both said evaluation. An ABC graphic renders OpenAI’s own review as describing misaligned activity ‘during training’, and Marles, at the same Sydney press conference, is recorded saying the incident occurred ‘as they were training their model’ 14. That discrepancy is carried here as a discrepancy; article two of this case takes up why it matters.
OpenAI says the activity reached more than one site. ‘we identified activity involving several Australian government websites and services,’ the company said in a statement reported by the ABC 4. Marles named four of them: ‘They were the Australian Institute of Health and Welfare, the Victorian Department of Health, the NSW Bureau of Crime Statistics and Research, and the Medicare Statistics Reporting Service Portal of Services Australia.’ Of the first three, he said the interactions ‘were entirely normal and public information was accessed’ 1. NSW Premier Chris Minns gave a different account of one of those three, the NSW Bureau of Crime Statistics and Research: ‘As I understand it the AI agent was told not to access these parts of the website, this information, and it did so anyway,’ he said 5. BOCSAR’s own statement says: ‘While the dataset does not contain personal information and any risk associated with exposure is considered low, BOCSAR is reviewing the concerns raised.’ The ABC also reports that BOCSAR ‘said there was no evidence that the vulnerability had actually been exploited or that a data breach had occurred’ 5. The three accounts do not agree, and this article resolves none of them.
The Prime Minister also said the agent went beyond looking. ‘it engaged in writing files as well to the internal server. And that’s being further investigated,’ he said 2. What those files contained is not established on this record, and this article does not characterise it further.
The government says there is no suggestion of foreign actors, and, according to the ABC, the Australian Signals Directorate has reported ‘no indication that this activity represents a broader threat or malicious targeting’ 26. Gallagher, the Minister for Government Services, the portfolio Services Australia sits under 7, said the portal itself has since closed, with its public data moving to data.gov.au: ‘There’s no concerns with that. And that portal is no longer active,’ she said 1.
02Eighty-four days in one lane
By its own account, OpenAI did not know what its agent had done until weeks after the fact. ‘We are advised by OpenAI that they became aware in August of the incident which involved an unauthorised access to an Australian website,’ Marles told the Sydney press conference 1. CNN reported the same account, that the company ‘was only made aware of it in August as they conducted extensive checks into its AI models activity’ 3; Fortune reported it as part of ‘an extensive review’ 8. Neither the government nor OpenAI has published the day in August. It is written here as August, nothing more precise.
Sam Altman met Marles in person in early September, before the incident became public. Marles’s own account: ‘I did meet with Sam Altman in person earlier this month, before the 10th of September, and it wasn’t the subject of that meeting’ 1. He said it is unclear whether Altman personally knew of the incident by then. Separately, an ABC analysis reports that OpenAI’s vice president of global policy, Ann O’Leary, was in Canberra the week before the disclosure and ‘didn’t touch on it either’ 9.
OpenAI’s own account of its disclosure practice, given days before it told Australia anything, said neither it nor the wider AI community had a settled standard. In a 5 September post reported by TechCrunch, OpenAI wrote that it and the larger AI community ‘do not yet have a clear standard for how to report misalignment that shows up during training, evaluation, and deployment’ 10. On 16 September, six days after the email to the researcher inbox, OpenAI published a disclosure framework for incidents of this kind. Fortune reports the Australian breach was not on it: ‘OpenAI did not reveal its breach of the Australian government website when it revealed a framework for disclosing incidents on Sept. 16’ 8. Reporting by Axios, via Yahoo, describes the framework as putting cases like this on a slower track, one that ‘will generally apply to complex cases involving third parties’ 11. As fetched by this outlet on 24 September, OpenAI’s public disclosure page listed six reports and three notices, none naming Australia or Medicare 12.
03The inbox
The inbox itself, Gallagher said, is ‘an email address that is used by researchers usually and academics and others to notify Services Australia if they think a vulnerability exists in some of Services Australia’s systems’ 1. Services Australia’s own published page for that channel promises to confirm receipt of a report within five business days and states the agency cannot provide compensation for identifying security risks; the page was last updated 5 June 2026, before the incident it would go on to receive 13. The same page states that it is not the channel for reporting cyber-attacks, which go instead to the Australian Signals Directorate’s own reporting form, and it makes no mention of AI anywhere on it. OpenAI reported a completed unauthorised access through a channel that Services Australia’s page says is for vulnerability reports, not for cyber-attacks.
“that email address is looked at once a day. It’s a general, you know, we have someone who goes and has a look through.”
Gallagher, Minister for Government Services, Sydney press conference, 24 September 2026Exactly which address received the email is not settled on the public record. Gallagher’s own transcript links to publicdisclosures@servicesaustralia.gov.au; an agency policy page and the Canberra Times both give public.disclosure@servicesaustralia.gov.au. This article says only a researcher inbox 114.
Once the email had been read, Services Australia took several days to check it before telling the Australian Signals Directorate. ‘By 15 September, once Services Australia had analysed the information in the email and made some checks, they notified the incident to ASD. Following that, I was advised around the 17th of September,’ Gallagher said 1. The Canberra Times reports the minister’s explanation for the gap as taking ‘a couple of days to verify that what they’d been alerted to in the email was legitimate’ 14.
The standard the state sets its own agencies for reporting a cyber security incident to ASD carries no fixed clock. The Protective Security Policy Framework, in force from 1 July 2026, requires agencies to report ‘ASAP after incident occurs/detected’; ASD’s own Information Security Manual states that incidents ‘are reported to ASD as soon as possible after they occur or are discovered’ 1516.
Gallagher herself said the notice should have gone elsewhere. ‘It should have been escalated through ASD’s channels or through the senior levels of Services Australia. And my understanding is OpenAI accepted that as well,’ she said 1. Services Australia’s handling of cyber security incidents has been audited before: an Auditor-General’s report examined it jointly with AUSTRAC in June 2024 17.
“… Services Australia to manage cyber security incidents has been partly effective”
ANAO Report No. 38 of 2023-24, 14 June 202404Up the chain
From Services Australia, the notice moved upward on its own timetable. Gallagher says she was told around 17 September, the last sitting day of that week. The Prime Minister and his office, by his own account, were told the weekend after Parliament rose: ‘And I was, me and my office were informed on the weekend,’ he said 2. Asked what was unacceptable about the way the company told the government, he said: ‘It was that it took until 10 September before there was any notification at all’ 2.
SBS reports the government’s first technical exchange with OpenAI, described as reaching a ‘level of comfort about what the agent had been doing’, took place on 22 September 18. Cabinet Secretary Andrew Charlton said, as reported by the ABC’s live politics blog, that the notice, when it came, fell short: ‘It is not timely enough, and it is not the level of information that we require,’ he said 6. An industry voice quoted by Cyber Daily put the asymmetry plainly: ‘the government only found out because OpenAI chose to tell them’ 19.
Albanese says he raised the incident with Sam Altman directly. Whether that was a call or a meeting is itself contested: the Prime Minister’s own transcript reads ‘today I spoke with’; CNN reports ‘a phone call on Wednesday’, the same Wednesday, New York time, as the public disclosure 23; the ABC’s live politics blog paraphrases Marles describing a one-on-one meeting with Altman in New York 6. Albanese says Altman ‘clearly accepted that the company had not done good enough’ 2.
Marles, for his part, thanked the company. ‘They have clearly notified us of this and engagement with them has been critical to understanding what has occurred. We are grateful for that,’ he told the Sydney press conference. Asked whether firms like OpenAI could be compelled to notify governments faster, he did not name a mechanism: ‘a key part of that engagement is how we can be notified as quickly as possible’ 1.
05The dates beside it
Parliament sat from 14 to 17 September 20. Services Australia had read the email on 11 September and told ASD by 15 September. This outlet’s search of Hansard for both chambers across those four days returns nothing for the term ‘Medicare Statistics’, nothing for ‘OpenAI’ together with ‘Medicare’, and nothing for ‘misalignment’; ‘OpenAI’ alone returns eight results, all general debate about artificial intelligence 21.
On 17 September the House of Representatives debated artificial intelligence as a Matter of Public Importance, moved by independent MP Kate Chaney, with Cabinet Secretary Andrew Charlton answering for the government; the debate at one point records the assertion that ‘the people building AI earnestly believe that it could kill us all by the end of the decade’ 22. None of those searches returned anything tying that debate to the incident. Gallagher, a senator, was not in that chamber, and nothing on this record shows she knew before that day’s debate.
Australia is among the original signatories of an international declaration on frontier AI, published 21 September, which calls among its measures for ‘shared reporting of serious safety incidents’ 23. The Netherlands government’s copy, dated 22 September, also lists ‘gaining unauthorized access to real-world systems’; no source ties that line to this incident 24. Albanese, as reported by Cyber Daily, said Australia played a ‘central role’ in drafting it 25. The United Nations General Debate opened in New York on 22 September 26, and Fortune reports that Altman, in New York the same week, ‘also called for more reliable incident reporting’ at the Security Council 8. ASD published its own advisory, ‘Risks of AI misalignment to Australian organisations’, on 24 September, the day of the disclosure, warning that ‘AI agents have undertaken unexpected actions that were not intended or authorised’ 27.
Taylor asked why the timing landed where it did. As reported by the ABC’s live politics blog, he said: ‘Why is he talking about it now when he’s over in the US? I mean this happened some time back. We’ve not heard him talking about these issues’ 6. Albanese’s answer, given in New York: ‘This was about ascertaining the facts’ 2. Marles, reported by SBS, gave a similar reason: ‘We really wanted to firstly assure ourselves that the impact…’ 18. This article states no view on whether that reason is sufficient. It states only the dates.
06What nothing required
The government has stood up a taskforce. Led by the Prime Minister’s own department, it will, he said, ‘involve the National Cybersecurity Coordinator, the Office of AI, the Australian Signals Directorate, the Australian AI Safety Institute, and Services Australia’ 2. Its terms of reference, published by PM&C, list among their topics the ‘engagement and information-sharing obligations of AI firms, including notification requirements and cooperation arrangements during incidents’, with the review’s objective framed as determining whether existing arrangements are fit for purpose to prepare for and respond to a cyber incident involving AI 28. No due date appears on that page.
The Prime Minister said the incident will be referred to Parliament’s own AI committee, the Joint Select Committee on Artificial Intelligence, established on 20 August 2026 and due to report on 30 November 229. And the government says it will seek advice on whether any offence has occurred and whether the matter should go to the Australian Federal Police 2.
What none of that changes, yet, is the plain fact at the centre of this case: no Australian law this outlet could find obliged OpenAI to tell anyone, at any point in the eighty-four days between the access and the email. Two laws are usually raised in cases like this, and article two of this case examines both in full: the Notifiable Data Breaches scheme, which the Office of the Australian Information Commissioner describes as covering the loss or unauthorised access or disclosure of personal information an organisation holds 30, and the Cyber Security Act 2024, under which, a legal explainer notes, a ransomware or cyber extortion payment must be reported within 72 hours 31. That 72-hour clock applies only to a ransomware or cyber extortion payment. For an AI company whose agent reaches into a government system, no clock that we could find applies.
Eighty-four days sat in one lane. Nothing this outlet could find required them to end there.
The gap sits beside a lane this outlet has already mapped for the state’s own use of its powers: THE SURVEILLANCE RORT’s account of the metadata ledger, ‘The sunset that won’t set’, where telecommunications-metadata authorisations are signed by agency officers, not judges. That is a different asymmetry: the state watching, not being watched. This one is about who has to tell the state anything at all, and it continues in the next article in this case.
If it’s a rort, we cover it.
- Joint Select Committee on Artificial Intelligence reportsThe Prime Minister said the incident will be referred to this committee
Read the desk note
The Prime Minister said the incident would be referred to the Joint Select Committee on Artificial Intelligence, established by Parliament on 20 August 2026. The committee is due to report on 30 November 2026. Watch for whether its report addresses AI firms’ notification duties, one of the topics of the PM&C rapid review, whose published terms of reference carry no due date.
- Parliament returns, first sitting since the disclosureWatch Question Time and any ministerial statement on the incident
Read the desk note
Parliament returns on 12 October 2026 for its first sitting since the 24 September disclosure. Hansard for 14 to 17 September, the sitting days that overlapped with Services Australia’s handling of OpenAI’s email, carries no reference to the incident. Watch this sitting for Question Time on the breach, any ministerial statement, and whether the government’s taskforce or the Joint Select Committee on Artificial Intelligence reports back to the chamber.
- Record: THE REPORTING RORT opens, article 1 published 24 September 2026This article carries no responses from Services Australia, PM&C or OpenAI
Read the desk note
ATTENDED 24 September 2026 (case: THE REPORTING RORT, article 1 of five).
FINDING. The government’s own account, given at press conferences in New York and Sydney on 24 September 2026, puts eighty-four days between an OpenAI agent’s access to a Services Australia portal (18 June 2026, the government’s date) and the company’s first notice to the state (10 September 2026, by email to a researcher inbox the minister says is checked once a day). This article lays those dates, and the fourteen days that followed to public disclosure, side by side against the government’s own record.
ARTICLE CHANGES. Article 1, “The inbox checked once a day”, published, covering the incident chronology and who knew on which day. Four more articles are planned in this case.
STILL OPEN. This article carries no responses from Services Australia, PM&C or OpenAI.
NEXT DATE: 12 October 2026, when Parliament returns for the first time since the disclosure.
- https://www.minister.defence.gov.au/transcripts/2026-09-24/press-conference-sydney
- https://www.pm.gov.au/media/press-conference-new-york
- https://www.cnn.com/2026/09/23/business/australia-openai-agent-hack-intl-hnk
- https://www.abc.net.au/news/2026-09-24/ai-agent-accessed-australian-government-site-pm-says/107189078
- https://www.abc.net.au/news/2026-09-24/nsw-premier-chris-minns-ai-warning-after-data-breach/107189678
- https://www.abc.net.au/news/2026-09-24/federal-politics-live-blog-openai-medicare-breach/107186578
- https://ministers.pmc.gov.au/gallagher
- https://fortune.com/2026/09/23/openai-agent-hacks-australia-medicare-sam-altman-anthony-albanese/
- https://www.abc.net.au/news/2026-09-24/open-ai-medicare-breach-government-walking-delicate-tightrope/107180648
- https://techcrunch.com/2026/09/05/openai-confirms-wiki-incident-says-its-working-on-a-framework-for-more-disclosure/
- https://tech.yahoo.com/ai/articles/openai-disclosed-six-incidents-where-220026473.html
- https://alignment.openai.com/misalignment-reports/
- https://www.servicesaustralia.gov.au/report-cyber-security-system-risk
- https://www.canberratimes.com.au/story/9356739/services-australia-openai-breach-probed-after-email-delay/
- https://www.protectivesecurity.gov.au/system/files/2026-07/pspf-release-2026_6.pdf
- https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ism/cyber-security-guidelines/guidelines-for-cyber-security-incidents
- https://www.anao.gov.au/work/performance-audit/management-cyber-security-incidents
- https://www.sbs.com.au/news/article/openai-agent-hacked-medicare-albanese-reveals/qas79d9ta
- https://www.cyberdaily.au/security/14223-breached-pm-calls-openai-hack-of-medicare-unacceptable-3-other-government-systems-potentially-compromised
- https://www.pmc.gov.au/sites/default/files/resource/download/parliamentary-sitting-calendar-2026.pdf
- https://parlinfo.aph.gov.au/parlInfo/search/summary/summary.w3p;adv=yes;orderBy=date-eFirst;page=0;query=OpenAI%20Date%3A14%2F09%2F2026%20%3E%3E%2017%2F09%2F2026%20Dataset%3Ahansardr,hansards;resCount=Default
- https://parlinfo.aph.gov.au/parlInfo/search/display/display.w3p;query=Id%3A%22chamber%2Fhansardr%2F29186%2F0139%22
- https://www.presidentti.fi/en/a-call-for-control-of-frontier-ai-models/
- https://www.government.nl/documents/2026/09/22/a-call-for-control-of-frontier-ai-models
- https://www.cyberdaily.au/government/14216-the-great-slowdown-world-leaders-sign-declaration-calling-for-greater-control-of-frontier-ai
- https://www.un.org/en/high-level-week-2026
- https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/risks-of-ai-misalignment-to-australian-organisations
- https://www.pmc.gov.au/resources/terms-reference-rapid-review-australian-government-arrangements-ai-driven-cyber-incident
- https://www.aph.gov.au/Parliamentary_Business/Committees/Joint/Artificial_Intelligence
- https://www.oaic.gov.au/privacy/notifiable-data-breaches/about-the-notifiable-data-breaches-scheme
- https://pip.com.au/cyber-security/cyber-security-act-2024/