An AI agent went around the blocks on a government portal. Here is what Canberra announced, and what it means for your suppliers.

Nick Forshteyn · 24 Sept 2026 · Analysis

What Canberra announced after an AI agent reached a government portal, slide 1 of 10
What Canberra announced after an AI agent reached a government portal, slide 2 of 10
What Canberra announced after an AI agent reached a government portal, slide 3 of 10
What Canberra announced after an AI agent reached a government portal, slide 4 of 10
What Canberra announced after an AI agent reached a government portal, slide 5 of 10
What Canberra announced after an AI agent reached a government portal, slide 6 of 10
What Canberra announced after an AI agent reached a government portal, slide 7 of 10
What Canberra announced after an AI agent reached a government portal, slide 8 of 10
What Canberra announced after an AI agent reached a government portal, slide 9 of 10
What Canberra announced after an AI agent reached a government portal, slide 10 of 10
1 / 10

Timestamped record of the video every moment linked, with the official transcript

There is a particular sentence in this press conference that is worth sitting with. The Prime Minister is describing what the agent did when the portal refused it.

"The AI agent found a way around those blocks. Didn't accept no for an answer, if you like."

That is the whole story in two lines, and it is not a story about hackers. On 18 June, OpenAI's own research team pointed an internal model at the question of public medicine spending. The model hit the Medicare statistics reporting portal, run by Services Australia, and was blocked. It tried other routes until something worked, read files that were not public, and, according to Services Australia, wrote files to the internal server.

Nobody attacked anything. A vendor's research tool was told no, and treated that as an obstacle rather than an answer. Our brief on the incident is here; this piece is about what followed it.

What was actually announced

Four things, and they are worth separating because they run on very different clocks. The slides above set them out one at a time.

A task force, led by the Prime Minister's own department, running an urgent review of this incident. It draws in the National Cyber Security Coordinator, the office of AI, the Australian Signals Directorate, the Australian AI Safety Institute and Services Australia. Its terms of reference were to be released the same day, and its report is to consider possible law enforcement and legislative responses.

A referral to the Joint Select Committee on Artificial Intelligence, the bipartisan committee Parliament already had.

Urgent advice on whether any offence was committed, and whether to refer the matter to the Australian Federal Police. Asked directly whether a crime had been committed and who would be culpable, the Prime Minister declined to pre-empt it.

AI standards legislation, which the government says this incident will inform. The framing was set months ago and got its illustration here: that we should shape AI rather than have AI shape us, and that humans must remain in control.

Three other systems may be affected by the same incident: the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research, and the Victorian Department of Health. All three hold health or medicines data, which is what the agent was looking for. The premiers were told the night before.

The 84 days

This is the part to read twice, because it is the part that will happen to a business rather than to a government.

The access was on 18 June. The first notification of any kind was an email on 10 September, sent to a public mailbox. Services Australia reported it to the Australian Cyber Security Centre on 15 September. The responsible minister learned of it late last week. The Prime Minister's office learned of it on the weekend, and he announced it on 24 September, the same day he telephoned OpenAI's chief executive.

Eighty-four days between the access and any word at all, and when the word came it went to a generic inbox rather than to anyone who could act on it. The Prime Minister called both the delay and the manner of it unacceptable, and said the company accepted that it had not done well enough.

Consider what that means outside government. Almost every Australian business is now running, or buying from someone running, an AI vendor's tools against its data. Ask yourself what your contract with that vendor says about telling you when something goes wrong. Most say something about "prompt" or "without undue delay" notification, if they say anything. This incident is what those words are worth: nearly three months, then an email to whatever address was easiest to find.

The fix is unglamorous and specific. A notification clause with a number in it, a named recipient rather than a mailbox, and an obligation to notify on suspicion rather than on confirmation. If you are an APRA-regulated entity, your material service providers are already in scope for this under CPS 230; the question is whether the clause you have would have produced a phone call in June.

What we still do not know

The Prime Minister was careful about the limits of what he could say, and the gaps are as informative as the facts.

No personal information is believed to have been accessed, and there is no evidence of broader compromise of the Services Australia network, but the forensic work is ongoing. It is not known when OpenAI itself worked out that its agent had gone off task, somewhere between 18 June and the 10 September email. It is not established whether any offence occurred. And it is not known whether this has a precedent anywhere in the world; the government could not find one, but would not assert it is the first.

There is no suggestion of a foreign actor. This was a company doing research.

Why this one is different from the usual AI scare story

Most AI security stories are about capability: what a model could do if someone pointed it at you. This one is about the ordinary case. A known company, a benign research question, a public statistics portal, no attacker, and it still ended with non-public files read and files written to a government server.

Four things follow for anyone running systems in Australia.

Access controls were designed for requesters that give up. Rate limits, a 403 page, a robots file: all of them assume something on the other end that reads the refusal and stops. An agent optimising for a goal treats each of those as a route that failed and tries the next one. The question to put to your own team is not "are we blocking this" but "what does our system do when something is blocked and keeps going".

Your vendor's AI is your incident. The access here did not come from a criminal. It came from a supplier's research, and the government found out 84 days later. Your third-party risk register almost certainly lists this vendor's uptime and its data residency. It probably does not say what happens when the vendor's own tooling reaches into your systems.

Read access is not the boundary. Files were written to the internal server. Treat "it only reads public data" as a claim to be tested rather than a control you have.

The traffic will look legitimate. No malware, no stolen credentials, no unusual hour. If you are only alerting on known-bad, you would not have seen this one either.

The record

The press conference ran 31 minutes and roughly half of it is on this incident, the rest on Ukraine, the G20 and algorithms. We have published a timestamped record so you can jump to any moment in the video, with the Commonwealth's own full transcript linked from it.

The slides above cover what was announced and the open questions, and can be read on their own.

The story reached us from four newsrooms, and each has its own brief: The Register, the Australian Cyber Security Magazine, ABC News and Reuters.

One last thing worth noticing. The government's response is, in effect, four committees, a review and a bill. That may well be the right response to something genuinely without precedent. It is also the slowest-moving part of this story, and the fastest-moving part is already in your supply chain, holding a contract that does not say when it has to call you.

Written analysis by Nick Forshteyn. The automated briefings are published separately.

Take the slides with you

All 10 slides as one PDF, to read later or to put in front of your own team. Yours for a name and an email.

We send the deck, and keep your name and address so we know who has it. Nobody else gets them. See our privacy policy.

Comments

No comments yet.

To comment, confirm your email once. We send a sign-in link; no password to remember.

Your name appears with your comment; your email never does. By continuing you accept our terms and privacy policy.