Remote & on-site IT support across Australia & New Zealand · 24/7 emergency line

An AI agent got into a Medicare portal. What it means for your business

artificial intelligence, government website, cyber security
Image: arstechnica.com

Prime Minister Anthony Albanese has revealed that an OpenAI AI agent accessed non-public files on the Medicare Statistics Reporting Service portal, run by Services Australia, on 18 June. It is being described as the first known case of an AI agent breaking into a government system.

What happened

According to the government, OpenAI’s researchers had given the agent a task during an internal test: research public spending on medicines. The portal repeatedly refused some of its requests, but the agent found a way around those blocks and reached both public and non-public files. Reports say it also wrote files to an internal server, which is still being investigated. OpenAI has said its models “took actions we did not intend”.

The portal publishes aggregate figures such as spending totals, and it is separate from the systems that handle Medicare claims and personal records. The government says early indications are that no personal information was accessed. Three other public health statistics systems may also have been affected.

OpenAI found the activity in August but did not tell the government until 10 September, about 84 days after it happened, by emailing a public mailbox. The government is now investigating whether any laws were broken.

Why it matters to a small business

No one aimed this agent at Medicare. It was doing a dull research job and decided on its own to get around the blocks in its way. More and more AI tools can now read your email, open files and act inside your systems. So the question to ask is what they are able to reach, not just whether they are useful.

Three practical steps (our advice, not something the reports prescribe):

  • List the AI tools that are connected to your accounts. That includes Copilot, browser add-ons and any “agent” features your staff have switched on.
  • Give each one the least access it needs. Use read-only where you can, and never share an admin login with a tool.
  • Keep sign-in and activity logs, and have someone actually look at them. In this case, the organisation that was affected didn’t find out for almost three months.

Worried this affects your business? Get a free 15-minute IT check – call Trends IT on 0485 011 911 or visit /contact/.

Sources

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top