After the OpenAI Medicare story

Before you give an AI tool access

An AI didn’t go rogue. A company gave it a job and didn’t stop it at a locked door. The same question applies to every tool you connect to your email, your files, or your clients’ data: who gave it the job? This page is three checks to run before you do.

Sources opened and quoted on 2 October 2026

01

What happened

  1. 18 June 2026During OpenAI's own testing, its AI gets past the blocks on an Australian government website with Medicare statistics.
  2. 11 August 2026OpenAI finds out.
  3. 10 September 2026OpenAI tells the Australian government, by a generic email to a public inbox.
  4. 1 October 2026OpenAI tells a second government, New South Wales, about a national parks website its AI also got into in June.
“In the course of that, our models took actions we did not intend.”
OpenAI, quoted by ABC News, 24 September 2026.
“The AI agent found a way around those blocks – didn’t accept no for an answer.”
Prime Minister Anthony Albanese, quoted by Al Jazeera, 24 September 2026.
“The government was only informed by a generic email to a low-level public inbox on September 10.”
ABC News, 26 September 2026.
02

What this means, and why you should care

It wasn't a one-off

OpenAI says it has notified "dozens of third parties", among them governments and universities. The kinds of things its agents did: used leaked passwords to log in, got into the back end of websites, got around subscriptions and other access barriers, and posted to other sites.

ABC News, 26 September 2026

It kept trying

ABC News reports that AI agents "spent almost a week trying to access Australian health data". ABC also notes those attempts have not been formally linked to the Medicare breach.

ABC News, 26 September 2026

It isn't only OpenAI

In August, Meta said its own AI model hacked another company during cybersecurity testing, after reaching the public internet because of an error in how the test was set up.

Al Jazeera, 24 September 2026

The warning system was weak on both sides

OpenAI found the breach in its own review, months later. Then the public inbox it emailed "was only monitored once a day", and it took Services Australia five days to tell the country's cyber agency. That inbox is now watched around the clock.

ABC News, 29 September 2026

Why you should care if you run a business. You are on both sides of this story. Your website, booking page, or client portal is a locked door someone else’s agent may push on. And the agent you connect to your inbox may be the one pushing on someone else’s.

These agents are given a task and work toward it. When the task meets a locked door, a person stops and asks. The Medicare agent found another way in. So the question is not whether your tools are clever. It is what they are allowed to touch, and who hears about it when they go further.

“You design your systems so that you don’t trust anybody by default.”
Chetan Arora, Monash University, quoted by ABC News, 29 September 2026.
03

Three checks before you connect a tool

1. What can it reach?

Give it the smallest access that still does the job. If it only needs to read your calendar, don't let it edit your calendar. If it only needs one folder, don't connect the whole drive.

Ask yourself: if this tool did the worst thing its access allows, what would that be? If the answer is "email every client" or "delete my files", cut the access down first.

2. What does it do when it hears no?

The Medicare website said no, and the AI found another way in. Your tools will hit locked doors too: a login, a paywall, a missing permission.

If the tool has a setting that makes it ask you before it sends, deletes, buys, or logs in somewhere, turn it on. Watch the first few runs yourself before you let it work alone.

3. Who gets told when something goes wrong, and how fast?

Open the privacy policy of the tool. Search for the words "breach", "incident", and "notify". Look for a time frame: how soon will they tell you?

If it doesn't say, now you know. And if the tool is yours, set up by you for your business, then the person who has to tell your clients is you.

Not sure whether your tool is an agent at all? Start with the agent guide. Pasting client data into a chatbot? Check the data-use settings first.

04

The one-minute checklist

  • I know exactly which accounts and folders this tool can reach.
  • It has the smallest access that still does the job.
  • It asks me before it sends, deletes, buys, or logs in anywhere.
  • I watched it run at least a few times before letting it work alone.
  • I searched the privacy policy for "breach" and know whether they promise to tell me, and how fast.
  • I know who I would tell, and how, if it touched client data it shouldn't have.
05

What this page does not say

  • This is not legal advice. What you have to report, and to whom, depends on where you are and what data you hold.
  • In the Australian case, the government said there was no evidence any personal information was accessed. What was accessed was aggregate health statistics and internal files.
  • Australia's new reporting rule is not law yet. The government says it hopes to introduce the legislation before the end of the year, and the reporting has no published deadline.
  • I have not reviewed any specific app's privacy policy for this page. The checks are what to look for, not a verdict on any tool.
06

Sources