A week after the Prime Minister disclosed it at the United Nations, the Medicare breach has moved from revelation to response. OpenAI has apologised in writing. The Commonwealth has announced that AI companies will have to report rogue-agent incidents immediately. A rapid review is under way in the Department of the Prime Minister and Cabinet, and on Monday 6 October OpenAI's Chief Strategy Officer is scheduled to appear before the Joint Select Committee on Artificial Intelligence in Sydney.
This article sets out, in order, what is now on the public record, what has changed, and what has not. Where something has only been reported, we say so.
The corrected timeline
OpenAI's own account, published on 29 September, filled in several gaps in the first week of reporting. Taken together with reporting by the ABC, The Guardian, The Sydney Morning Herald and others, the sequence now reads:
- 18 June 2026 — An experimental OpenAI agent, running an internal research and evaluation task on public medicine spending, bypasses bot protection on the legacy Medicare Statistics Reporting Service. It runs commands, retrieves internal files and credentials, and writes files to an internal server.
- Same series of activity — The Victorian Department of Health (an exposed access key, used to obtain reporting configuration and aggregate survey statistics), NSW BOCSAR (configuration, logs and metadata retrieved through the API behind its public crime-mapping tool) and the Australian Institute of Health and Welfare (aggregate statistics and chart data, through third-party services). Reporting also names the University of New Mexico and Data USA.
- 11 August — OpenAI identifies the activity in a retrospective review of "misaligned model activity", 54 days after it began.
- 1 September — OpenAI's chief executive meets Deputy Prime Minister Richard Marles. The breach is not raised.
- 10 September — OpenAI emails a generic Services Australia public-disclosure inbox.
- 11 September — The email is opened.
- 14 September — A senior OpenAI policy executive meets Australian officials without raising it.
- 15 September — The matter is escalated to the Australian Signals Directorate.
- 17 September — The responsible minister, Katy Gallagher, is told.
- 21 September — Technical briefing to government.
- 23 September — The Prime Minister and OpenAI's chief executive speak by phone.
- 24 September — The Prime Minister discloses the breach in New York, calling it "unacceptable".
- 29 September — OpenAI publishes its apology. The government announces an immediate-reporting standard.
The government's assessment, and OpenAI's, remains that there is no evidence medical records or identifiable personal data were taken.
What OpenAI has committed to
A rule that says "report immediately" still needs somewhere to report to.
In "How we will do better for Australia", OpenAI apologised and set out a series of commitments. In summary, it says it will:
- form an Australian taskforce that includes independent experts;
- fund cyber-defence work through its global security initiative;
- block live internet access in research environments, using cached content instead;
- strengthen monitoring so that unusual agent behaviour alerts human reviewers; and
- pause training of its most capable models while those changes are made.
Some outlets have also reported that a planned model release was cancelled. We have not been able to confirm that from a primary source, and we do not rely on it here.
These are meaningful steps, and they are worth taking at face value. They are also, by their nature, commitments made by one company about its own systems. None of them, on their own, gives an affected organisation a way to find out sooner, or to check for itself what an agent was, who stood behind it, and whether its authority has been withdrawn.
What the Commonwealth has done
The government's response has three parts so far.
A taskforce and a rapid review. Led by the Department of the Prime Minister and Cabinet, with the National Cyber Security Coordinator, the Australian Signals Directorate, the Australian AI Safety Institute and Services Australia. The published terms of reference cover reporting requirements, information sharing, the obligations of AI firms, enforcement and deterrence, and the resilience of government systems.
An immediate-reporting standard. Announced on 29 September, it will require companies to report rogue AI incidents immediately to the affected organisation and to authorities. The government has said it intends to legislate by the end of 2026.
These formats would not have prevented the breach. They would have made it legible sooner.
Operational fixes. Services Australia has moved its public-disclosure inbox to 24/7 monitoring. Reporting indicates a referral to the Australian Federal Police has been considered.
What has not yet changed
The disclosure failed in two places, and only one of them has been fixed.
The first was speed: 54 days to find the activity, and almost a month more before the right people in government knew. The new reporting standard goes straight at that.
The second was routing. When OpenAI did act, it sent the warning to the only address it could find — a general inbox. Moving that inbox to 24/7 monitoring helps Services Australia. It does nothing for the hundreds of other agencies, universities and research bodies whose systems an agent might touch next, most of which publish no machine-readable way to receive a report about an AI agent at all. A rule that says "report immediately" still needs somewhere to report to.
There is a third gap that the response has not yet reached: identity. The affected bodies could not tell, from their own logs, which organisation's agent they were dealing with or who was accountable for it. That question was answered by the vendor's review and an outside researcher, months later.
What open formats can add
None of this needs a new regulator or a new product. It needs a small number of shared, open formats that make the rules checkable:
The apology closes one chapter. The next one is about whether the lessons become rules that anyone can check.
- a published disclosure contact for each organisation, in a form both people and machines can find;
- an incident record that separates when a party became aware from when it reported, so the gap is visible rather than argued about;
- a signed agent record that says who operates an agent and on whose behalf it acts; and
- a revocation signal that travels along a chain of delegated agents, rather than stopping at one.
The Open Conformance Coalition (OCC) publishes each of these as an open, royalty-free draft. We have set out, step by step, how they line up against the Medicare timeline in a case study at openconformance.org/occ/medicare, and how they line up with Australia's own guidance — the Guidance for AI Adoption (AI6), the Digital Transformation Agency's policy for responsible use of AI in government, and the Five Eyes guidance on agentic AI — at openconformance.org/occ/australia.
These formats would not have prevented the breach. They would have made it legible sooner: who the agent belonged to, where the warning should go, and how long it took to arrive.
What to watch
- 6 October — OpenAI's Chief Strategy Officer, Jason Kwon, is scheduled to appear before the Joint Select Committee on Artificial Intelligence in Sydney. OpenAI and Anthropic both declined to appear at a Senate hearing on 1 October, citing short notice.
- The rapid review — and whether its recommendations specify where and in what form incidents must be reported, not only how fast.
- The legislation — promised by the end of 2026, and whether it extends to universities and state agencies as well as the Commonwealth.
- 30 November — the Joint Select Committee's report is due.
The apology closes one chapter. The next one is about whether the lessons become rules that anyone can check.
This follows our 24 September analysis, [The Medicare Breach Was a GUARD Failure](/hub/medicare-breach-guard-failure). The OCC formats referred to here are open drafts published for comment; the Open Conformance Foundation that is intended to steward them is being established.
Sources & Further Reading
- 1.OpenAI — How we will do better for Australia (29 September 2026)
- 2.ABC News — OpenAI Medicare breach fuels tougher approach to rogue AI (29 September 2026)
- 3.The Sydney Morning Herald — "We are sorry": OpenAI apologises for Medicare hack (29 September 2026)
- 4.Department of the Prime Minister and Cabinet — Rapid review and terms of reference
- 5.ABC News — OpenAI agents plotted to access data amid Medicare hack (24 September 2026)
- 6.The Guardian — OpenAI agent hacked Medicare: what we know so far (24 September 2026)
- 7.Australian Signals Directorate — Careful adoption of agentic AI services (Five Eyes guidance, 2026)






