> ## Content Index
> Fetch the complete content index at: https://www.dailyferment.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# OpenAI's agent got into Medicare. It told the bug inbox, 84 days later.
- URL: https://www.dailyferment.com/openai-medicare-portal-breach-duty-to-report/
- Published: 2026-10-07T16:00:00.000Z
- Updated: 2026-10-07T15:59:59.000Z
- Description: An OpenAI agent reached a Medicare portal on 18 June. OpenAI told Australia on 10 September, through the inbox researchers use to report bugs. Road law says the one who caused it reports differently.
- Author: Rana Bilal Zafar
- Tags: Where Systems Meet People, AI, Security, #reframe

Yesterday, 6 October, OpenAI's chief strategy officer Jason Kwon sat in front of Australia's Joint Select Committee on Artificial Intelligence in Sydney and apologised. "We are sorry and we know we have work to do to rebuild trust with the Australian people," he said, as reported by IAPP.

The apology was for something that happened on 18 June, when an OpenAI agent, running in an internal evaluation, got into the Medicare Statistics Reporting Service portal run by Services Australia. OpenAI says it found out on 11 August. It told Australia on 10 September. And the way it told them is the part I keep coming back to.

The question I want to work out: when it's your own system that did the damage, who are you supposed to tell, and how fast?

## What happened, and who was told when

ABC published the timeline on 24 September. Breach on 18 June. OpenAI becomes aware on 11 August "during a review of OpenAI misaligned model activity during training". Sam Altman meets Australia's Defence Minister Richard Marles in San Francisco on 1 September and, Marles says, doesn't mention it. On 10 September OpenAI sends an email to publicdisclosures@servicesaustralia.gov.au, which ABC describes as "an address used by academics and researchers to notify weaknesses in Services Australia's systems". Services Australia sees it the next day, tells the Australian Signals Directorate on 15 September, and the Prime Minister announces it on 24 September.

That's 84 days from the event to the notice, and 30 days from OpenAI knowing to OpenAI telling.

OpenAI's own account, quoted by ABC, is that its models were looking up answers about Australia "during an internal evaluation" and "took actions we did not intend". It found no evidence of patient records being accessed; what was reached was aggregate health statistics and internal file names.

## Was it even a hack?

My first reaction was that this is a simple case of a company sitting on bad news. Then I read The Record's piece from 25 September. Alexander Martin reports that the portal's archived code "explicitly directed visitors to an unauthenticated endpoint", a guest door the site itself pointed to. Ciaran Martin, who used to run Britain's National Cyber Security Centre, told him: "It's still unclear if what's happened would constitute a hack in the normal sense of the term."

So maybe the agent walked through a door that was left open. That would make the government's language too strong. But I don't think it changes the question about the notice, and the reason comes from somewhere a long way from AI.

![Timeline from 18 June (agent reaches the Medicare portal) to 11 August (OpenAI aware), 10 September (email to the public disclosure inbox) and 24 September (PM announces), above two boxes: the passer-by's channel, a researcher reporting a weakness, and the driver's duty under section 170, stop and report whether or not at fault](https://storage.ghost.io/c/d7/b7/d7b77195-48c5-45ab-8688-51750879d1d6/content/images/2026/10/df34-duty.png)

The researcher's inbox or the driver's duty? Sources: ABC News, IAPP, Road Traffic Act 1988 s170.

## The driver's duty doesn't depend on fault

Section 170 of the UK's Road Traffic Act 1988 applies when an accident happens "owing to the presence of a mechanically propelled vehicle on a road or other public place" and someone is hurt or property is damaged. It doesn't ask whose fault it was. The driver "must stop" and give their name and address to anyone with reasonable grounds to ask. If they don't, they must report it to the police "as soon as is reasonably practicable and, in any case, within twenty-four hours".

The law draws a line between two people who might both see the same dented car. A passer-by who notices it can tell someone, or not, through whatever channel they like. The driver whose car caused it has a duty that starts the moment it happens, runs to the owner or the police, and has a clock on it. And it holds even if the other car was badly parked.

Read OpenAI's notice against that. The publicdisclosures inbox is the passer-by's channel. It exists so outsiders who spot a weakness can say so. OpenAI wasn't an outsider who spotted something. Its agent was the vehicle. Kwon more or less said this himself at the hearing: "I think people were thinking about this as a technical situation, and they wanted to contact the technical counterparties." In hindsight, he said, it would have been more appropriate to report directly to government officials.

That framing, a technical situation, is the passer-by's framing. It turns "our agent went somewhere it shouldn't" into "your website has a weakness". Both might be true. Only one of them is the reporter's to say.

I wrote earlier about [OpenAI catching an agent in 15 minutes and stopping it after 2.5 hours](https://www.dailyferment.com/openai-agent-dns-escape-alert-to-kill-gap/). That was the gap inside the company. This is the gap outside it, and it was much longer. And the question I asked when [an agent caused an outage and nobody was clearly on call for it](https://www.dailyferment.com/incident-caused-by-ai-agent-who-is-on-call/) applies here too: someone has to own the moment after.

## Where the comparison breaks

A driver knows they've hit something, usually at once. OpenAI says it didn't know for almost eight weeks, and only found out by reviewing logs of misbehaving runs. The 24 hour clock in section 170 assumes you felt the bump. For agents running at scale, the honest version might be a clock that starts at discovery, plus a duty to look. That second part is the one no rule I know of asks for yet.

The other difference is that nobody was hurt here, as far as anyone has said. Section 170 still applies to property, though, and a government's systems are property. The pledge from Anthropic's Dave Orr at the same hearing, as ABC's live blog reported it, was to tell the Australian government "within a matter of days, or sooner". That's a promise, not a duty. But it's the driver's version, not the passer-by's.

## What I'm confident of, and what I'm not

The dates and the inbox are established from ABC's timeline, and Kwon's words come from IAPP's report of the hearing. Whether the agent hacked anything, or used a door the site left open, is disputed and I can't settle it. That the driver's duty is the right model for AI labs is my inference. Whether any law will put a clock on it is a guess, though Anthropic's people said at the hearing they'd welcome clearer reporting rules.

The claim, in one sentence: when your own system causes the damage, you aren't a bug reporter, you're the driver, so the duty is to stop and report to the owner fast, whether or not it turns out to be your fault.

## Sources

ABC News, "OpenAI hacked Medicare portal, Prime Minister Anthony Albanese says", 24 September 2026\. https://www.abc.net.au/news/2026-09-24/ai-agent-accessed-australian-government-site-pm-says/107189078

IAPP, "OpenAI outlines updated safety measures in response to Australia Medicare portal breach", 6 October 2026\. https://iapp.org/news/a/openai-outlines-updated-safety-measures-in-response-to-australia-medicare-portal-breach

ABC News, "OpenAI executive flew to Australia to apologise over Medicare hack. Here are the key takeaways", 6 October 2026\. https://www.abc.net.au/news/2026-10-06/openai-hearing-apology-key-takeaways/107235640

ABC News, federal politics live blog, 6 October 2026\. https://abc.net.au/news/2026-10-06/federal-politics-live-blog-coalition-migration-oct-6/107230622

Alexander Martin, "Doubts grow over claims OpenAI agent hacked Australian Medicare portal", The Record, 25 September 2026\. https://therecord.media/openai-australia-breach-cyber

Road Traffic Act 1988, section 170\. https://www.legislation.gov.uk/ukpga/1988/52/section/170