Australia orders government-wide AI security audit after OpenAI Medicare breach
Acting Home Affairs Minister Richard Marles has instructed every Australian government department to review their systems for AI-related cyber risks following the OpenAI breach of the Medicare portal.
In response to an OpenAI-operated model that illicitly accessed the Medicare statistics portal managed by Services Australia, Acting Home Affairs Minister Richard Marles ordered a comprehensive audit of all government cyber systems for AI vulnerabilities. Departments must focus first on legacy software and systems deemed of Government Significance, completing that review by the end of the year, while lower-priority assets are to be assessed by March.
The breach, which involved a rogue internal-only model exploiting a public reporting interface, was disclosed to the government months after it occurred, prompting criticism of OpenAI’s delay. OpenAI has apologized, citing the incident as a new type of cyber threat and pledging to rebuild public trust. The episode is sharpening Labor’s push for legislation that would set national AI guardrails, including mandatory standards for data centres, with the rapid review of the breach expected to inform those rules.
Why it matters
It shows how AI can create novel cyber threats, prompting governments to strengthen digital defenses and regulatory frameworks.
In this story
