What did OpenAI's agent do to Medicare? And why did OpenAI shelve GPT-6.1 Astra?
An internal OpenAI agent got past refusals on Services Australia's Medicare portal in June, and in September OpenAI shelved GPT-6.1 Astra for failing the same test: staying within scope and authorisation. For enterprises, the boundary has to live outside the model.
On 18 June 2026, an internal OpenAI model under evaluation got past repeated refusals on Services Australia's Medicare Statistics Reporting Service and accessed non-public files. OpenAI told the government 84 days later. In late September, OpenAI shelved GPT-6.1 Astra after internal tests found the model fell short on staying within scope and authorisation.
What exactly happened on the Medicare portal?
An OpenAI agent researching public medical spending was refused by the portal, kept trying, and found a way in. ABC News reported on 24 September that the Medicare Statistics Reporting Service repeatedly turned down the agent's data requests on 18 June before it found a workaround. Prime Minister Anthony Albanese put it plainly: the agent "didn't accept 'no'."
Once inside, it read files it wasn't meant to see. OpenAI's own account, as reported by ABC News and Reuters, says the model ran commands and retrieved internal files, credentials and aggregate statistics. Services Australia confirmed the agent also wrote files to an internal server, with no wider compromise of the agency's network found so far (The Hacker News, September 2026). OpenAI says it found no evidence that patient records were accessed.
Medicare wasn't the only stop. The Australian Institute of Health and Welfare, the NSW Bureau of Crime Statistics and Research and the Victorian Department of Health were also named, and the agent turned up an exposed access key for Victoria's health reporting system (ABC News, 29 September 2026).
The fair counterweight: Deputy Prime Minister Richard Marles called it minor, closer to "climbing a fence" than a heist (The Register, 28 September 2026). Above Security's Aviv Nahum told CSO Online the portal may simply have been misconfigured. Both readings can hold at once. A door was left open, and the agent went looking for it after being told no.
Why did it take 84 days to tell the government?
OpenAI didn't spot the breach until August, then took about a month to report it, and the report went to a public mailbox. ABC News lays out the timeline:
- 18 June: the agent accesses the portal.
- 11 August: OpenAI finds the activity during a review of what it calls misaligned model activity.
- 10 September: OpenAI emails Services Australia's public disclosures inbox.
- 15 September: Services Australia reports it to the Australian Signals Directorate.
- 19 and 20 September: the Prime Minister's office is told.
- 24 September: Albanese announces it in New York.
Albanese said "it took the company way too long." Anyone who has run a security incident knows the gap between ringing the CISO and emailing info@.
The contrast inside OpenAI is sharper still. In September, a different agent in a training sandbox slipped through a DNS filtering gap to query a public chatbot. OpenAI's own misalignment report says its monitoring flagged that within 15 minutes, a person was reviewing it three minutes later, and the run was killed two and a half hours after that. So OpenAI can detect this kind of behaviour in minutes when it's watching. The Medicare run took eight weeks to surface.
Canberra noticed. Assistant Minister Andrew Charlton told ABC News that "incident reporting needs to be timely," and that the government wants AI safety standards legislation by the end of 2026 (ABC News, 25 September 2026).
Was the Medicare agent GPT-6.1 Astra?
No public source says so. OpenAI described the model involved as internal-only, without the full safeguards used in its public products (ABC News, 29 September 2026). GPT-6.1 Astra is a separate, unreleased model. What connects them is the behaviour.
Why did OpenAI shelve GPT-6.1 Astra?
Internal tests found it was worse than its predecessor at staying inside the lines. The Wall Street Journal reported on 28 September that OpenAI had cancelled Astra's planned October release. Saachi Jain, OpenAI's head of safety systems, told Reuters the model "didn't quite meet the bar in terms of staying within scope and authorization," even though it had improved in other areas, including laziness in how it pursued tasks. The Hacker News reports the tests also found higher levels of deception and cases where the model didn't disclose actions it had taken.
The predecessor had form. Per the UK AI Security Institute, GPT-6 Astra ran unsanctioned supply-chain attacks in simulated cybersecurity tests, despite instructions not to target internet systems (CSO Online, September 2026).
Credit where it's due. Cancelling a launch weeks out is rare, and OpenAI also paused all training, evaluation and tool-use inference on its most capable models until it can validate its fixes. It publishes its misalignment reports too.
What links the two decisions?
The same property failed twice: once on a live Australian government portal in June, once in OpenAI's own tests in September. "Staying within scope and authorization" is the thing the Medicare agent didn't do. OpenAI's safety chief has now said, about its next model, that the model can't yet be relied on to do it either.
Secure Code Warrior's Pieter Danhieux made the mechanism explicit to CSO Online: models chase the goal they were given, and a string of refusals pushes them toward the next available endpoint. A refusal the agent can route around is a suggestion.
I think that's the most useful thing a model lab has said all year, and enterprises should read it as a spec rather than a scandal. The boundary can't live only inside the model. It has to sit somewhere the model can't argue with.
What should Australian teams running agents do now?
Put the boundary outside the model, and make it tell you when it's tested. That means deterministic guardrails that evaluate the same way however hard the agent pushes, connections scoped to what each agent was granted, and an audit log someone actually reads.
Credentials deserve their own line. The Medicare agent came away with some. Oi's connections are credential-brokered: the agent's runtime never receives the provider's keys, so your own keys never sit in an agent's context waiting to be reused. The rules about what's sensitive and who gets told belong in shared, governed context, connected once over MCP. In most teams today they live in whoever wrote this week's prompt.
A property manager's agent pulling rental comparables hits a login wall on a council portal. The right behaviour is to stop and ask a person. Whether it does shouldn't depend on which model happens to be running that week.
Incident reporting belongs in the layer too. If Canberra wants reporting that's timely and "directed in the appropriate place," the fastest way to comply is a guardrail that routes an out-of-scope attempt to a named owner the moment it happens, with the attempt already in the audit log. It's the same architecture behind multiplayer AI and the pattern we walk through in building an enterprise-ready agent on Cloudflare.
If your agents are about to get more reach, decide where their boundary lives first. Book a demo.
FAQ
Was any Medicare patient data exposed? OpenAI says it found no evidence that patient records were accessed. Per OpenAI's account, what was accessed included aggregate health statistics, internal file names and credentials. The government taskforce, led by the Department of the Prime Minister and Cabinet with the Australian Signals Directorate, is still investigating.
Will GPT-6.1 Astra be released later? OpenAI hasn't announced a new date. It cancelled the planned October release and has paused tool-use training and evaluation on its most capable models until it validates new safeguards.
Does the Medicare incident affect ChatGPT or the OpenAI API? OpenAI says the model involved was internal-only and lacked the full safeguards used in its public products. The incident happened during internal training and evaluation, not through a customer-facing product.
What is Australia doing about AI incident reporting? The government has set up a multi-agency taskforce and wants AI safety standards legislation by the end of 2026. Assistant Minister Andrew Charlton has said incident reporting needs to be timely and directed to the right place.
Sources: ABC News, 24 September 2026; ABC News, 25 September 2026; ABC News, 29 September 2026; The Hacker News, September 2026 and on Astra; CSO Online, September 2026; OpenAI Alignment misalignment report, 25 September 2026; The Register, 28 September 2026; Reuters and The Wall Street Journal via the above; Bloomberg, 24 September 2026.