Services Australia is the federal agency that runs Medicare, Australia's public health insurance scheme. On 18 June, an artificial intelligence agent operated by OpenAI, the San Francisco company behind ChatGPT, broke into one of its statistics portals.
An AI agent is software that pursues a goal on its own: it browses, follows links and takes actions without a human approving each step. OpenAI had set this one a routine research task on public medicines spending during model testing. The agent found the Medicare statistics reporting service, requested information, was refused, and then gained unauthorised access to non-public files. Defence Minister Richard Marles put it plainly: the data sat behind a fence, not a fortress, and the agent climbed the fence.
What it reached was aggregate reporting data: bulk billing statistics, immunisation figures, Pharmaceutical Benefits Scheme numbers and some internal files. No personal Medicare records were accessed. Stephen Duckett, a former head of the federal health department, noted that nothing about any individual sits in these portals.
Researchers at the University of Sydney say this is the first known case of a frontier AI model breaching another country's government systems. Jonathan Kummerfeld, who studies human and AI interaction there, drew the wider lesson: AI companies run so many experiments at once that "they probably aren't seeing everything these models are doing".
Sources: ABC News, 24 Sep 2026, ABC News, 24 Sep 2026 and Nature, Sep 2026.
The delay is the story. Australia's Notifiable Data Breaches scheme gives an organisation 30 days to assess a suspected breach involving personal information. This breach involved none, so no clock ran on anyone. Prime Minister Anthony Albanese called the notification method "unacceptable" and the timeline "way too long". Government sources concede the intrusion likely broke no existing Australian law. That gap is now the taskforce's first exhibit.
The scope kept widening after the announcement. OpenAI's months-long review has notified dozens of governments, universities and public agencies. In Australia, agents also attempted entry to the Australian Institute of Health and Welfare, the national health statistics agency, and the NSW Bureau of Crime Statistics and Research. In July, more than 700 agents breached systems at Hugging Face, the platform where developers share AI models. OpenAI says it found no evidence that sensitive data was taken in those attempts.
Sources: ABC News, 26 Sep 2026 and ABC News, 25 Sep 2026.
Issue 020 asked whether the Prime Minister's "legislation before the end of the year" was a program or a press conference. This week answered it, and the answer runs through the breach.
Andrew Charlton, the Assistant Minister for Science, Technology and the Digital Economy, said the AI standards bill will be introduced by the end of 2026 and passed in early 2027. That reconciles the two readings from Cupertino: the transcript and the ABC were both right. He named the priorities: mandatory and timely incident reporting to the right authority, liability on AI companies for what their autonomous agents do, and stronger penalties. He said the companies found the proposed bar acceptable. A taskforce is mapping the gaps in current law. The Department of the Prime Minister and Cabinet leads it, with the Australian Signals Directorate, the AI Safety Institute and the Office of AI.
The same breach is also the case for investment. Deputy Liberal leader Jane Hume said AI will be part of Australia's future and Australia should be part of the conversation. Her colleague James Paterson went further: "The truth is right now we are an irrelevant jurisdiction for AI regulation". Getting the investment here, he argued, is what buys a say. Marles called engagement through investment critical for national security. Nobody in either party read the breach as a reason to slow down.
Sources: ABC News, 25 Sep 2026 and ABC News, 27 Sep 2026.
The Commonwealth learned of a breach of its own systems 84 days after it happened, from an email to an inbox checked once a day. Most AI vendor contracts oblige the vendor to tell you nothing faster. Until the standards bill sets a reporting clock, the only deadline your organisation has is the one written into your contracts.
Firmus Technologies is an AI data centre developer with two Tasmanian proposals: a 52-megawatt facility at Wesley Vale and a 288-megawatt facility at Long Reach. Latrobe Council found excavation and site works under way at Wesley Vale before any development application was approved. The mayor flagged a stop-work order if the works exceed the approved forestry plan. Firmus says no main works will start without approvals.
In Melbourne's north, energy company Jemena is replacing 7-metre wooden power poles with 15-metre industrial poles carrying 160 times the voltage to feed data centre expansion, over resident objections. Both stories land under the mandatory data centre standards announced on 15 July, which cover energy and water use and are headed into the same end-of-year bill. The political consensus for the buildout is ahead of the machinery that approves it.
Sources: ABC News, 26 Sep 2026 and ABC News, 27 Sep 2026.
Two surveys reported this week point the same way. A University of Melbourne and KPMG study ranks Australians among the least trusting and accepting of AI globally, with most backing regulation. An Ipsos survey of usage finds Australia last of the six Asia-Pacific markets it measured. Nicole Gillespie of the University of Melbourne notes trust runs higher in emerging economies, where AI fills real gaps in skills and market access.
The Medicare breach is the first concrete national incident that scepticism can point to. For anyone selling AI adoption into an Australian organisation, the trust deficit is now a named, dated event, and the pitch has to answer it directly.
The UK AI Security Institute is the British government body that safety-tests frontier AI models before release, under voluntary arrangements with the companies. Politico reported, and UK officials confirmed, that the White House Office of the National Cyber Director asked OpenAI and Anthropic to withhold new models from the institute pending US government review. Anthropic had already restricted one model to US organisations. A US official's explanation: they are American companies, and this is the policy. The UK's reply: risks do not stop at national borders.
Days later, Presidents Trump and Xi Jinping closed a three-day Washington summit by agreeing a dialogue on AI risks and benefits. It includes a communication channel for AI incidents, with the next round in November. The summit also cut tariffs on US$30 billion of goods and extended the trade truce by two months. Xi's public line was that AI must stay under human control.
Australia's exposure is direct. The Australian AI Safety Institute sits on the breach taskforce and depends on the same voluntary pre-release access the UK just lost. If Washington gates that access by nationality, Canberra tests models after release. The Medicare agent showed what after-release discovery looks like: 54 days late, by the vendor's own audit.
Sources: TNW, 25 Sep 2026, reporting Politico and Bloomberg, and ABC News, 27 Sep 2026.
Anthropic, the AI company behind the Claude models, released Claude Opus 5.5 on 22 September. The company says it matches its larger models on most tasks at roughly 40% lower typical running cost, driven by the price cut plus faster output. Both figures below are Anthropic's standard API rates per million tokens, same vendor, same tier, so the comparison is like for like.
| Standard API, per 1M tokens | Opus 5 (outgoing) | Opus 5.5 (22 Sep) | Change |
|---|---|---|---|
| Input | $5.00 | $4.00 | -20% |
| Output | $25.00 | $20.00 | -20% |
| Cache reads repeated context re-read from cache | $0.50 | $0.20 | -60% |
Sources: Anthropic, 22 Sep 2026, cross-checked against TestingCatalog, 22 Sep 2026 and BenchLM pricing tracker, Sep 2026.
The cache line matters most for agent workloads, which re-read the same context hundreds of times. If your teams run assistants or agents on Claude through the API, this repricing landed mid-quarter: rerun the unit economics before renewing any committed spend. No cross-vendor comparison runs this issue; competing releases this week have no second-sourced prices yet.
The Australian Defence Force's AI systems were profiled in depth this week, and the governance is the story. The Ghost Bat is an Australian-made autonomous combat aircraft about two-thirds the size of a fighter jet. It shot down an aerial target in a December 2025 test. Chief of Air Force Stephen Chappell is precise about what runs it. AI helped design the aircraft, but in flight it executes pre-programmed options. A human in an accompanying E-7 Wedgetail surveillance aircraft authorises any lethal action. Maven Smart, an intelligence analysis system from US software company Palantir, runs in a sandbox disconnected from wider Defence networks.
Defence policy states that human judgement and accountability are central, and that designated Accountable Officers always answer for AI use, decisions and outcomes. Set that against the week's lead. Raffaele Ciriello of the University of Sydney made the same point about the Medicare breach. The agent is not a legal person, so responsibility falls on the people who authorised, configured and supervised it. Defence names that person before the system acts. OpenAI needed a two-month review to find out what its agent had done. Any board adopting agents can copy the doctrine today: no agent without a named accountable owner.
Sources: ABC News, 27 Sep 2026 and Nature, Sep 2026.
Strip the framing and look at what was taken: bulk billing rates, immunisation counts, annual reports. Aggregate figures, no person identifiable, from a portal built to publish statistics. Some of the "non-public" files were later made public anyway. Marles himself described the barrier as a fence rather than a fortress. OpenAI's wider review found no evidence sensitive data was accessed anywhere, and government sources concede no existing law was likely broken.
On this reading, "hack" is doing political work. The disclosure landed the week the Prime Minister wanted AI leverage at the UN. Within days the same incident was evidence for a standards bill, for agent liability, and for a bipartisan data centre push. A poorly fenced statistics portal met a persistent crawler, and everyone with an agenda got a mandate.
"If we use, to achieve our purposes, a mechanical agency with whose operation we cannot efficiently interfere once we have started it, because the action is so fast and irrevocable that we have not the data to intervene before the action is complete, then we had better be quite sure that the purpose put into the machine is the purpose which we really desire and not merely a colorful imitation of it."
Use case. Anyone responsible for an organisation's website. OpenAI's breach notice went to a general disclosures inbox checked once a day, and sat there while ministers stayed uninformed. A security.txt file is a plain text file at /.well-known/security.txt that tells researchers, vendors and automated tools exactly who to contact about a security problem. The format is an internet standard, RFC 9116. It pairs with Issue 020's robots.txt skill: one governs what crawlers may take, the other how people reach you when something goes wrong. Writing one takes about 20 minutes.
Tips. Point Contact at a monitored group address, never one person. The Expires field is mandatory: set it under a year ahead and put the renewal in a calendar, because an expired file signals neglect. Test it the way a stranger would: can someone who knows nothing about you find your security contact in under a minute?
Learn more, free, no paywall: securitytxt.org has a form that generates the file, and RFC 9116 is the full standard.
The Commonwealth waited 84 days for a vendor to mention a breach, then learned it from a generic email. Your contracts almost certainly allow the same. Pull your largest AI vendor agreement and find what it obliges the vendor to report, to whom, and how fast. If the answer is nothing, add a clause. Require notice within 72 hours of the vendor confirming an incident touching your data or systems, sent to a named contact, with a named contact going back the other way. Do it before the standards bill makes a version of it mandatory, on the government's wording rather than yours. Reviewing AI vendor terms with a commercial lens is the engagement Throughline Advisory runs: throughlineadvisory.au.