Did AI Really Hack Medicare?

Canberra says an OpenAI agent bypassed Medicare safeguards, but archived portal code raises a more awkward possibility: the system may have exposed the route itself. The Government has confirmed an investigation is still underway into exactly what happened.

Did AI Really Hack Medicare?

Australia was told a rogue AI had broken into Medicare.

The reality may be considerably more embarrassing.

Prime Minister Anthony Albanese said an OpenAI agent encountered barriers while searching the Medicare Statistics Reporting Service, refused to take no for an answer and found a way around them, gaining “unauthorised access” to public and non-public files.

It was immediately portrayed as a chilling glimpse of autonomous AI defeating government cyber defences.

There is just one problem.

The supposed locked door may have been open all along.

Technical analysis of archived versions of the Medicare portal found that the Government’s own code explicitly directed statistics requests through a /SASStoredProcess/guest endpoint requiring no username or password.

So before Canberra uses this extraordinary “AI hack” to help justify new AI laws, Australians deserve an answer to a very simple question:

What, exactly, did the AI hack?

Recorded Future News examined archived versions of the Medicare portal after Australian security researchers questioned the official account. The archived JavaScript explicitly directed production statistics requests to a /SASStoredProcess/guest endpoint. That endpoint required no username or password. In other words, the system itself appears to have exposed a guest route for ordinary statistics queries.

While OpenAI has acknowledged that its models took actions the company did not intend, and the Government says access to some material was unauthorised, neither side has publicly released the activity logs showing exactly what the agent requested, what barriers it encountered, or what technique it used.

Even some of the more dramatic details may have ordinary explanations. Albanese said the agent discovered internal filenames and caused files to be written to an internal server. The archived portal, however, appears to have exposed internal path information in publicly served JavaScript and to have generated temporary chart files on the server as part of its normal operation.

That leaves a basic unresolved question: did the AI actually defeat a security control, or did it exploit functionality the Government’s own website had left exposed?

The distinction matters because the incident quickly became part of a much larger policy argument.

The Albanese Government had already announced a national AI framework on July 15, more than two months before the Medicare incident was made public. That plan included Australian AI standards and a broader effort to place AI policy within the Government’s national-interest agenda.

Then, when Albanese revealed the Medicare incident on September 24, he announced a multi-agency taskforce involving the Department of Prime Minister and Cabinet, the National Cyber Security Coordinator, the Office of AI, the Australian Signals Directorate, the Australian AI Safety Institute and Services Australia. He said the review would examine possible law-enforcement and legislative responses, and that lessons from the incident would inform the Government’s AI standards legislation.

By September 25, Albanese was still describing the event as an AI agreed being “told no” and then finding a way to circumvent barriers. Yet the forensic investigation was still ongoing.

Curiously, the government was already developing AI standards. Then a technically unusual incident was publicly described in highly dramatic terms before the underlying mechanism had been fully established. The same incident was immediately cited as evidence relevant to future legislation.

So what the hell was this? Was it just an excuse to push draconian rules? Only the technical evidence can tell us that. So they should publish it.

Release the relevant request logs, with genuinely sensitive information redacted. Show what barrier the agent encountered. Show what authentication or access control it bypassed. Identify the supposedly non-public material and how it was protected. Explain what files were written to the server and whether that differed from the portal’s normal behaviour.

If the AI genuinely defeated Australian Government cyber defences, that would be important evidence for policymakers considering the risks posed by autonomous agents.

If it merely navigated an exposed guest interface and reached information the Government had failed to secure properly, that is a very different story.

Before the Medicare episode becomes a lasting example used to shape Australian AI regulation, Australians are entitled to know which story is true.

What, exactly, did the AI hack?

Thought for the Day

“Sunlight is said to be the best of disinfectants.”
– Louis D. Brandeis

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to Confidential Daily.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.