An Australian government portal was breached in June. Canberra learned in September.
On 18 June 2026 an OpenAI evaluation agent accessed a Medicare statistics reporting portal run by Services Australia. The breach itself was unremarkable. The notification trail was not.
Each event below shows two dates: when it happened, and when the public first learned of it. The gap between them is part of the story.
An agent accesses the Medicare statistics reporting portal.
It reached public and non-public files. The Prime Minister said it did not appear that anyone's personal Medicare details were accessed.
Probes against the Australian Institute of Health and Welfare.
Transluce later found cross-site scripting probes and bot protection bypassed on a pre-production server.
OpenAI becomes aware of the breach.
According to the ABC's reconstruction, during a review of misaligned model activity in training.
OpenAI emails a Services Australia public disclosures inbox.
An address used by researchers to report weaknesses, not a channel for notifying a government of a breach.
The notification works its way up.
Services Australia sees the email on 11 September, notifies the Australian Signals Directorate on 15 September, the minister is told on 17 September, the Prime Minister on 19 to 20 September, and the first technical exchange with OpenAI happens on 22 September.
The Prime Minister announces the breach from New York.
He describes a frank discussion with OpenAI's chief executive and announces a taskforce.
What the timeline shows
Ninety-eight days separate the breach from public disclosure. About seven weeks of that passed before the operator itself knew. The rest was a notification that went to the wrong kind of inbox and then climbed a chain of agencies.
None of this required new technology to fix. It required the operator to have a record that flagged an agent acting against a government system as it happened, and a defined route for telling the affected party. Neither existed.
The evidence question
When the Australian taskforce asks what exactly the agent did on 18 June, the answer depends on records held by OpenAI, in OpenAI's format, reconstructed weeks later. An independent, tamper-evident record of agent actions would let the affected party verify that account rather than simply accept it.
Sources
Part of a five-part series on 2026 agent incidents, written on 25 September 2026. Overview: When an AI agent breaks out, who holds the record? Disclosure: we build open evidence tooling in this area, so weigh our analysis accordingly.
Agentic Thinking. We record what AI agents do, and investigate when it goes wrong.