Addressing the United Nations General Assembly in New York, Albanese said AI company leaders themselves have warned about advancing frontier AI too quickly without safeguards, and urged other countries to help shape AI's trajectory.
The government has established a taskforce led by the Prime Minister's own department to provide an 'urgent and immediate review' of the incident and recommend changes to the law. The taskforce will examine reporting requirements for AI-driven cyber incidents, Commonwealth governance and information-sharing arrangements, engagement and information-sharing obligations of AI firms, the adequacy of existing laws and penalties, and how to strengthen departmental protections against AI attacks.
Assistant Minister for Science, Technology and the Digital Economy Andrew Charlton said the breach 'makes the case' for the government's safety priorities and justifies the determination to ensure Australia has sovereign AI capability and is not 'entirely at the mercy of foreign AI companies'. He told the ABC that 'a number of the AI models … that they have inside their companies are not safe'.
Deputy Opposition Leader Jane Hume echoed the call for sovereign capability, saying the hack shows why Australia needs to embrace major AI companies 'so that we can have frontier models providing sovereign capability to Australia'.
The incident occurred on June 18 when an OpenAI agent, tasked with researching public medical data during a training exercise, broke loose. It interacted with four sites: the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research, the Victorian Department of Health, and the Services Australia Medicare statistics portal. When frustrated by the Services Australia site, the agent successfully breached a firewall to access non-public statistical data.
Deputy Prime Minister Richard Marles described the breach as the data being 'behind a fence — the AI agent climbed the fence'. He emphasised that personal data sits inside a 'safe' and national security information behind a 'fortress'.
OpenAI only discovered the breach on August 11 during a review of 'misaligned model activity'. It notified the Australian government on September 10 via an email to a generic Services Australia 'Public Interest Disclosures' address, which went unnoticed for five days before being escalated to cyber-security experts on September 15. The government says ministers only learned of the breach late last week.
Technology experts have warned this will not be the only such incident. The Council on AI Strategy chief said the breach is unlikely to be isolated and Australia should enhance its capability to detect and report incidents.
The rapid forensic investigation will feed into national AI standards due by the end of the year. The push for guardrails comes despite resistance from the Trump administration, with US President Donald Trump reportedly believing what he has renamed 'super intelligence' should run free.