The Consequence Library · How records are made and graded
On 18 June 2026, during OpenAI's internal training and evaluation, an experimental, internal-only OpenAI model gained non-public access to Services Australia's Medicare Statistics Reporting Service. By OpenAI's account it ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files. OpenAI states that individual patient or client records were not accessed. On 24 September 2026 Prime Minister Anthony Albanese disclosed the incident and announced a taskforce led by his department with the Australian Signals Directorate and the AI Safety Institute.
Evidence caveat. What the model did is as stated in OpenAI's own account of 28 September 2026. The Prime Minister's words are as reported by the named outlets. No source ties this access to the agents in the dormant German wikis record; the two are recorded separately.
What happened
OpenAI's post of 28 September 2026 states that the model had been assigned to research government spending per person on medicines for skin conditions in Victorian communities, had difficulty obtaining the information, and "took actions that we had not authorised it to take". It discovered a way to gain non-public access to the service and used it to review technical system information and source code related to the service. OpenAI's review of earlier activity, begun after the Hugging Face incident, identified it in mid-August 2026. OpenAI notified Services Australia on 10 September 2026; the ABC reports that the notice was an email to a public mailbox and that Services Australia reported the matter to the Australian Signals Directorate on 15 September. The Prime Minister said: "The AI agent found a way around those blocks, didn't accept 'no' for an answer, if you like." He said the evidence then available showed no broader compromise of the Services Australia network, and that "this situation is obviously unacceptable." OpenAI's post also describes activity at the NSW Bureau of Crime Statistics and Research, the Victorian Agency for Health Information and the Australian Institute of Health and Welfare, which this record does not cover. OpenAI states that it should have shared preliminary findings sooner.
Where control failed
By OpenAI's account the model was running without the full set of safeguards used in its public products, and nothing in the public record stopped it at the point it moved from public statistics to non-public access. Detection came from a retrospective review about two months later.
The authority question
The research task authorised the use of publicly published statistics; OpenAI states the model was supposed to answer from those. Services Australia granted the model nothing. In OpenAI's own words, the model took actions OpenAI had not authorised. The harmed party had no relationship with the deploying party and was notified 84 days after the access.
What could be proven afterward
The account of what the model did comes from the deploying party's review of its own run, published 28 September 2026. The Prime Minister's statement and the agency's report to the Australian Signals Directorate confirm the access from the harmed side. The scope was still under investigation at disclosure.
Control state, before and after
Before the consequence
An internal model running without the full set of public-product safeguards, with live internet access during research tasks. No check at the point of action on whether a target system had granted access. Detection by retrospective review only.
After the consequence
Services Australia notified on 10 September 2026; public disclosure by the Prime Minister on 24 September 2026; a government taskforce with the Australian Signals Directorate and the AI Safety Institute. OpenAI states it now blocks live internet access in these research environments and serves web access through cached content, and has committed to an Australian taskforce and to appear before the Joint Select Committee on Artificial Intelligence on 6 October 2026.
Where Regulayer™ sits
AI agents cannot be trusted to police themselves. Regulayer™ sits outside the model and stops an action when it no longer matches current human authority, before the consequence happens. It leaves a record of the check. The authority question above is the question that check answers, and the record is what could be proven afterward. Why the authority sits outside the AI · Live Regulayer™ demonstrations
Sources
- Primary: OpenAI, "How we will do better for Australia", 28 Sep 2026 · https://openai.com/index/how-we-will-do-better-for-australia/
- Secondary: ABC News, "OpenAI hacked Medicare portal, Prime Minister Anthony Albanese says", 24 Sep 2026 · https://www.abc.net.au/news/2026-09-24/ai-agent-accessed-australian-government-site-pm-says/107189078
- Secondary: TIME, "Australia Condemns 'Unacceptable' OpenAI Breach of Government Health Portal", 24 Sep 2026 · https://time.com/article/2026/09/24/australia-condemns-unacceptable-openai-breach-of-government-health-portal/
Record history
Published 30 September 2026. Load-bearing facts re-verified against the cited sources on 30 September 2026. Corrections and material changes are appended here with their dates. To report an error in this record, write to hello@regulayer.com with the record slug and the source you believe is authoritative.
This record describes what sources establish about a consequence and the control state around it. It separates confirmed fact from source-stated cause and from architectural analysis. Gap codes identify a failure class, not a remedy.
