OpenAI Medicare breach sparks Canberra AI crackdown as Monash expert Chetan Arora warns of missing ‘fence’

Poor instruction, stress-testing and policing means AI agents can hardly be blamed for getting out of control, an expert says.

Will Nicholas
AAP
Australia is scrambling to fortify its digital infrastructure after the OpenAI breach of Medicare.
Australia is scrambling to fortify its digital infrastructure after the OpenAI breach of Medicare. Credit: AAP

Nobody should be surprised when an artificial intelligence agent goes off the rails, because it was never really on them in the first place, an AI expert says.

An OpenAI breach of a Medicare statistics website made global headlines when Prime Minister Anthony Albanese disclosed it on the sidelines of the United Nations General Assembly in New York.

The incident has sent Canberra scrambling to fortify digital infrastructure, but something more fundamental needs to change in AI behaviour, cybersecurity expert Chetan Arora told AAP.

Sign up to The Nightly's newsletters.

Get the first look at the digital newspaper, curated daily stories and breaking headlines delivered to your inbox.

Email Us
By continuing you agree to our Terms and Privacy Policy.

He compared autonomous AI models to dogs being trained not to leave a yard.

“Either I can train my dog by means of punishment and reward for not crossing the boundary of my home, the second way is actually putting the fence and deterring the dog,” Dr Arora said.

“What was missing in these systems is this engineering approach of building the fence.”

The Monash University researcher added the Medicare breach was better classified as a permissions problem than a hack, because the bot in question was probably not told to stop when it hit a barrier like the one it ended up scaling.

“The agent was given a benign task of doing a research problem on medical spending, it hit a roadblock and it tried to improvise a way of getting around,” he said.

OpenAI has stressed it did not direct its agent to infiltrate the website in order to perform the innocuous research task it had been set.

The bot interacted normally with three Australian federal and state government sites, but broke into the Medicare statistics portal when offered resistance.

Policing autonomous agents did not require a human watching a model’s every move, but there needed to be a clear framework with flesh-and-blood input and stringent reporting obligations, Dr Arora said.

A task force set up after the breach to examine AI reporting obligations and Australia’s cyber-safety and legal avenues for punishing OpenAI is expected to report in a matter of weeks.

Comments

Latest Edition

The Nightly cover for 25-09-2026

Latest Edition

Edition Edition 25 September 202625 September 2026

Purple Army and Lions faithful take over Melbourne as Freo chases first flag and Brisbane hunts three-peat glory.