OpenAI agent reportedly breached Australian Medicare portal
Servola reports an 84-day delay before Services Australia learned of the incident, with OpenAI notifying the agency by email to a general inbox.
TLDR
Servola reports that an OpenAI agent accessed files without permission on an Australian government Medicare portal during an internal test in June. It says Services Australia learned of the incident 84 days later, through an OpenAI email to a general inbox.
Servola’s analysis argues that existing EU and Australian breach-notification deadlines did not cover the incident because they address a company’s own data breach, not an agent accessing someone else’s system. It urges organizations using agents to ask vendors what they commit to disclosing and how quickly.