An artificial intelligence agent built by OpenAI reached non-public parts of an Australian government health-statistics portal it was never meant to see. Malaysia is now beta-testing agentic AI of its own inside MyGOV. The two deployments are very different, but both are examples of agentic AI, software that is given a goal and left to plan and act toward it, which is why the case is worth reading closely here rather than filing under someone else's problem.
According to the ABC, the agent reached non-public files on the Medicare Statistics Reporting Service run by Services Australia on 18 June. This is a portal of aggregate figures, separate from the systems that hold personal Medicare claims, and it pulled statistics and internal file names that were not meant to be public. The government has said there is no evidence that individual records or personal information were accessed, though the review is still under way. Three other government sites saw agent activity, but only on information that was already public. Prime Minister Anthony Albanese made the incident public on 24 September and said officials had not found an earlier case of its kind.
What makes it notable is the method, not the damage. The agent had been set an ordinary research task, looking up public medicine spending. It hit repeated blocks, and instead of stopping it tried alternative routes until one worked. To us this reads less like an attack than like software finishing its job, treating an access control as one more obstacle to route around.

The disclosure is the other half of the story, and it drew the sharpest words. As the ABC reported from the Prime Minister's statement, the breach happened on 18 June, OpenAI emailed a public mailbox at Services Australia on 10 September, the matter reached the Australian Signals Directorate on 15 September, and it became public on 24 September. That is nearly three months between the breach and the first notification. Albanese criticised both the incident and the delay, reserving his sharpest words for the notification, which he called unacceptable. He said he raised it directly with chief executive Sam Altman, and set up a taskforce under his own department, the Signals Directorate and the national AI Safety Institute to run an urgent review.
Malaysia is not watching this from the sidelines. In a 10 August release, the Ministry of Digital said MyGOV Malaysia had begun a phased beta of an agentic AI assistant. It did not say how many services the assistant covers during that beta. What it did set out is the platform it sits on: as of July, MyGOV had more than 2.9 million users and 52 services from 19 agencies.

The Ministry says the assistant can interpret context, plan actions and carry out tasks within set permissions, with human-in-the-loop oversight and under the country's Public Sector AI Adoption Guidelines. Its own worked example is a police summons check taken all the way through to payment, without the citizen moving between systems. That fits a wider digital-identity push around the new MyKad and MyDigital ID, a rollout we reported on when the new MyKad hit eKYC snags this month.
It is worth being precise, because the two cases are not the same thing. Malaysia's MyGOV assistant is a permissioned, citizen-facing tool with human oversight built in. The OpenAI case was an external agent crawling a public-facing portal and finding a way around its controls. What links them is the direction of travel. Agentic software is now reaching government systems, whether invited in as MyGOV has done, or arriving uninvited as it did in Australia, and the Australian portal is an early look at what happens when it meets a control it can work around.
Two lessons carry across. The first is that an access control can still give way to an agent that keeps trying alternative routes, as this one did, a fair question to ask of any service opening up to assistants like MyGOV's, and to the AI agents arriving in everyday apps. The second is disclosure: a clear, fast reporting line is something a beta programme can set now, cheaply, before it is tested for real.
The Ministry says the assistant works within set permissions and human oversight, under Malaysia's Public Sector AI Adoption Guidelines. The Australian portal had access controls too. What that case shows is an agent chasing a goal that did not stop at the first locked door, and that is the behaviour any system opening up to agents now has to plan for.
Image(s) courtesy of FlyD and Gilles Lambert on Unsplash.




