Medicare AI breach tests how cyber wordings define unauthorised access
The wording question is whether access was authorised, not what the machine intended, says Lockton's cyber lead
Medicare AI breach tests how cyber wordings define unauthorised access
CYBER
By Daniel Wood
24 Sep 2026

Prime Minister Anthony Albanese used a press conference in New York on Thursday to reveal that an OpenAI agent had gained unauthorised access to an Australian government portal in June. Across the city, OpenAI chief executive Sam Altman was addressing the United Nations Security Council on the dangers of the technology. Insurance Business has reached out to brokers and insurers to find out what a cyber policy does when there is an incident like this.

Mark Luckin (pictured), national manager for cyber and technology sector at Lockton Companies Australia, said the answer turns on what the wording tests.

"The trigger should be the outcome, not the motive behind it," said Sydney based Luckin.

Albanese said that an OpenAI research model, given a task on June 18 to research public medicine spending, found the Medicare statistics reporting service portal administered by Services Australia and kept working at it after being refused.

"The AI agent found a way around those blocks. Didn't accept no for an answer, if you like," Albanese said.

OpenAI has said its models took actions the company did not intend. Albanese was explicit that no foreign actor was involved, describing it as a research project that got into areas it should not have.

Whether the wording tests motive or outcome

Luckin challenged the premise that unauthorised access should require somebody to have acted deliberately. Better wordings, on his account, apply an objective test: was the access authorised by the insured, rather than what was in the mind of the person, or the machine, obtaining it. An agent gaining access it was not permitted to have should be capable of constituting a cyber incident even where its operator never intended that outcome.

Watch next: Cyber’s AI risks, new players and systemic threats

Wordings that still lean on concepts such as malicious or deliberate conduct, or that assume a human threat actor, are the ones he sees becoming outdated as autonomous agents increasingly cause outcomes their operators did not specifically intend.

What this incident lacks is instructive. No malice, no instruction, no intent. What remains is access nobody authorised. 

Acting Prime Minister Richard Marles put the security question plainly to the ABC. "We keep our most important national security information behind a fortress. This was really kept behind a fence that the AI agent effectively climbed over," he said.

The second assumption, that the insured knows

The other thing a cyber policy often takes for granted is that the insured finds out.

OpenAI notified Services Australia on September 10 by email to a public mailbox, close to three months after the event. Services Australia reported it to the Australian Signals Directorate's Australian Cyber Security Centre on September 15. Albanese said both the delay and the method were unacceptable and that he raised them with OpenAI CEO Sam Altman by phone.

"He clearly accepted that the company had not done good enough," the Prime Minister said.

Luckin's position is that an insured cannot be held to a standard it had no means of meeting.

"Insurance generally cannot expect an organisation to notify an incident it genuinely does not know has occurred," he said.

Where awareness begins in September, he argued, the immediate priority is notification to the insurer at that point, leaving the policy mechanics to determine which period responds. The same distinction governs regulatory obligations. Under the Notifiable Data Breaches regime, the assessment duty starts when an organisation becomes aware of information giving it reasonable grounds to suspect an eligible breach, not retrospectively from the date an invisible intrusion occurred.

Read next: CFC folds cyber, AI wording into financial institutions suite

What he draws from the event is a dependency. Meeting your own obligations, once the clock starts, rests on a third party telling you quickly enough that the clock can start at all.

Three other systems may have been affected. Albanese named the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research and the Victorian Department of Health.

None of them knew either.

Albanese has announced a taskforce led by his department, involving the National Cybersecurity Coordinator, the Office of AI, the Australian Signals Directorate, the Australian AI Safety Institute and Services Australia, with the incident also referred to the Joint Select Committee on Artificial Intelligence.

Related Stories
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB AU.