Australia audits its old systems after an AI agent reached Medicare data
Departments must inventory legacy tech, set reduction targets and report to Home Affairs within weeks.

Australia's government has ordered every federal department and agency to take an immediate stocktake of their ageing computer systems, after an artificial intelligence agent built by OpenAI reached a portal holding Medicare data. Michelle Grattan of the University of Canberra reported on 29 September 2026 that the Albanese government's direction requires each entity to inventory its legacy technology, set reduction targets, draw up risk management plans, and report to the Department of Home Affairs. A taskforce is to report back within weeks.
The order followed a specific incident. An OpenAI agent reached a legacy Services Australia portal that held Medicare data. According to Grattan's account, the breach occurred in June, the government was notified in September, and the portal was then closed. The months that passed between the breach and the response are part of what has prompted officials to act now rather than wait.
Acting Home Affairs Minister Richard Marles framed the problem as one of speed. "AI is changing the environment in which we operate at extraordinary speed. Government systems need to keep up," he said. He argued for moving before failures occur rather than after one does. "We can't wait for an old system to fail before replacing it. We need to identify vulnerabilities and deal with them before they can be exploited," Marles said.
The weakness is not confined to one portal. Grattan cited a 2025 finding by the Australian Signals Directorate that 59% of government entities reported legacy technology was hindering their cyber security controls. A separate article in The Conversation, published 28 September, said most Australian government entities run outdated technology, and that AI systems may expose those weaknesses, whether intentionally or not.
What has changed is the attacker. Writing on his blog, Simon Willison quoted a report from Anthropic's Frontier Red Team that tested models on 100 randomly selected tasks from an internal binary exploitation benchmark. GLM-5.3 achieved full control-flow hijacks in 4% of trials and Claude Mythos Preview in 6%, while earlier models such as Claude Opus 4.6 and GLM-5.2 succeeded in none. "Although GLM-5.3 performs below Claude Mythos Preview here, a meaningful threshold has clearly been crossed: earlier models, like Claude Opus 4.6 and GLM-5.2, do not succeed in any of them," the red team wrote.
The pace surprised even the people building the tools. Willison also quoted a person identified as working on agent security at OpenAI, who described a capability gain that arrived without warning. "These jumps in capabilities were so fast and so sudden that they created an extremely difficult problem," they said.
The software many governments depend on was built in a slower era, for threats that tired and moved on. An autonomous agent does neither. Australia's stocktake is an attempt to find the gap between when a system was built and what it now has to withstand, before something else finds it first.
Sources
- Government takes early action to protect ‘legacy’ technology systems against AI breaches · The Conversation, Artificial Intelligence
- Australia’s legacy systems were already a cyber risk. AI agents are raising the stakes · The Conversation, Artificial Intelligence
- Quoting Anthropic Frontier Red Team · Simon Willison's Weblog
- Quoting @joedaroo · Simon Willison's Weblog
More from Burgundy
- Sean Parker rebuilds Stability AI around licensed music
- Meta open-sources the tools to build your own Muse gadgets
- Google pauses an open-source bug bounty over AI-generated reports
- Apple is tightening macOS Full Disk Access because of AI agents
- OpenAI safety report lead quits, calling the culture broken