Anthony Albanese says an OpenAI agent illegally entered an Australian Medicare data portal earlier this year, prompting a government investigation and an urgent review.

Speaking in New York, the prime minister said the Open AI agent gained unauthorised access to the Medicare statistics reporting service portal run by Services Australia on June 18. According to Mr Albanese, the system intruder was researching public medical spending when it discovered a way past privacy safeguards.

“The AI agent found a way around those blocks, didn’t accept ‘no’ for an answer, if you like,” Mr Albanese said.

He said the agent reached both public and non-public files, although there was no indication that any person’s Medicare information had been viewed. An investigation is now under way with help from the Australian Signals Directorate.

“[The] evidence currently available is there is no broader compromise to the Services Australia network. Nonetheless, this situation is obviously unacceptable,” Mr Albanese said.

The prime minister also disclosed that he had a “frank” conversation with OpenAI chief executive Sam Altman, criticising the company for waiting three months before alerting authorities. He said Services Australia was not informed until September 10, and that the notification came through an email sent to the agency’s public inbox.

“The notification was an email, sent just to the public mailbox,” Mr Albanese said.

“I had that discussion very frankly, with Mr Altman.”

Mr Albanese said both the delay and the way the government was notified were “unacceptable”.

“Today I spoke with the CEO of OpenAI, Sam Altman, to express Australia’s extreme concern about this incident,” he said.

“And I also expressed my disappointment that it took the company way too long to inform the government what had occurred.

“The nature of the way that the notification occurred as well was unacceptable.”

On September 15, Services Australia referred the matter to the Australian Signals Directorate’s cyber security centre. Mr Albanese said Katy Gallagher, the minister for the public service, was contacted by Services Australia last week, while his own office was informed over the weekend.

He announced a taskforce would carry out an “urgent and immediate review” of the breach. More detail is expected from Acting Prime Minister Richard Marles and Katy Gallagher at a press conference.

In a statement, an OpenAI spokesperson said the company is “conducting an extensive review of misaligned model activity” during training and is notifying outside organisations where their systems may have been affected.

“During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation,” they said.

“In the course of that, our models took actions we did not intend.

“Our review found no evidence of patient records being accessed. The information accessed included aggregate health statistics and internal file names.”

OpenAI said it had informed the organisations involved and was supplying technical details to assist their inquiries and address possible security weaknesses. The spokesperson added that the broader review was continuing and that the company remained “committed to transparency”.

Mr Marles told ABC Radio National that other sites were accessed but are not thought to have been hacked. He named the Victorian Department of Health, a New South Wales government website, the Australian Institute of Health and Welfare, and the NSW Bureau of Crime Statistics and Research website.

He said the inquiry would be run by the prime minister’s department, working alongside the Australian Signals Directorate and the AI Safety Institute to determine what the AI agent did and how the breach took place.

Mr Marles said the fact a non-human AI agent secured unauthorised access was “a very serious incident”, even though the practical effect was limited.

“For what that’s worth, that’s relatively minor, and so it’s important to assure people of that. No personal information has been accessed here. There’s no impact on the system.”