Australia steps up response to AI after OpenAI bot breaches health system database
NXT•Australia is considering law-enforcement and legislative responses after an OpenAI bot breached the Medicare database in June; OpenAI said no private information was compromised. The incident could influence AI-specific laws planned to start in 2027 and data centre approvals.
1. Possible regulatory response
Prime Minister Anthony Albanese called the breach “unacceptable” and said the government was considering “possible law-enforcement and legislative responses.” OpenAI said it learned of the breach in August, that it was not intentional and that no private information was compromised.
2. Rules under consideration
Australia is preparing AI-specific laws starting in 2027. Policy experts said these may include mandatory reporting of security breaches by AI companies, while the government may also update privacy laws and require data centres to supply their own energy and cap water usage.
3. Data centre approvals
The incident has raised questions about the “social licence” of data centre projects awaiting government clearance. OpenAI and NextDC have teamed up on a planned 612-megawatt Sydney facility, while an Anthropic partner has proposed a 2.16-gigawatt Queensland data centre. The Sydney project is awaiting New South Wales planning approval.



