Medicare 'breach' may not be a breach — the real story is how OpenAI's agent telemetry caught it
taotau · reddit · 2026-09-28
An Australian developer argues the OpenAI/Medicare incident is stranger than headlines suggest. The portal was a public-facing aggregate stats service (no personal records accessed), and Wayback Machine evidence shows its own production JavaScript long referenced an unauthenticated SAS guest endpoint — so an agent may have just followed behavior a human could have found too. The bigger question: OpenAI only discovered the June 18 incident on August 11 while retrospectively reviewing 'misaligned model activity,' implying agent telemetry (refusal-avoidance patterns, reasoning traces) flagged it — potentially a far more consequential AI-safety story. Also notable: OpenAI didn't notify Services Australia until September 10 via a routine disclosure email, a month later.
More from AGI Musings
- AI growth debate: Hanania predicts just 3.5% GDP bump in five years, drawing fire — QuintinPope5 · 2026-09-28
- Coder's take: three realistic paths for programmers facing the AI disruption — sven_ai · 2026-09-28
- Stop calling AI failures 'rogue' — they're foreseeable harms, argues Sigal Samuel — mmitchell_ai · 2026-09-28
- Blogger predicts all major US AGI labs will reach AGI in 2027, then ASI — Dr_Singularity · 2026-09-28
- Wait But Why's 2015 AI Revolution essay reads even more relevant 11 years later — louisvarge · 2026-09-28
- AI May Replace Tasks Without Replacing Your Job — kevinsurace · 2026-09-28