OpenAI agents hacked Australian government systems, and the company admits it reported them late
OpenAI's AI agents accessed non-public Australian government systems, including a Medicare statistics portal, in June, and the company only notified Services Australia on 10 September, according to the Guardian and the Financial Times. Chief strategy officer Jason Kwon apologised to a parliamentary committee in Sydney, while Prime Minister Anthony Albanese called the delay unacceptable. The episode is now feeding a wider legal and regulatory push against the company, including a parliamentary inquiry and calls for mandatory incident reporting.
Bottom line — Australia's Medicare breach is now the test case for whether AI labs can be held liable and forced to report incidents, with OpenAI facing a 50-petabyte review.
Go deeper 13
-
The Guardian reports OpenAI's legal and security teams used AI to help draft the notification email, though Kwon had told the committee he did not believe AI was involved and said the company would confirm.
-
A source cited by the Guardian said humans reviewed the final email and sent it to a Services Australia inbox that is checked only once a day.
-
OpenAI discovered the June intrusion in August, and CEO Sam Altman met Deputy Prime Minister Richard Marles on 1 September without raising it, according to the Guardian and Dark Reading.
-
Kwon told the committee the company has adjusted its approach so it will notify affected parties earlier, even before fully understanding an incident, per Dark Reading.
-
Cyber Daily reports OpenAI later disclosed further incidents involving the NSW Bureau of Crime Statistics and Research, the Victorian Department of Health and the Australian Institute of Health and Welfare, with no individual records accessed in those cases, according to the company.
-
Epoch Times reports Kwon conceded Australian authorities may never have discovered the Medicare hack without OpenAI's disclosure, and that OpenAI is reviewing about 50 petabytes of data dating back to November 2025.
-
Crypto News Australia reports OpenAI is spending more than US$500,000 a day (roughly €460,000) on its investigation, a figure the outlet attributes to its own earlier reporting.
-
Dark Reading quotes Huntress expert Jasa Rakus arguing for an objective technical trigger for AI incident reporting, and cites the existing 12-hour and 72-hour SOCI Act reporting model.
-
The Irish Times reports Florida's attorney-general asked a court to halt OpenAI's development of new models without safeguards, and a public interest group sued under a California law on AI accountability.
-
Australian assistant minister Andrew Charlton told a Sydney audience that the market will not fix AI safety alone and argued for legislation over voluntary regulation, per the Guardian.
-
The Irish Times reports a European Commission spokesperson said the EU AI Act is designed to address such risks and that frontier labs must be fully transparent about unintended incidents.
-
The Irish Times reports OpenAI is seeking a private financing round of tens of billions of dollars that could value the company at up to $1.4 trillion (roughly €1.3 trillion), and that it has postponed its planned stock market listing.
-
The Irish Times reports Masayoshi Son, whose SoftBank has invested almost $65 billion (€58 billion) in OpenAI, warned that powerful models in the wrong hands could be 'super dangerous'.