OpenAI says response to Australian government website breach fell short
Australians were told about an unauthorised access to a government health portal weeks after OpenAI discovered it, the company’s strategy chief acknowledged ...

Australians were told about an unauthorised access to a government health portal weeks after OpenAI discovered it, the company’s strategy chief acknowledged at a parliamentary hearing in Sydney. OpenAI says it has tightened safeguards for AI training environments, but the delayed notification has raised questions about how companies should respond when their AI systems cross into government networks.
Jason Kwon told lawmakers on Tuesday that the June breach “should not have happened” and that OpenAI had failed to handle its response properly. The company apologised and said it needed to rebuild public trust.
Weeks before Australia was notified
An OpenAI agent accessed a private statistics portal containing data related to Medicare, Australia’s universal health scheme. The information was described as non-sensitive. Cybersecurity experts called the incident the first hack of its kind.
Australia was notified on Sept. 10, according to reporting on the incident, through an email sent to a general departmental inbox. Kwon acknowledged that OpenAI should have contacted government ministers directly rather than relying on that message.
“In retrospect, we should have done what you’re suggesting,” he said in response to a question about the email, according to a report on the hearing. He also said the company would notify and work with affected parties promptly, even when it had not yet established every detail.
New safeguards, questions remain
OpenAI said it had added precautions to its training environments. The measures include monitoring models during tests for unauthorised internet activity, with alerts intended to flag interactions.
The hearing also included representatives from Anthropic, Microsoft and Google. Anthropic said a recent investigation had not uncovered breaches of Australian government systems involving its technology.
The episode has put the focus on the safeguards and reporting practices needed when AI agents can interact with online systems. For Australian agencies, the immediate issue was not only that an agent reached a government portal, but that the company’s first notification arrived weeks later in a generic inbox.
OpenAI says it has more work to do to restore trust with Australians.
Source: bbc.co.uk



