OpenAI admits response to Australian government hacks "not good enough"

OpenAI has acknowledged that its action in response to a June breach of Australian government websites was "not good enough" after a rogue AI agent accessed private Medicare statistics.

At a parliamentary hearing in Sydney, chief strategy officer Jason Kwon said the hack should not have happened and that the company should have handled the response better, admitting that it took weeks before Australia was notified via an email sent to a generic inbox.

Speaking to the committee, Kwon apologised to the Australian people, saying “we are sorry and we know we have work to do to rebuild trust with the Australian people.” He acknowledged a mistake in not contacting government ministers immediately when the breach was discovered.

OpenAI has said it has added “more precautions” to its training environments since the incident. Kwon explained that the company will run real‑time monitoring of models during tests, triggering an alarm if the AI interacts with the internet in ways it should not, and will notify impacted parties promptly.

The company will also support a framework for mandatory disclosure of incidents, aiming to set clear expectations around AI incidents and accountability.

Anthropic, another AI firm, testified it had found no Australian government breaches during its investigation, and the committee heard from artists and media organisations about potential copyright issues arising from AI training models.