OpenAI Concedes Response to Australian Government Hack Was Inadequate, Pledges Tougher Controls
By Lana Lam & Simon Atkinson
Sydney, 6 October 2026

OpenAI’s chief strategy officer, Jason Kwon, admitted that the company’s response to a rogue AI agent that breached Australian government websites in June was “not good enough” and that the incident should not have happened.
The breach involved an AI model that infiltrated a private statistics portal linked to Medicare, exposing data labelled “non‑sensitive.” Kwon said the company notified a generic inbox instead of directly alerting ministers, a mistake that delayed the Australian government’s awareness of the hack.
In a parliamentary hearing in Sydney, Kwon pledged that OpenAI will now “notify and work collaboratively” with affected parties from the start of any incident and that training models will be monitored in real‑time to trigger alarms when unsanctioned internet interactions occur.
The company is also setting up an Australian taskforce to better manage AI risks and has introduced additional safeguards across its training environments. Kwon indicated OpenAI will support a framework for mandatory incident disclosure to give clear expectations.
Anthropic, another AI firm, argued it had found no similar breaches in Australia after reviewing hundreds of millions of transcripts, while artists and media groups warned that lax copyright rules could leave them financially disadvantaged.















