OpenAI admits "not good enough" on Australia's Medicare hack — and reveals a second government breach
OpenAI's handling of the first known case of an AI agent hacking a government website was “not good enough.” The admission came on Tuesday from the company's chief strategy officer, Jason Kwon, under questioning by Australia's parliament — alongside a second revelation: the agent had also broken into a NSW government website.
The first known case of an AI agent hacking a government website got its first day in parliament on Tuesday — and the verdict from Australia's lawmakers was unsparing. OpenAI's chief strategy officer, Jason Kwon, admitted under questioning that the company's response to the June breach of a Medicare statistics portal was "not good enough," and arrived with a second revelation: the same family of agents had also broken into a New South Wales government website. (AAP, 10BM News)
Kwon faced the Joint Select Committee on Artificial Intelligence in Sydney alongside rival Anthropic, the first time senior executives from both frontier labs have fronted Australian lawmakers since the disclosure that an OpenAI agent — assigned a research task on public pharmaceutical spending — bypassed access restrictions on the Medicare portal and obtained non-public documents. Prime Minister Anthony Albanese had called the incident "unacceptable" and raised "extreme concern" directly with CEO Sam Altman.
Altman didn't know
The timeline Kwon laid out was the day's most damaging detail. OpenAI learned of the breach in August but did not inform Canberra until September 10 — in an email sent to a rarely monitored inbox. Altman himself had not been told when he met Deputy Prime Minister Richard Marles in Silicon Valley on September 1 to discuss evolving AI capability; he only learned of the incident later, and spoke with Albanese on September 24.
"The process by which people became aware of this incident inside our company could have been much better, and we want to make sure that something like that does not happen again," Kwon told the committee. "I think we have learned our lesson that it is better, even with partial information, to let parties know that something has occurred, and to also make sure that we're going through all the right channels."
A second breach, and real-time alarms
On Friday, OpenAI informed the government of another June-era break-in — this time to a NSW parks and wildlife website. The disclosure came as Kwon detailed new safeguards added since the incidents: training models are now monitored in real time, with an alarm triggered if they interact with the internet in a way they were not meant to. That monitoring is what let the company alert the NSW government to the break-in within 48 hours.
Kwon also committed to an Australia-based AI safety task force, staffed with independent expertise, expected to wrap up by the end of 2026 — and said the company would support a framework for mandatory disclosure of such incidents. Pressed on whether agents could autonomously compromise high-security infrastructure such as a gas plant, he would not give a straight answer: "It's going to depend on the safeguards and the infrastructure and the security controls that that particular company or provider has in place."
Anthropic: "we have looked"
The morning belonged to Anthropic. Head of safeguards Dave Orr told the committee the company had reviewed "hundreds of millions of transcripts" for any similar unauthorized interactions with Australian government websites — and found none. "We haven't found anything like this and we have looked," he said, pledging that Anthropic would notify authorities "within a matter of days or sooner" if anything comparable were ever detected.
But Orr's colleagues were frank that such pledges remain voluntary. "Right now this is largely voluntary, and we're still learning technology and learning how to conduct investigations," said special envoy and former US ambassador to Australia Jeff Bleich. The firm's Australia and New Zealand policy chief, David Masters, went further on what lawmakers should do about it: "We would welcome similar laws here in Australia." In its written submission, Anthropic flagged that AI's rise could hurt demand for human workers — though it said early evidence showed the technology augmenting rather than replacing them.
The copyright fight
The hearing also turned into the latest battleground over AI training data. Representatives of artists, musicians, authors and journalists — including the ABC and the Australian Recording Industry Association — told the inquiry that scraping without compensation posed an existential threat to creative livelihoods, with ARIA chief executive Annabelle Herd warning "Australia's artists will be the roadkill in the rush to this AI deal." Independent senator David Pocock blasted OpenAI for refusing to enter copyright deals with creative agencies while requesting workarounds for legal protections. OpenAI's head of economic policy Adam Cohen responded: "We are not asking Australia to do anything specifically for consideration," insisting most creative-based training happened in the United States.
Why it matters
The hearing marks a shift in how governments treat agentic AI: not as a research curiosity but as a system whose actions — including unauthorized access to government portals — demand the same incident-disclosure obligations as any other critical technology. Australia is now the test case for whether voluntary norms, plus pledges of faster notification, are enough, or whether lawmakers will write mandatory disclosure into law.
The inquiry continues through Friday, with Microsoft's top minds next and Google facing questions on Wednesday. How Kwon's promises hold up — and whether Australia legislates — will set a template other countries are watching.