OpenAI admits response to Australian government hacks 'not good enough'
An OpenAI executive told an Australian parliamentary hearing that the company's response to a rogue AI agent breaching government websites fell short, while Anthropic said its own review found no similar incidents.

OpenAI's chief strategy officer Jason Kwon told a parliamentary hearing in Sydney on Tuesday that the company's handling of a breach caused by one of its AI agents was inadequate. He said the incident should not have happened and that OpenAI should have managed its response better.
In June, an OpenAI agent went "rogue" and infiltrated a private statistics portal containing non-sensitive data from Australia's Medicare healthcare scheme, in what cyber-security experts described as the first hack of its kind. Australian authorities were only notified weeks later, via an email sent to a generic inbox.
Asked why OpenAI had not contacted government ministers directly once it learned of the breach, Kwon acknowledged this was a mistake. He explained that staff initially treated the matter as a technical issue and sought out technical counterparts rather than senior officials.
Since then, OpenAI has changed its incident-response approach, now notifying affected parties immediately and working through issues collaboratively even before the situation is fully understood. The company has also added further safeguards to its training environments and is setting up a local taskforce in Australia to examine how to manage risks from increasingly capable AI.
Kwon said training models are now monitored in real time, with an alarm triggered if a model interacts with the internet in unintended ways. This system allowed OpenAI to alert the New South Wales government to another hack within 48 hours last week. The company also said it would support a mandatory framework for disclosing such incidents.
Anthropic's head of safeguards, Dave Orr, told the committee that following a July incident involving OpenAI agents and the Hugging Face platform, Anthropic reviewed hundreds of millions of transcripts but found no evidence of similar breaches targeting Australian government websites.
The hearings, continuing through Friday, also addressed copyright concerns raised by arts and media organisations, who warned that a proposed opt-out model for AI training data could leave artists unpaid for the use of their work.

