The tech giant admits the response could have been better, adding that the breach might not have been discovered if an email was never sent.
OpenAI has apologised for the unauthorised access to a Services Australia Medicare website and admitted the company’s response “should have been better” and revealed that the attack was “not super sophisticated”.
Appearing at the Joint Select Committee on Artificial Intelligence’s inquiry in Sydney on Tuesday, representatives of the tech giant faced questioning over an OpenAI agent’s access to the Medicare website on 18 June.
OpenAI did not tell Services Australia until 10 September, with the government taking another two weeks to publicly announce the breach.
This article originally ran on TMR’s sister site, Health Services Daily. TMR readers can sign up for a discounted subscription.
“I want to begin with an apology,” OpenAI chief strategy officer Jason Kwon said in his opening statement to the inquiry.
“During internal training and evaluation, our models accessed Australian government websites in ways they were not directed to. That should not have happened.
“We also should have handled our response better. We are sorry, and we know we have work to do to rebuild trust with the Australian people.
“We are committed to doing that work.”
Independent Senator David Pocock asked why OpenAI sent an email to a general government email address when it discovered the Services Australia breach.
“I assume someone in your government relations teams or someone in your company has mobile phone numbers of ministers and various people in government,” Senator Pocock said.
“How come there wasn’t that contact? Why did you just send an email to some arbitrary department email?”
Mr Kwon admitted that that response was not good enough.
“in retrospect, we should have done what you were suggesting,” he said.
“The reason why it happened the way that it did is I think people were thinking about this as a technical situation and they wanted to contact the technical counterparties, but it’s not good enough.”
Mr Kwon also told the inquiry that OpenAI CEO Sam Altman was not aware of the breach when he met with Deputy Prime Minister Richard Marles on 1 September.
Labor MP Jonathan Duniam asked whether the Australian public would know about the breach if OpenAI had not have sent that email to a government address.
“If you hadn’t voluntarily provided that information to government, we still wouldn’t know today,” Mr Duniam said.
Mr Kwon said: “Yeah, it’s possible that it would not have been discovered.
“It’s possible that somebody might have discovered some activity online, but not necessarily been able to attribute it to our agents.
“On the look back after the Hugging Face incident, as we discover these events sometime in mid-August, work through our analysis, then got to disclosures within 30 days of our discovery.
“[We] wish we had done the notifications faster, but I think that what you say is a reasonable conclusion.”
Mr Kwon was asked for more details regarding the Services Australia website breach.
“It found a non-public access point, and we would probably have to take this question on notice to get to the technical details in terms of how sophisticated the measures were,” he said.
“But my understanding, based on some of the briefings I got, is that it was not super sophisticated.
“I think the question … is not so much about the sophistication as much as the automation, and it’s the fact that now you have the ability to … take agents and then apply them to a goal, and they will continue to work towards that goal.”
Senator Pocock asked how much revenue OpenAI had made since establishing an Australian subsidiary in May last year.
Mr Kwon took the question on notice.
Related
In his opening statement, Mr Kwon said:
“We believe AI can advance scientific discovery, and medical research, improve productivity, grow businesses, and make a positive difference to people’s lives here in Australia, and around the world.
“But for that to happen, people have to be able to trust this technology and the companies building it.
“That work begins with our own safeguards.
“Following the Hugging Face incident, our response has focused on strengthening research security, monitoring, and model alignment, as well as improving how we identify, escalate, and respond to incidents.
“In some cases, we’ve also chosen to pause training of our certain frontier models while we strengthen our training infrastructure, monitoring, and approach to alignment. These steps are especially important as we enter a new era of AI capabilities.
“As these systems become more capable, the risks are evolving too, requiring new approaches to how we protect systems and respond to emerging threats.
“Our responsibility goes beyond our own systems. It also means helping Australia prepare and respond to these risks.”
Mr Kwon said OpenAI was committing resources and technical assistance to affected Australian agencies to help strengthen cyber defences through the $1 billion Daybreak Fund.
“We’re also establishing a local task force here in Australia, with independent Australian expertise, to make recommendations on how to better manage the risks associated with increasingly capable AI.
“We expect it to complete its work by the end of the year.
“When we identify additional incidents, as we did recently with the NSW National Parks and Wildlife Service, we will notify affected parties promptly and directly and provide updates as further facts emerge.
“These responsibilities become more important as AI has become part of everyday life here in Australia.”
Mr Kwon said around half of Australian adults used ChatGPT every week and Australia was leading the business adoption of AI globally.
OpenAI was investing in AI skills training and education in Australia, and working with Australian labs to accelerate scientific discovery, he said.
“We’re committed to building on this work and helping Australia realise the benefits of AI.
“That starts with acknowledging where we fell short, falling through on our commitments that we’ve made, and earning the trust of the Australian people through our actions.”
Labor MP Andrew Hastie asked for OpenAI’s 60-second elevator pitch “for Aussie mums, dads, workers and seniors” who don’t understand AI but have seen negative headlines in the last two weeks.
Mr Kwon said the technology has the potential “to deliver great benefits to everyday people” and gave examples such as diagnosing cancers and rare diseases, and visually impaired people using the technology to navigate their environment.
“In other places in the world, you have 17 and 18-year-olds using the technology to design advanced wildlife detection systems to solve for the after-effects of climate change in states like California, which are very susceptible to wildfires.”
In its submission to the inquiry, OpenAI said Australians send almost 60 million messages to ChatGPT each day, which is an increase of around 30% over the past year.
“AI is already part of everyday life in Australia.
“Australia has also risen to the Top 20 globally in ChatGPT messages per capita since the beginning of 2026.
“And it now ranks among the Top 15 globally for per-capita adoption of agentic AI tools.
“That level of adoption presents Australia with an opportunity: to translate widespread use of AI into higher productivity, stronger skills, and broader economic opportunity.”
Anthropic has ‘no evidence of breaches’
Earlier in the day, representatives from Anthropic were asked how confident they were that their organisation had not breached any Australian government websites.
“And do you have visibility over significant breaches through use of your models by private individuals or organisations?” MP Kate Chaney asked.
Anthropic head of safeguards Dave Orr said Anthropic had been running a lengthy investigation in the wake of the Hugging Face disclosures to understand whether their models had accessed networks “in an unauthorised way”.
“This has involved reviewing hundreds of millions of transcripts and had not found any evidence of a breach of Australian government websites.
“We have not found any cases where it interacted with Australian government systems in some sort of unauthorised way.
“We haven’t found anything like this, and we have looked.”
But Mr Orr said they had less visibility of customer usage because those prompts and responses were not stored.
“This is something that is very commonly demanded by enterprise customers, and is standard.
“We’ve been working toward retaining more data so that we can run investigations if we need to, but for the majority of our historical usage by customers, that usage is in ZDR [zero data retention], and so we can’t look through it and determine if you know anything like this happened.”



