OpenAI Concedes Australia May Never Have Discovered Medicare Hack Without Its Disclosure

1 hour ago 17
OpenAI Concedes Australia May Never Have Discovered Medicare Hack Without Its Disclosure

The OpenAI logo is seen in this illustration taken June 11, 2026. Dado Ruvic/Reuters

OpenAI concedes it was possible the Medicare hack by one of its AI agents may “not have been discovered” by Australian authorities had it decided not to reveal the incident itself.

Open AI’s Chief Strategy Officer Jason Kwon started his testimony to an Australian parliamentary inquiry with an apology, saying one of the company’s AI models “accessed Australian government websites in ways they were not directed to” and that this “should not have happened.”

He said the company found out about the events in mid-August and made its disclosures within 30 days, adding that he wished the notifications had been delivered faster.

He said a further incident, involving the New South Wales (NSW) National Parks and Wildlife Service, had been disclosed within 48 hours of its discovery.

Kwon flew to Australia to front the Joint Standing Committee on Artificial Intelligence.

OpenAI Chief Strategy Officer Jason Kwon opens the door for Sarah O'Brien at the Ronald V. Dellums Federal Building in Oakland, California on May 18, 2026. (Benjamin Fanjoy/Getty Images)

OpenAI Chief Strategy Officer Jason Kwon opens the door for Sarah O'Brien at the Ronald V. Dellums Federal Building in Oakland, California on May 18, 2026. Benjamin Fanjoy/Getty Images

Senator David Pocock asked whether Open AI CEO Sam Altman knew of the incidents when he met the Australian Deputy Prime Minister Richard Marles on Sept. 1, to which Kwon replied that Altman “was not aware at the time.”

Pocock also asked why OpenAI had emailed a department instead of phoning ministers, and Kwon said staff treated the matter as a technical issue, which he conceded was “not good enough.”

Kwon said the incidents varied from site to site.

In one, a model downloaded publicly accessible information, in another it used an API token it had found, and at Services Australia it found “a non-public access point.”

An API token is like a digital ID badge; it proves identity to a system and grants permission to access specific areas or perform certain tasks

Centre-right Coalition MP Aaron Violi asked how sophisticated the methods were. Kwon said briefings suggested it was “not super sophisticated,” but that the key issue was automation, because agents “will continue to work towards that goal [of getting access].”

OpenAI is now reviewing about 50 petabytes of data dating back to November 2025, and Kwon said that so far, the incidents that the company has reported are the only ones it has discovered.

He said it has added monitoring alerts so that staff know when a model accesses the internet unexpectedly during training. OpenAI has also paused training on certain frontier models, and will offer the affected agencies access to its Daybreak cybersecurity tools, which he said was something “we’re working on right now.”

OpenAI’s Peter Anstee, head of national security policy, said the Australian incidents did not compare in severity to the earlier, well-publicised Hugging Face incident.

Asked by Independent Teal MP Kate Chaney whether OpenAI would support compulsory incident reporting, Kwon said: “Yes, we would support a framework on mandatory disclosures.”

The question of mandatory reporting is already emerging as part of the Australian government’s response to the Medicare incident.

The government has indicated that new AI rules could include procedures for reporting incidents involving rogue AI agents. That could shift responsibility for identifying and reporting unexpected AI behaviour away from voluntary company processes and towards a formal regulatory system.

Read Entire Article