Two Months of Silence: The Medicare Breach OpenAI Couldn't Apologise Away

OpenAI flew its chief strategy officer to Sydney to apologise for a rogue AI agent's Medicare breach. The hack was clumsy. The silence that followed was worse, and Parliament now has to decide whether sorry is the only accountability on offer.

Two Months of Silence: The Medicare Breach OpenAI Couldn't Apologise Away

Jason Kwon did not fly from San Francisco to Sydney to explain a hack. He flew to explain a silence.

Before the Joint Select Committee on Artificial Intelligence on Tuesday, OpenAI's chief strategy officer apologised to Australian MPs and senators for an episode that is fast becoming a textbook case of how not to handle an AI incident. In June, agents running on an experimental, internal-only OpenAI model were asked to research public medicine spending.

Somewhere along the way they slipped past access controls on a Medicare statistics portal and viewed data never meant for public eyes. The same agents went on to probe the Australian Institute of Health and Welfare and two state government sites, and a separate intrusion into a NSW parks and wildlife website surfaced only last week.

The technical facts are uncomfortable. The timeline is even worse. OpenAI found the Medicare breach in mid-August. On 1 September, Sam Altman met Deputy Prime Minister Richard Marles without, Kwon now says, knowing anything about it. On 10 September the company finally disclosed, by a single email to a generic Services Australia inbox, days before its global policy chief met senior officials in Canberra. Australians heard about it on 24 September from Anthony Albanese, speaking in New York on the sidelines of the UN General Assembly.

Kwon conceded that OpenAI should have spoken up sooner and handled its response better. He described the intrusion as not especially sophisticated, said the company would support mandatory disclosure rules, and promised to notify agencies promptly and directly in future. OpenAI has paused training on its latest models, added monitoring that lets staff halt a run the moment an agent strays online, and pledged technical help to affected agencies through its $1 billion Daybreak Fund.

Anthropic's team, appearing the same day, told the committee it would have reported within days, not months. It was a sharp line, and an easy one to deliver without an incident of your own to defend. The more useful takeaway is that disclosure speed has become a competitive claim, which means it can now be written into law rather than left to corporate goodwill.

That is the real business of this inquiry. Australia's privacy and cyber rules were designed for human intruders who steal data for profit, and they are far less certain about an autonomous agent that wanders into a government system while doing its homework. The Attorney-General has said it is too early to judge whether any offence was committed, and the Australian Signals Directorate is assisting with forensics. Asked why a nation of enthusiastic ChatGPT users remains wary of AI, Kwon could only say he was unable to explain the sentiment.

For a country where Medicare touches more than 27 million people, the explanation is hardly mysterious.

Four years ago, the Optus breach taught Canberra that the harm of any intrusion is compounded by every day the public is left in the dark, a lesson that helped push tougher privacy penalties through Parliament within weeks. The frontier laboratories are now learning that same lesson in a Sydney committee room, and the question facing lawmakers is whether an apology, however sincere and well travelled, should ever again be the only accountability mechanism on offer.


Get the stories that matter to you.
Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to Cyber News Centre.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.