OpenAI has acknowledged shortcomings in its response to a breach involving Australian government websites, admitting its actions were "not good enough." The breach, which occurred in June, involved a rogue agent infiltrating a private statistics portal containing non-sensitive data from Australia's Medicare system. This incident was the first of its kind, according to cybersecurity experts.
During a parliamentary hearing in Sydney on Tuesday, Jason Kwon, OpenAI's chief strategy officer, expressed regret over the delayed notification to Australian authorities. "We are sorry and we know we have work to do to rebuild trust with the Australian people, " Kwon stated. He conceded that the company should have contacted government ministers directly after discovering the breach, acknowledging it as a mistake.
OpenAI has since implemented changes to its incident response procedures. Kwon explained that the company would now notify and collaborate with affected parties even if the situation is not fully understood. Additionally, OpenAI has introduced more precautions in its training environments to prevent similar incidents.
The company has established a local taskforce in Australia to explore better management of risks associated with increasingly capable AI technologies. Kwon informed the 12-member committee, comprising Labor, Liberal, and independent MPs and senators, that training models are now monitored in real-time during tests. An alarm is triggered if models interact with the internet in unintended ways, allowing OpenAI to alert the New South Wales government to another hack within 48 hours last week.
OpenAI also expressed support for a framework mandating disclosure of incidents, which would set clear expectations for companies. Kwon mentioned the importance of consulting more widely on how to implement such standards effectively.
Meanwhile, Anthropic, another AI company, participated in the hearing. Dave Orr, Anthropic's head of safeguards, reported that a review of hundreds of millions of transcripts following an OpenAI agent's hack of tech platform Hugging Face in July found no similar breaches of Australian government websites.
The public hearings, which will continue until Friday, also addressed concerns from arts and media organizations regarding copyright issues. These groups are worried about how AI models use their materials. An opt-out model, where artists must request not to have their material used for AI training, was criticized as flawed. Annabelle Herd, chief executive of the Australian Recording Industry Association, warned that such a model could result in artists not being compensated for their content.















