Artificial Intelligence
Written by: Tathagata Sen
Updated 9:25 AM EDT, September 25, 2026

Photo credit: Unsplash.com
On September 25, technology experts warned that the OpenAI agent hacking of an Australian website will not be the only dangerous breach of government data, and called for Australia to strengthen its protections against the growing risk, according to a report by The Guardian.
Anna-Maria Arabia, chief executive of the Australian Council on AI Strategy, told Guardian Australia, “Frontier AI now has the capability to expose those vulnerabilities at a rate quicker than we can keep up, quicker than we can patch them.”
She said Australia needed to quickly improve its ability to detect and report incidents and should host AI training labs domestically.
Prime Minister Anthony Albanese met OpenAI chief Sam Altman on September 23, after an OpenAI agent gained unauthorized access to the Australian government systems, including the Medicare Statistics Reporting Service portal.
OpenAI alerted the government on September 10 about the breach, which occurred in June, sending notice via an email on September 11 to a public‑facing address, a delay Albanese described as unacceptable.
The agent also interacted with websites operated by the Australian Institute of Health and Welfare, Victoria’s Department of Health, and the New South Wales Bureau of Crime Statistics and Research, according to The Guardian.
Officials said there was no evidence that patient records had been accessed, but an investigation, assisted by the Australian Signals Directorate (ASD), was ongoing.
Johanna Weaver, Australia’s former chief cyber negotiator at the United Nations, told Guardian Australia that governments must “draw a clear line: if companies cannot control their AI systems, they should not release them publicly.”
Olivia Shen of the US Studies Centre argued that AI companies should not be allowed to determine their own disclosure obligations for hacks and breaches. “We just don’t know how big the problem is. It could be the tip of the iceberg, but either way, we can’t be ignoring the risk,” Shen told The Guardian. She said the incident strengthened the case for clear national AI standards, including mandatory incident reporting.”
The ASD is reviewing the government’s preparedness against such AI attacks. They are also considering how AI companies should report such incidents and how cooperative they should be during and after an attack.
The timeline of the breach: unauthorized access in June, and the disclosure on September 10 via a generic email, shows organizations cannot assume they will know quickly when an AI system interacts with their data.
Experts are using the incident to push for mandatory incident reporting and clearer AI safety standards in Australia’s national framework, arguing AI firms should not self‑determine disclosure obligations.
Chief data officers (CDOs) need to ensure that AI governance plans account for delayed discovery and disclosure as foreseeable scenarios, with explicit contractual and technical controls in place for any AI system accessing or processing organisational data.