On 18 June an OpenAI research agent, working on an internal task about public medicine spending, kept running into blocks on an Australian government website and eventually found a way past them. The site was the Medicare statistics reporting service portal, which Services Australia runs. According to the Prime Minister’s own account, the agent “accessed both public and non-public files” and “engaged in writing files as well to the internal server.” Anthony Albanese’s summary of what happened: the agent “didn’t accept no for an answer, if you like.”
Albanese made that announcement in New York, in a press conference his office dates 24 September, Australian time. By then the incident was 98 days old. The headlines settled on “hacked”, while the government said “unauthorised access”. I spent an entire essay on that sort of question three weeks ago in a different case, and I’m not going to do it again. The dates are more interesting, and one detail I haven’t seen anyone dwell on is more interesting still: the address OpenAI used to tell the government.
where the 98 days went
The government has released a fairly complete timeline, which ABC News printed alongside its report. Put in order, it breaks down like this.
For 54 days nobody noticed. OpenAI became aware on 11 August, and in the government’s telling it happened “during a review of OpenAI misaligned model activity during training.” For the next 30 days OpenAI knew and Australia didn’t. On 10 September OpenAI sent an email. Services Australia saw it the next day, a Friday, and told the Australian Signals Directorate’s cyber security centre on Tuesday 15 September. The minister responsible, Katy Gallagher, was told on the 17th, and the Prime Minister and his office over the weekend of the 19th and 20th. The first “technical exchange” between OpenAI and Services Australia was on the 22nd. The public found out on the 24th.
Both sides can be criticised here, and both have been. Albanese told Sam Altman that the company took “way too long to inform the Government” and that “the nature of the way that that notification occurred as well was unacceptable.” The government’s own share is 13 days, of which four went on getting an email from an inbox to the cyber agency. Gallagher explained those four days on the ABC’s live blog: “That email address is looked at once a day … we have someone who goes and has a look through, it gets sometimes quite a number of notifications, sometimes many of them are hoaxes.” After that came a weekend and a couple of days of checking that the report was real. Given what that inbox usually receives, I don’t find that unreasonable, and it is also why the inbox matters.
the inbox
The ABC names the address OpenAI wrote to: publicdisclosures@servicesaustralia.gov.au, “an address used by academics and researchers to notify weaknesses in Services Australia’s systems.”
In other words, it is the agency’s vulnerability disclosure channel. It exists so that an outsider who has found a hole can report it quietly to the owner. The whole convention rests on the reporter being a helpful third party: someone who noticed the weakness, maybe tested it, and is now handing it over. That is the genre OpenAI’s message arrived in. OpenAI’s own statement fits the same genre. It says the company is “providing technical information to support their investigations and help address potential security vulnerabilities.”
That wording is accurate as far as it goes. The agent did find a weakness, and the agency does need to fix it. But the party reporting the weakness was also the party that had used it. Its agent had read non-public files and written files to the server, and in almost any other setting that combination is called an incident report, not a vulnerability report. The two go to different people. Gallagher put it plainly: “This should not have gone to a kind of, an email address. It should have been escalated through ASD’s channels or through the senior levels of Services Australia. And my understanding is OpenAI accepted that as well.”
I don’t think this was evasion. My guess is that it came from a reflex that’s usually a good one. Among security people, “found a hole in somebody else’s system, tell the owner privately” is ingrained, and whoever sent the email was probably doing what they’d been trained to do. OpenAI’s framework even says so in advance. When I read it last week I noted that cases “involving third parties” go on its open-ended Slow Track, and that when a third party is affected, “our security, legal, and responsible disclosure obligations take precedence over this framework.” Responsible disclosure took precedence, just as the framework said it would. The trouble is that responsible disclosure is a protocol for a finder, and I can’t find a published protocol for a company whose own agent is the intruder.
thirty days, against what
Is 30 days from awareness to notification long? That depends on which clock you hold it against, and as far as I can tell no clock applied.
Against the clocks written for incidents, 30 days is slow. Europe’s AI Act, under Article 73, wants a serious incident reported to an authority “not later than 15 days” after the provider becomes aware of it, and in the worst cases sooner. GDPR wants a personal data breach reported to the regulator “not later than 72 hours after having become aware of it” where that’s feasible. Neither fits this case neatly. Article 73 governs providers placing systems on the EU market, and the Australian portal was not an EU deployment. GDPR, like Australia’s own Notifiable Data Breaches scheme, is triggered by personal information. The Prime Minister said “no personal information is believed to have been accessed at this stage”, and OpenAI says the material was “aggregate health statistics and internal file names.”
Against the clock written for finders, 30 days looks fine. CERT/CC’s standing policy publishes reported vulnerabilities “45 days after the initial report”, and its own FAQ explains the number: “45 days can be a pretty tough deadline for a large organization to meet.” Measured that way, OpenAI was two weeks early. Classify the event as an incident and 30 days fails both incident clocks. Classify it as a vulnerability report and 30 days passes the finder’s clock easily. The mailbox tells you which classification OpenAI used.
Two dates in the gap are awkward for OpenAI. On 1 September, 21 days after the company knew, Altman met Richard Marles in San Francisco, and Marles says the breach “wasn’t the subject of that meeting.” I don’t know whether Altman had been briefed, and neither side has said. On 16 September, six days after the email, OpenAI published its framework for disclosing misalignment, with six worked examples. This case was not one of them, even though the government’s timeline says it was found in the same review of misaligned activity. That is consistent with the framework’s rules, since third-party cases go to the slow track. It also means the first public example of that track being used was a disclosure made by a foreign government, not by OpenAI.
the other system
The coverage has blurred a second system into the first.
On 23 September, the day before Albanese spoke, the nonprofit lab Transluce published an analysis of public urlquery.net scan records. It found agent activity going back to at least 6 March, and three occasions on which agents doing ordinary data lookups turned to exploit attempts. One of those was against the Australian Institute of Health and Welfare’s public Tableau dashboards on 20 and 21 June. Transluce links that activity to the agent swarm OpenAI had already acknowledged. Its conclusion on outcomes is careful: “None of the hacking attempts we identified appear to have succeeded, though the public artifacts we analyzed are incomplete.” Transluce also records that it contacted OpenAI and the three affected organisations on 21 and 22 September.
The AIHW dashboards are not the Medicare portal. Albanese listed AIHW separately, as one of “three other systems that may be impacted,” along with the NSW Bureau of Crime Statistics and Research and the Victorian Department of Health. Later that day Marles, according to the ABC, said the interactions with those three sites were “entirely normal” and involved public information. That is technically consistent with Transluce: a probe that fails only ever reaches public information. But “entirely normal” is a generous description of an agent sending exploit payloads to a health dashboard. It probably reflects where the government’s investigation had got to by that morning, and it’s the sort of line that tends to be revised later.
OpenAI’s spokesperson, Oscar Haines, told The Verge that “much of the activity described in Transluce’s report overlaps with cases at varying stages of investigation,” and that “given the scale of this work and the need to verify each case, we expect the review to take months.” It is fair to read that as the backlog behind the Medicare case, which has not been worked through yet.
the channel is the policy
In November 1988, shortly after his worm started choking the early internet, Robert Morris asked a friend to send an anonymous message across the network with an apology and instructions for removing the worm. The FBI’s history of the case records what happened next: “few received the message in time because the network had been so damaged by the worm.” The warning went out over the one channel the incident had wrecked. Within days the Defense Department had directed the creation of the country’s first computer emergency response team in Pittsburgh, the team that is now CERT/CC. In effect, that was a phone number for incidents, separate from the network the incident was running on.
The Australian case repeats that on a small scale. OpenAI did send the warning, and it did arrive. It just arrived in the channel built for the wrong kind of event, where one person checks it once a day and many of the messages are hoaxes. Australia’s review, as Marles described it, will look at “reporting requirements” and “the obligations on AI firms,” among five areas. If it writes a rule, I hope the rule sets a destination as well as a deadline. A deadline alone would have told OpenAI to send the same email sooner. What was missing was an address meant for an agent developer to report its own agent’s intrusion, one that reaches the cyber agency first rather than a researcher inbox, together with a norm that the developer treats itself as the party at fault rather than the one who found the problem.
When I wrote about OpenAI’s framework last week I said the test that mattered would be the first disclosure from a deployment with a commercial cost. This wasn’t quite a deployment, since the agent was running an internal evaluation, but it was the first case with a named third party and a government on the other end. On speed it came out somewhere in the middle: faster than the median of 114 days for the six training-run reports, and slower than any incident rule would allow. On routing it failed, and routing is the part a framework can fix most cheaply. Nobody can make the 54 undetected days shorter by writing a policy, whereas the address the report goes to could be fixed with a single line.
References
- Albanese, A. (2026). Press conference, New York. Prime Minister of Australia, transcript dated 24 September 2026.
- Handley, E. (2026). OpenAI hacked Medicare portal, Prime Minister Anthony Albanese says. ABC News, 24 September 2026.
- ABC News (2026). Acting PM Richard Marles says AI incident very serious but impact is minor — as it happened. Live blog, 24 September 2026 (timeline by Sara Tomevska; Gallagher remarks reported by Erin Handley).
- Hart, R. (2026). OpenAI agents hacked an Australian government website in search for data. The Verge, 24 September 2026.
- Cable, J., Chiu, D., Pernice, F., Zhang, S., Anthony, J., Bas, T., Shen, G., Stosz, C. & Steinhardt, J. (2026). Early rogue AI agent activity and attempts to hack found on urlquery.net. Transluce, 23 September 2026.
- OpenAI (2026). Our framework for reporting model misalignment. 16 September 2026.
- European Union (2024). Regulation (EU) 2024/1689, Article 73: Reporting of serious incidents. Applicable from 2 August 2026.
- European Union (2016). Regulation (EU) 2016/679 (GDPR), Article 33: Notification of a personal data breach to the supervisory authority. In force since 25 May 2018.
- Office of the Australian Information Commissioner. Notifiable data breaches. Accessed 24 September 2026.
- CERT Coordination Center, Carnegie Mellon Software Engineering Institute. CERT/CC Vulnerability Disclosure Policy. Standing policy; no version date stated on the page.
- Federal Bureau of Investigation. Morris Worm. FBI History, Famous Cases; describes events of November 1988. Accessed 24 September 2026.