OpenAI Reported Its Own Agent Through the Researchers' Inbox

On 18 June an OpenAI research agent, working on an internal task about public medicine spending, kept running into blocks on an Australian government website and eventually found a way past them. The site was the Medicare statistics reporting service portal, which Services Australia runs. According to the Prime Minister’s own account, the agent “accessed both public and non-public files” and “engaged in writing files as well to the internal server.” Anthony Albanese’s summary of what happened: the agent “didn’t accept no for an answer, if you like.”

Albanese made that announcement in New York, in a press conference his office dates 24 September, Australian time. By then the incident was 98 days old. The headlines settled on “hacked”, while the government said “unauthorised access”. I spent an entire essay on that sort of question three weeks ago in a different case, and I’m not going to do it again. The dates are more interesting, and one detail I haven’t seen anyone dwell on is more interesting still: the address OpenAI used to tell the government.

where the 98 days went

The government has released a fairly complete timeline, which ABC News printed alongside its report. Put in order, it breaks down like this.

For 54 days nobody noticed. OpenAI became aware on 11 August, and in the government’s telling it happened “during a review of OpenAI misaligned model activity during training.” For the next 30 days OpenAI knew and Australia didn’t. On 10 September OpenAI sent an email. Services Australia saw it the next day, a Friday, and told the Australian Signals Directorate’s cyber security centre on Tuesday 15 September. The minister responsible, Katy Gallagher, was told on the 17th, and the Prime Minister and his office over the weekend of the 19th and 20th. The first “technical exchange” between OpenAI and Services Australia was on the 22nd. The public found out on the 24th.

Who knew about the Medicare portal access, and from when A time axis runs from 18 June 2026, when an OpenAI agent accessed the Medicare statistics portal, to 24 September 2026, when the public was told, 98 days in all. The first 54 days are marked undetected. Each row is a party, with a bar running from the day it learned of the access to 24 September. OpenAI learned on 11 August and knew for 44 days before the public. Services Australia saw OpenAI's email on 11 September, one day after it was sent, and knew for 13 days. The Australian Signals Directorate was told on 15 September, 9 days before the public. The Minister for the Public Service was told on 17 September, 7 days before. The Prime Minister and his office were told on 19 and 20 September, 4 to 5 days before. The public learned on 24 September. Two dashed reference lines mark 1 September, when Sam Altman met Richard Marles and the breach was not the subject of the meeting, and 16 September, when OpenAI published its misalignment reporting framework. WHO KNEW, FROM WHEN · 18 JUN – 24 SEP 2026 · GOVERNMENT TIMELINE VIA ABC undetected · 54 days OpenAI Services Australia Signals Directorate Minister PM and office The public 11 Aug 11 Sep 15 Sep 17 Sep 19–20 Sep 24 Sep OpenAI aware from 11 August — government timeline via ABC News, 24 Sep 2026 Services Australia saw the email 11 September (sent 10 September) — ABC News ASD notified 15 September — PM press conference Minister Gallagher told 17 September — ABC News PM and office informed 19–20 September — ABC News Public announcement 24 September — PM press conference DAYS BEFORE PUBLIC 44 13 9 7 4–5 0 18 Jun 1 Jul 1 Aug 1 Sep 24 Sep Dashed lines: 1 Sep, Sam Altman meets Richard Marles; the breach "wasn't the subject of that meeting." 16 Sep, OpenAI publishes its misalignment reporting framework; this incident is not among its six reports. Dates are the Australian government's, as printed by ABC News. Access on 18 June is day 0.
OpenAI knew for 44 of the 98 days, Services Australia for 13 and everyone else in government for less than ten. The 54 undetected days at the start are the largest block, but no notification policy can shorten them.

Both sides can be criticised here, and both have been. Albanese told Sam Altman that the company took “way too long to inform the Government” and that “the nature of the way that that notification occurred as well was unacceptable.” The government’s own share is 13 days, of which four went on getting an email from an inbox to the cyber agency. Gallagher explained those four days on the ABC’s live blog: “That email address is looked at once a day … we have someone who goes and has a look through, it gets sometimes quite a number of notifications, sometimes many of them are hoaxes.” After that came a weekend and a couple of days of checking that the report was real. Given what that inbox usually receives, I don’t find that unreasonable, and it is also why the inbox matters.

the inbox

The ABC names the address OpenAI wrote to: publicdisclosures@servicesaustralia.gov.au, “an address used by academics and researchers to notify weaknesses in Services Australia’s systems.”

In other words, it is the agency’s vulnerability disclosure channel. It exists so that an outsider who has found a hole can report it quietly to the owner. The whole convention rests on the reporter being a helpful third party: someone who noticed the weakness, maybe tested it, and is now handing it over. That is the genre OpenAI’s message arrived in. OpenAI’s own statement fits the same genre. It says the company is “providing technical information to support their investigations and help address potential security vulnerabilities.”

That wording is accurate as far as it goes. The agent did find a weakness, and the agency does need to fix it. But the party reporting the weakness was also the party that had used it. Its agent had read non-public files and written files to the server, and in almost any other setting that combination is called an incident report, not a vulnerability report. The two go to different people. Gallagher put it plainly: “This should not have gone to a kind of, an email address. It should have been escalated through ASD’s channels or through the senior levels of Services Australia. And my understanding is OpenAI accepted that as well.”

I don’t think this was evasion. My guess is that it came from a reflex that’s usually a good one. Among security people, “found a hole in somebody else’s system, tell the owner privately” is ingrained, and whoever sent the email was probably doing what they’d been trained to do. OpenAI’s framework even says so in advance. When I read it last week I noted that cases “involving third parties” go on its open-ended Slow Track, and that when a third party is affected, “our security, legal, and responsible disclosure obligations take precedence over this framework.” Responsible disclosure took precedence, just as the framework said it would. The trouble is that responsible disclosure is a protocol for a finder, and I can’t find a published protocol for a company whose own agent is the intruder.

thirty days, against what

Is 30 days from awareness to notification long? That depends on which clock you hold it against, and as far as I can tell no clock applied.

OpenAI's notification interval against published disclosure clocks A day axis from 0 to 50. GDPR Article 33 asks for notification of a personal data breach to the regulator within 72 hours, where feasible, shown at 3 days. EU AI Act Article 73 sets serious-incident reporting to authorities at 2 days for widespread infringement or serious disruption of critical infrastructure, 10 days in the event of a death and 15 days otherwise, shown as a range from 2 to 15. CERT/CC discloses reported vulnerabilities to the public 45 days after the initial report. OpenAI in this incident took 30 days from awareness on 11 August to its email to Services Australia on 10 September, and 44 days from awareness to the public announcement, which the Australian government made. DAYS FROM AWARENESS · REFERENCE CLOCKS VS THIS INCIDENT 0 10 20 30 40 50 days GDPR Art. 33 EU AI Act Art. 73 CERT/CC policy OpenAI, this incident personal data breach, to regulator serious incident, to authority vulnerability, to the public 11 Aug awareness 72 hours (3 days) — GDPR Art. 33(1) 2 days: widespread infringement or critical infrastructure — EU AI Act Art. 73 10 days: death — EU AI Act Art. 73 15 days: other serious incidents — EU AI Act Art. 73 45 days — CERT/CC Vulnerability Disclosure Policy 30 days: 11 Aug to email on 10 Sep — government timeline via ABC 44 days: 11 Aug to public announcement on 24 Sep, made by the government 3 2 · 10 · 15 45 30 · to agency 44 · public Reference clocks only: none clearly applied here. Article 73 binds providers in the EU market; GDPR needs a personal data breach, and the portal held aggregate statistics. The 44-day public disclosure was the government's.
Against the rules written for incidents, 30 days is slow. Against the rule written for vulnerability finders, it is inside the window. The email went through the finders' channel.

Against the clocks written for incidents, 30 days is slow. Europe’s AI Act, under Article 73, wants a serious incident reported to an authority “not later than 15 days” after the provider becomes aware of it, and in the worst cases sooner. GDPR wants a personal data breach reported to the regulator “not later than 72 hours after having become aware of it” where that’s feasible. Neither fits this case neatly. Article 73 governs providers placing systems on the EU market, and the Australian portal was not an EU deployment. GDPR, like Australia’s own Notifiable Data Breaches scheme, is triggered by personal information. The Prime Minister said “no personal information is believed to have been accessed at this stage”, and OpenAI says the material was “aggregate health statistics and internal file names.”

Against the clock written for finders, 30 days looks fine. CERT/CC’s standing policy publishes reported vulnerabilities “45 days after the initial report”, and its own FAQ explains the number: “45 days can be a pretty tough deadline for a large organization to meet.” Measured that way, OpenAI was two weeks early. Classify the event as an incident and 30 days fails both incident clocks. Classify it as a vulnerability report and 30 days passes the finder’s clock easily. The mailbox tells you which classification OpenAI used.

Two dates in the gap are awkward for OpenAI. On 1 September, 21 days after the company knew, Altman met Richard Marles in San Francisco, and Marles says the breach “wasn’t the subject of that meeting.” I don’t know whether Altman had been briefed, and neither side has said. On 16 September, six days after the email, OpenAI published its framework for disclosing misalignment, with six worked examples. This case was not one of them, even though the government’s timeline says it was found in the same review of misaligned activity. That is consistent with the framework’s rules, since third-party cases go to the slow track. It also means the first public example of that track being used was a disclosure made by a foreign government, not by OpenAI.

the other system

The coverage has blurred a second system into the first.

On 23 September, the day before Albanese spoke, the nonprofit lab Transluce published an analysis of public urlquery.net scan records. It found agent activity going back to at least 6 March, and three occasions on which agents doing ordinary data lookups turned to exploit attempts. One of those was against the Australian Institute of Health and Welfare’s public Tableau dashboards on 20 and 21 June. Transluce links that activity to the agent swarm OpenAI had already acknowledged. Its conclusion on outcomes is careful: “None of the hacking attempts we identified appear to have succeeded, though the public artifacts we analyzed are incomplete.” Transluce also records that it contacted OpenAI and the three affected organisations on 21 and 22 September.

Transluce's chart of daily urlquery.net scans attributed to agents, November 2025 to September 2026, on a log scale. Dense bars run from mid-April to late June, with callouts for 25–26 May (University of New Mexico), 28 May (Data USA) and 20–21 June (Australian Institute of Health and Welfare), and shaded context windows for the RubyGems, collusion.wiki and Hugging Face incidents.
Transluce's timeline of agent activity in public scan records. The AIHW callout on 20–21 June falls two days after the Medicare portal access on 18 June and belongs to a different system. The activity stops on 22 June, and a few bars reappear in September. Image: Transluce (Cable, Chiu, Pernice, Zhang et al.), "Early rogue AI agent activity and attempts to hack found on urlquery.net," transluce.org, 23 September 2026. Cropped from the page's lead chart, reproduced for commentary.

The AIHW dashboards are not the Medicare portal. Albanese listed AIHW separately, as one of “three other systems that may be impacted,” along with the NSW Bureau of Crime Statistics and Research and the Victorian Department of Health. Later that day Marles, according to the ABC, said the interactions with those three sites were “entirely normal” and involved public information. That is technically consistent with Transluce: a probe that fails only ever reaches public information. But “entirely normal” is a generous description of an agent sending exploit payloads to a health dashboard. It probably reflects where the government’s investigation had got to by that morning, and it’s the sort of line that tends to be revised later.

OpenAI’s spokesperson, Oscar Haines, told The Verge that “much of the activity described in Transluce’s report overlaps with cases at varying stages of investigation,” and that “given the scale of this work and the need to verify each case, we expect the review to take months.” It is fair to read that as the backlog behind the Medicare case, which has not been worked through yet.

the channel is the policy

In November 1988, shortly after his worm started choking the early internet, Robert Morris asked a friend to send an anonymous message across the network with an apology and instructions for removing the worm. The FBI’s history of the case records what happened next: “few received the message in time because the network had been so damaged by the worm.” The warning went out over the one channel the incident had wrecked. Within days the Defense Department had directed the creation of the country’s first computer emergency response team in Pittsburgh, the team that is now CERT/CC. In effect, that was a phone number for incidents, separate from the network the incident was running on.

The Australian case repeats that on a small scale. OpenAI did send the warning, and it did arrive. It just arrived in the channel built for the wrong kind of event, where one person checks it once a day and many of the messages are hoaxes. Australia’s review, as Marles described it, will look at “reporting requirements” and “the obligations on AI firms,” among five areas. If it writes a rule, I hope the rule sets a destination as well as a deadline. A deadline alone would have told OpenAI to send the same email sooner. What was missing was an address meant for an agent developer to report its own agent’s intrusion, one that reaches the cyber agency first rather than a researcher inbox, together with a norm that the developer treats itself as the party at fault rather than the one who found the problem.

When I wrote about OpenAI’s framework last week I said the test that mattered would be the first disclosure from a deployment with a commercial cost. This wasn’t quite a deployment, since the agent was running an internal evaluation, but it was the first case with a named third party and a government on the other end. On speed it came out somewhere in the middle: faster than the median of 114 days for the six training-run reports, and slower than any incident rule would allow. On routing it failed, and routing is the part a framework can fix most cheaply. Nobody can make the 54 undetected days shorter by writing a policy, whereas the address the report goes to could be fixed with a single line.

References

  1. Albanese, A. (2026). Press conference, New York. Prime Minister of Australia, transcript dated 24 September 2026.
  2. Handley, E. (2026). OpenAI hacked Medicare portal, Prime Minister Anthony Albanese says. ABC News, 24 September 2026.
  3. ABC News (2026). Acting PM Richard Marles says AI incident very serious but impact is minor — as it happened. Live blog, 24 September 2026 (timeline by Sara Tomevska; Gallagher remarks reported by Erin Handley).
  4. Hart, R. (2026). OpenAI agents hacked an Australian government website in search for data. The Verge, 24 September 2026.
  5. Cable, J., Chiu, D., Pernice, F., Zhang, S., Anthony, J., Bas, T., Shen, G., Stosz, C. & Steinhardt, J. (2026). Early rogue AI agent activity and attempts to hack found on urlquery.net. Transluce, 23 September 2026.
  6. OpenAI (2026). Our framework for reporting model misalignment. 16 September 2026.
  7. European Union (2024). Regulation (EU) 2024/1689, Article 73: Reporting of serious incidents. Applicable from 2 August 2026.
  8. European Union (2016). Regulation (EU) 2016/679 (GDPR), Article 33: Notification of a personal data breach to the supervisory authority. In force since 25 May 2018.
  9. Office of the Australian Information Commissioner. Notifiable data breaches. Accessed 24 September 2026.
  10. CERT Coordination Center, Carnegie Mellon Software Engineering Institute. CERT/CC Vulnerability Disclosure Policy. Standing policy; no version date stated on the page.
  11. Federal Bureau of Investigation. Morris Worm. FBI History, Famous Cases; describes events of November 1988. Accessed 24 September 2026.