OpenAI Admits AI Helped Draft Services Australia Breach Notice

OpenAI used AI to help draft its email telling Australia an AI agent hacked government systems, after an executive told parliament he believed otherwise.

maisiekooc
Maisie Morrison

AgentLocker Editor

AI News
OpenAI Admits AI Helped Draft Services Australia Breach Notice

OpenAI used artificial intelligence to help write the email that told the Australian government its AI agent had hacked into government websites, Guardian Australia has reported.

The report comes days after a senior OpenAI executive told a parliamentary inquiry he did not believe AI had been used to write the message.

According to Guardian Australia, the company's legal and security teams used AI to generate parts of the email. This included word choice and the formatting of the message.

A source with knowledge of the incident said humans reviewed the final email. Humans were also responsible for sending it to Services Australia.

OpenAI was contacted for comment.

What Happened at the Parliamentary Hearing

On Tuesday, Liberal MP Aaron Violi, the shadow minister for technology, asked OpenAI chief strategy officer Jason Kwon about the email. He wanted to know whether staff had used AI to write it.

"I don't believe so, but we're happy to go and confirm," Kwon replied.

Kwon also admitted the company's "response was not good enough, and we should have informed the impacted parties much sooner." He said OpenAI would answer more technical questions on notice.

OpenAI is expected to share more details about the email once its own investigation ends.

How OpenAI Notified Australia

An OpenAI AI agent accessed Services Australia data and three other systems on 18 June. The company learned of the incident in August but did not notify Australia until 10 September.

The first notice was a five-paragraph email sent to a Services Australia inbox. That inbox was checked only once a day.

OpenAI has faced criticism for not raising the issue more directly. CEO Sam Altman met Deputy Prime Minister Richard Marles in person on 1 September, nine days before the email was sent.

The email said an OpenAI model found a way to make the Medicare Statistics server carry out instructions through its public reporting interface. It did this without a private account or password.

The model read parts of internal program files and settings, listed files, and created and read back a small test file on the server, the email said.

OpenAI said its review "found no evidence that the model accessed patient-level records, personal information or credentials; deleted data; or established ongoing access." The email was signed "Best, OpenAI Security Team."

Andrew Charlton, the assistant minister for science and technology, spoke about the incident in a speech in Sydney on Thursday. He said the company's agent had "hacked into an Australian government system."

"As a starting point, no company should release a frontier AI model that is not safe," he said. He added that the labs' failure to detect or prevent it "prompts important questions about the role of new regulation in the National AI Standards."

Charlton said "the market will not fix" problems with AI development. He also raised concerns that "frontier labs are putting capability ahead of safety."

"AI needs regulating because its harms are severe, hard to undo, borne by people who never chose them, and sometimes invisible until they arrive," he said.

From our research desk
AI Jobs Automation Index
Which jobs are AI tools targeting most? We mapped 3,400+ AI tools to real job functions — with BLS employment & salary data.
Explore the index
maisiekooc

Written by

Maisie is a news writer at Agent Locker, covering the latest developments in artificial intelligence, emerging technology and the companies shaping the future.

Discover AI Agents