{"slug": "openai-used-ai-to-write-email-warning-australian-government-ai-had-hacked", "title": "OpenAI used AI to write email warning Australian government AI had hacked", "summary": "OpenAI used AI to help draft parts of the 10 September email notifying the Australian government that its AI agent had accessed Services Australia data and three other systems, Guardian Australia reported, contradicting chief strategy officer Jason Kwon's testimony at a parliamentary hearing on Tuesday that he did not believe AI was used. The agent's 18 June intrusion into the Medicare Statistics service at medicarestatistics.humanservices.gov.au was known to OpenAI in August, but the company emailed the publicdisclosures@servicesaustralia.gov.au inbox — checked once per day — nine days after CEO Sam Altman met deputy prime minister Richard Marles on 1 September; Kwon told the inquiry OpenAI's \"response was not good enough, and we should have informed the impacted parties much sooner.", "body_md": "OpenAI used AI to help write the email to the Australian government advising that its AI agent had hacked into key departmental websites, Guardian Australia can reveal.\n\nOn Tuesday, one of the company’s executives [told a parliamentary inquiry that he didn’t believe](https://www.theguardian.com/technology/2026/oct/06/openai-delivers-a-mea-culpa-to-the-australian-government-in-person-but-answers-still-elude) that its own technology had been used to create the email, but said the company needed to confirm this.\n\nGuardian Australia understands AI was used by OpenAI’s legal and security teams to generate [parts of the wording of the email](https://www.theguardian.com/technology/2026/sep/29/openai-apology-rogue-agent-hacked-medicare-australian-government-websites), including word selection and formatting of the message. But a source with knowledge of the incident said humans reviewed the final email, and humans were responsible for actually sending the communication to the Services Australia inbox.\n\nOpenAI was contacted for comment.\n\nAn artificial intelligence agent developed by OpenAI [accessed Services Australia data and three other](https://www.theguardian.com/australia-news/2026/sep/24/anthony-albanese-says-openai-agent-hacked-medicare-extreme-concern-sam-altman) systems in June. The company notified Australia on 10 September despite becoming aware of the incident in August.\n\nThe company’s first notification to Australia came in a five-paragraph email to a Services Australia inbox, publicdisclosures@servicesaustralia.gov.au, which was only checked once per day.\n\nOpenAI has come under fire for not raising the issue in a more formal or direct way, including during a face-to-face meeting between the company’s CEO, Sam Altman, and Australia’s deputy prime minister, Richard Marles, on 1 September, nine days before the company emailed Services Australia but nearly a month after it first learned of the 18 June intrusion.\n\nJason Kwon, OpenAI’s chief strategy officer, admitted in a parliamentary hearing on Tuesday that the company’s “response was not good enough, and we should have informed the impacted parties much sooner”.\n\nDuring the hearing, Liberal MP Aaron Violi – the shadow minister for technology – had asked Kwon specifically about the email and whether AI had been involved in its creation.\n\n“I appreciate that, to get the data and have a review, you’ve got to use AI agents, and obviously your business uses AI. When you notified Services Australia via email, did your staff use AI to construct that email?” Violi asked.\n\nKwon responded: “I don’t believe so, but we’re happy to go and confirm.”\n\nKwon indicated during the hearing that OpenAI would provide specific responses to more technical queries in answers to questions on notice.OpenAI is expected to provide more information about the email once its own investigation has concluded.\n\nThe email, obtained by Guardian Australia in September, advised Services Australia: “We are notifying you of a security vulnerability identified during our review of OpenAI model activity involving Services Australia’s Medicare Statistics service at medicarestatistics.humanservices.gov.au.\n\n“An OpenAI model identified a way to make the server carry out instructions sent through the public reporting interface, without a private account or password. It was able to access this to read portions of internal program files and settings, obtain a list of files, and create and read back a small test file on the server.”\n\nThe email advised that OpenAI’s review “found no evidence that the model accessed patient-level records, personal information or credentials; deleted data; or established ongoing access”, and sent information about the “affected URL” and “affected report”.\n\n“We recommend that the team responsible for the service investigate the vulnerability and assess the changes needed to prevent it. We would be glad to brief your security team and provide supporting evidence as available.\n\n“Best, OpenAI Security Team.”\n\nAndrew Charlton, the assistant minister for science and technology, spoke about the OpenAI incident in a speech in Sydney on Thursday, describing the company’s agent as having “hacked into an Australian government system”.\n\n“As a starting point, no company should release a frontier AI model that is not safe,” he said.\n\n“Yet the fact that has occurred, and the fact that the labs did not detect or prevent it, prompts important questions about the role of new regulation in the National AI Standards.”\n\nCharlton said frontier AI “pushes the limits” of existing government conventions and protocols around assessing safety risks, and went beyond “conventional” approaches.\n\nThe assistant minister said “the market will not fix” issues with AI development, a contrast to the United States’ approach of letting companies operate with a degree of self-regulation. Charlton raised concerns that “frontier labs are putting capability ahead of safety”, positing that Australia can have the most impact on the development of AI by hosting and influencing frontier labs.\n\n“AI needs regulating because its harms are severe, hard to undo, borne by people who never chose them, and sometimes invisible until they arrive,” he said.\n\n“The market will not fix this alone, because the incentives reward speed and capability, and even the people at the top of the industry cannot slow down by themselves.”\n\n**Do you know more? Email josh.butler@theguardian.com**", "url": "https://wpnews.pro/news/openai-used-ai-to-write-email-warning-australian-government-ai-had-hacked", "canonical_source": "https://www.theguardian.com/australia-news/2026/oct/08/openai-used-ai-to-help-write-email-warning-australian-government-ai-had-hacked-its-websites", "published_at": "2026-10-09 04:07:09+00:00", "updated_at": "2026-10-09 04:47:37.356910+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-agents", "ai-safety", "ai-policy"], "entities": ["OpenAI", "Services Australia", "Jason Kwon", "Sam Altman", "Richard Marles", "Aaron Violi", "Guardian Australia", "Medicare Statistics"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/openai-used-ai-to-write-email-warning-australian-government-ai-had-hacked", "markdown": "https://wpnews.pro/news/openai-used-ai-to-write-email-warning-australian-government-ai-had-hacked.md", "text": "https://wpnews.pro/news/openai-used-ai-to-write-email-warning-australian-government-ai-had-hacked.txt", "jsonld": "https://wpnews.pro/news/openai-used-ai-to-write-email-warning-australian-government-ai-had-hacked.jsonld"}}