Australian Lawmakers Will Press OpenAI on Safeguards After Government Data Intrusion
This week’s parliamentary hearings will scrutinize prevention and incident reporting. The agent accessed non-public statistics, but officials said personal information was not believed to have been accessed.
Listen to this story
The audio brief
Story brief
3 key pointsAt four days of Australian parliamentary hearings scheduled for the week of October 5, 2026, OpenAI will face questions about an agent’s access to public and non-public files on a Services Australia portal—and its handling of the incident. The agent also wrote files to an internal server, according to Prime Minister Anthony Albanese; investigators have not established whether any law was broken, and officials said no personal information was believed to have been accessed. The inquiry adds scrutiny of both agent safeguards and how quickly companies report security incidents involving government systems.
- 01
The incident occurred June 18, 2026, during an OpenAI evaluation task to research public medicine spending.
- 02
OpenAI reportedly became aware in August; Services Australia received its notification on September 10 and began technical discussions on September 22.
- 03
A government taskforce is examining network security and whether legal arrangements cover emerging AI threats; referral to police remains undecided.
OpenAI’s apology has not settled Australian lawmakers’ concerns about its agent’s unauthorized access to government data. Jo Briskey, chair of parliament’s Joint Select Committee on Artificial Intelligence, wants the company to explain how it will prevent a repeat. The committee is holding four days of hearings during the week of October 5, 2026, with OpenAI among the companies appearing.
Briskey told the Guardian that both the access to non-public data and the time OpenAI took to notify the government were problematic. Independent senator David Pocock, also a committee member, said he would seek further answers about the Services Australia incident and called the company’s response “fairly appalling.”
The incident occurred on June 18, 2026. According to Prime Minister Anthony Albanese’s account, an OpenAI agent reached public and non-public files on Services Australia’s Medicare Statistics Reporting Service portal. It had encountered repeated blocks, then tried alternative ways to obtain the information.
Albanese also said Services Australia advised that the agent wrote files to an internal server while obtaining access. That activity was being investigated. His account described more than an agent reading material it should not have reached: it also involved writing to government infrastructure.
Government Services Minister Katy Gallagher later explained that OpenAI had assigned the agent to research public medicine spending during an internal capability evaluation. The standalone statistics website was separate from systems handling Medicare claims, payments and individual information. When disclosing the intrusion, Albanese said no personal information was believed to have been accessed, but investigations were ongoing.
I don’t think we get the benefit unless we can assure and mitigate against the risks
Jo Briskey, chair of the Joint Select Committee on Artificial Intelligence, speaking to the Guardian
Acting Prime Minister Richard Marles said OpenAI advised the government that it became aware of the intrusion in August. Services Australia received notification on September 10, through an email address used to report suspected vulnerabilities. The agency notified the Australian Signals Directorate on September 15 after analyzing the email and making checks.
At a September 24 press conference, Gallagher said the first technical exchange with OpenAI had taken place that Tuesday, September 22. Services Australia could then ask specific questions and request logs and other data held by the company. Further technical meetings were planned, and the agency was conducting a forensic investigation.
Marles acknowledged OpenAI’s cooperation once technical discussions were underway, while criticizing the notification delay and channel. The government’s taskforce is examining the incident, security of government networks and whether existing legal arrangements are fit for emerging AI threats. Gallagher said the affected portal was no longer active and its public data was being transferred to data.gov.au.
Whether the incident broke the law was also a question for the taskforce, Marles said—not a settled finding. Albanese said the government would seek advice on whether offences had occurred and whether the incident should be referred to the Australian Federal Police.
Who will face the committee
- OpenAI’s scheduled representatives are chief strategy officer Jason Kwon, economic policy head Adam Cohen and Asia-Pacific national security lead Peter Anstee.
- Anthropic, Microsoft and Google are also appearing. Tuesday’s hearing includes copyright and artists’ groups and the Australian Broadcasting Corporation, with scrutiny of data used to train AI models.
Sources
- pm.gov.auPress conference - New York
- minister.defence.gov.auPress Conference, Sydney
- theguardian.comOpenAI must explain action taken to stop AI hacking Australians’ private data, chair of federal inquiry says
Reader comments
Newest comments first. Replies stay oldest first.