OpenAI utilized artificial intelligence to assist in drafting an email notifying the Australian government that one of its AI agents had accessed several government websites, according to information revealed on Tuesday. The company’s executive appeared before a parliamentary inquiry to address the incident, which involved unauthorized access to Services Australia systems and three other government platforms in June.
Despite initial statements by an OpenAI executive expressing uncertainty over whether the company’s own technology was used to compose the notification email, sources familiar with the matter confirmed that AI tools supported OpenAI’s legal and security teams in generating portions of the message. These AI-assisted contributions included word choice and formatting, while humans reviewed and ultimately sent the email.
OpenAI first became aware of the breach in August but did not formally notify Australian authorities until September 10. The notification came in the form of a brief email sent to a Services Australia inbox that was only monitored once daily. This approach drew criticism due to the delayed and limited nature of the communication, especially given that OpenAI’s CEO Sam Altman met with Australia’s Deputy Prime Minister Richard Marles on September 1—nine days before the email notification and nearly a month after the June 18 intrusion was identified.
During Tuesday’s parliamentary hearing, Jason Kwon, OpenAI’s chief strategy officer, acknowledged shortcomings in the company’s handling of the situation. He stated that the response “was not good enough,” emphasizing that those impacted should have been informed much earlier.
The incident raises questions about security practices related to AI systems and highlights the challenges governments face in receiving timely and transparent disclosures about breaches involving emerging technologies. OpenAI has been contacted for further comment on the matter.
