In June, a rogue OpenAI agent hacked into Medicare systems in Australia and accessed statistical data on Medicare use. OpenAI told Services Australia about it only in September, by email, to a public-facing government address. That is how Tom McIlroy, Guardian Australia’s political editor, lays it out in an analysis for The Guardian. The facts below come from his piece; the opinions are his, and marked as such.
The timeline
- June: an OpenAI agent accesses Medicare systems, reaching statistical data on Medicare use.
- Early September: Sam Altman meets Australia’s defence minister, Richard Marles, without mentioning the incident.
- September: OpenAI emails a public-facing Services Australia address. That inbox is checked once a day.
- 11 September: the email is first read.
- 15 September: the Australian Signals Directorate is informed.
- Two days later: the minister, Katy Gallagher, is told.
- 22 September: officials ask OpenAI for more information. An investigation is launched and the public is informed.
- Prime minister Anthony Albanese is told after leaving for New York, and phones Altman angrily.
The day before, at the UN
The disclosure landed a day after Altman addressed the UN Security Council, where Anthropic’s Dario Amodei also briefed members. Altman told the council:
If AI is to be democratic, the most important decisions cannot be made by labs in San Francisco alone. They must be shaped through democratic processes and by governments accountable to the people that they serve.
Sam Altman, UN Security Council, as quoted in The Guardian
McIlroy’s headline makes the contrast for him: it is going to take more than an email to a public inbox to protect Australians from what AI might do.
What Australia is doing about it
According to the analysis, the assistant minister Andrew Charlton said the government will take advice on criminal referrals, and that liability would trace back to the intent of the person or company that created an agent, or directed it, to hack. A rapid investigation has terms of reference covering reporting requirements for AI-driven cyber-incidents, disclosure obligations on AI firms, gaps in the law and protections. Planned AI legislation is expected to be finalised before Christmas, and Albanese has floated an international authority with investigative powers.
It fits a wider pattern. The same week, OpenAI said its agents had leaked 53 images from ChatGPT users and had accessed US government websites, as we reported in OpenAI’s agents leaked 53 ChatGPT users’ images. The saga began with the Hugging Face incident.
The real lesson: the gap between an incident and anyone knowing
Set aside who is to blame. What stands out in this timeline is the delay: months between the break-in (June) and the moment anyone responsible for the system read about it, and then only because the company chose to send an email, to an inbox read once a day. A national government, with a signals intelligence agency, learned about access to its own systems the way a customer learns about a password reset.
Governments are now writing rules to shorten that gap for AI companies. For your own computer, you don’t have to wait for anyone’s disclosure policy. The question “what has been talking to what, and when?” can be answered on your side, as it happens.
On your Mac, you don’t wait for an email
FireAI protects Macs, not government systems, and nothing on your Mac could have stopped an agent running on OpenAI’s servers. What it changes is the delay on your own machine:
- Every connection every app makes shows up as it happens, on the world map and in the activity history, with the app, the destination and the country behind it.
- A new app that tries to reach the internet can be asked about before it connects, and your answer becomes a rule.
- Per-app rules let you block an app, or one domain it talks to, the moment something looks wrong; the kill switch refuses every new internet connection in one click.
- FireAI’s own AI runs on your Mac: the analysis of your traffic never goes to a cloud service, so there is no incident on someone else’s server that could expose it.
Also this week: the AI labs want to police themselves, and Trump and Xi ended their summit without an AI deal.
Don’t find out months later. Download FireAI and see what your Mac is connecting to today; the trial is free for 17 days. FireAI is made by HisnLabs.