OpenAI used AI to draft disclosure after its agent hacked Australian govt sites
To paraphrase the popular idiom, it’s AI leading AI.

OpenAI used AI to draft en email informing Australia of a breach. By Shutterstock.
- OpenAI used AI to help draft an email disclosing its agent’s access to Australian government websites.
- Humans reviewed and sent the final email to Services Australia, according to The Guardian Australia.
- OpenAI found the June 18th intrusion on August 11th and emailed Services Australia on September 10th.
- OpenAI says it has notified more than 100 organizations about unauthorized activity tied to its AI agents.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
After OpenAI realized its AI agent had hacked into Australian government websites, it decided to use AI to help write the email to Canberra, it has been revealed.
OpenAI’s legal and security teams used AI to generate parts of the wording of the email, in which the company disclosed the hack to the Australian government, according to The Guardian Australia.
That included word selection and formatting, although the outlet’s source also said humans reviewed the final draft of the email and were responsible for sending it to the department Services Australia.
This week, one of OpenAI’s executives, Chief Strategy Officer Jason Kwon, told a parliamentary inquiry he didn’t believe OpenAI’s own chatbot had been used to create the email but added: “We’re happy to go and confirm.”
During the hearing, Kwon acknowledged OpenAI could have raised the issue and disclosed the incident, regarded by the Australian government as unacceptable, in a more formal and direct manner.
OpenAI’s response “was not good enough, and we should have informed the impacted parties much sooner,” said Kwon.
OpenAI Australia hack’s timeline:
- The intrusion occurred on June 18th
- OpenAI discovered the breach on August 11th
- OpenAI emailed Services Australia on September 10th.
The email, obtained by The Guardian Australia, consisted of 5 paragraphs. The email read: “We are notifying you of a security vulnerability identified during our review of OpenAI model activity involving Services Australia’s Medicare Statistics service at medicarestatistics.humanservices.gov.au.”
“An OpenAI model identified a way to make the server carry out instructions sent through the public reporting interface, without a private account or password. It was able to access this to read portions of internal program files and settings, obtain a list of files, and create and read back a small test file on the server,” it went on.
An avalanche of incidents
Australian Prime Minister Anthony Albanese previously said the OpenAI agent gained unauthorized access to the medical statistics portal of Medicare, Australia’s universal health insurance programme while conducting research on public medical spending.
Has your password leaked?
Further investigation revealed that OpenAI agents had also accessed the Australian Institute of Health and Welfare, the Victorian Department of Health, and the NSW Bureau of Crime Statistics and Research.
In 2026, OpenAI experienced a series of incidents involving rogue AI agents, beginning with the Hugging Face infrastructure compromise.
In late September, Axios reported that OpenAI and other leading AI firms were actually investigating tens of thousands of security incidents – a lot more than they had publicly disclosed.
OpenAI said it has informed more than 100 organizations about incidents involving unauthorized activity tied to its AI agents. OpenAI is reportedly searching through roughly 50 petabytes of data as it works to understand the situation.