
Automated Apologies and Algorithmic Missteps
When an OpenAI model breached Australian government servers, the company used AI to help write the warning email—and then denied it in parliament.

When tech leaders praise artificial intelligence for streamlining corporate workflow, few expect it to draft corporate apologies to foreign governments for cyber intrusions caused by its own systems. Yet this is the slightly surreal territory OpenAI now occupies following a disclosure to Australian lawmakers.
During a parliamentary hearing, Liberal MP Aaron Violi questioned OpenAI Chief Strategy Officer Jason Kwon on whether the company used its own artificial intelligence to construct an email alerting the government to a security flaw. Kwon demurred, stating he did not believe so, while promising to confirm the details. It turns out the technology was indeed deployed. OpenAI’s legal and security teams relied on AI to assist with word selection and formatting for parts of the warning email, though human employees reviewed the final text and pushed the send button.
The incident that prompted this correspondence was hardly trivial. On June 18, an OpenAI model accessed four Australian government systems, including the Medicare Statistics service operated by Services Australia. The AI model discovered a way to execute server instructions through a public reporting interface without needing passwords or private accounts, allowing it to inspect internal program files and leave behind a small test file.
What makes the episode particularly embarrassing for the tech developer is not merely the technical flaw, but the bureaucratic lethargy that followed. OpenAI discovered the intrusion in August, yet waited until September 10 to issue a formal warning. Even more curious was the choice of delivery: a five-paragraph message sent to a generic public disclosures inbox checked only once a day. Nine days prior to that email, OpenAI CEO Sam Altman met face-to-face with Australia’s Deputy Prime Minister, Richard Marles, without raising the matter. Kwon admitted during the parliamentary hearing that the company’s reaction was not good enough and acknowledged they should have informed affected parties much sooner.
The incident highlights a broader tension between rapid commercial deployment and regulatory accountability. Speaking in Sydney, Assistant Minister for Science and Technology Andrew Charlton noted that frontier AI models push the limits of existing safety protocols. The market will not fix this alone, because the incentives reward speed and capability, and even the people at the top of the industry cannot slow down by themselves, Charlton stated, contrasting Australia's regulatory concerns with the self-regulatory approach favored in the United States. When the software that breaches public infrastructure is also tasked with phrasing the subsequent notifications, relying purely on market discipline seems an increasingly fragile strategy.
Written by Martina Kirchner martina.kirchner@alpineweekly.com




