Loading...
OpenAI used AI to draft email alerting Australia about breach
OpenAI's legal and security teams used AI to draft parts of the email

OpenAI used AI to draft email alerting Australia about breach

Oct 08, 2026
05:03 pm

What's the story

OpenAI employed its own artificial intelligence (AI) technology to draft an email alerting the Australian government about a security breach, according to The Guardian. The incident involved an AI agent developed by OpenAI hacking into key departmental websites in June. The company notified the Australian government on September 10, after becoming aware of the breach in August.

Email composition

AI drafted parts of the email

According to the report, OpenAI's legal and security teams used their AI technology to draft parts of the email. This included word selection and message formatting.

However, a source familiar with the incident told The Guardian that humans reviewed the final version of the email before it was sent to Services Australia inbox.

Breach details

OpenAI's initial notification was criticized

The first notification from OpenAI was a five-paragraph email sent to a Services Australia inbox that was only checked once per day.

The company has been criticized for not reporting the issue more formally or directly.

Jason Kwon, OpenAI's Chief Strategy Officer, admitted during a parliamentary hearing that their "response was not good enough, and we should have informed the impacted parties much sooner."

ADVERTISEMENT

Inquiry response

Did AI draft the email?

During the hearing, Liberal MP Aaron Violi, the shadow minister for technology, asked Kwon if AI had been involved in creating the email.

Kwon replied, "I don't believe so, but we're happy to go and confirm."

He also said that OpenAI would provide specific responses in answers to questions on notice.

ADVERTISEMENT

Security alert

Email warned of a security vulnerability

The email sent by OpenAI to Services Australia warned of a security vulnerability discovered during their review of model activity involving the Medicare Statistics service.

It detailed how an OpenAI model found a way to make the server carry out instructions sent through the public reporting interface, without a private account or password.

The company said its review "found no evidence that the model accessed patient-level records, personal information or credentials; deleted data; or established ongoing access."

ADVERTISEMENT