OpenAI "fell short" in its responses to internal AI agents accessing non-public data in Australian government websites, the company behind ChatGPT told a parliamentary inquiry on Tuesday.
The American AI giant has confirmed its AI agents recently accessed data within at least five federal and state government websites – some of which was non-public, including a Medicare data portal it breached in June.
The Australian government was not informed of that incident until OpenAI notified Medicare's operator Services Australia by email in September.
Labor MP Jo Briskey, who chairs the joint select committee on AI, described that incident as "utterly unacceptable" during an inquiry hearing in Sydney.
OpenAI's chief strategy officer Jason Kwon, who travelled from the US to front the inquiry, said while the Services Australia breach was “not super-sophisticated", the company's response "was not good enough" and it "should have informed the impacted parties much sooner".
"The reasoning for why that did not happen is we wanted to understand more of the facts before we spoke to the impacted parties," he said.
"But because of the novelty of this situation, I think we have learned our lesson that it is better to inform even with partial information, to let parties know that something has occurred.
"And to also make sure that we're going through all the right channels, so that multiple members and aspects of government are informed of what's happening in the situation."
Kwon also agreed with a suggestion that the Services Australia breach "might not have been discovered" if OpenAI had not emailed the agency to notify its cybersecurity staff.
The Australian government is considering implementing a mandatory reporting regime for AI-related cybersecurity incidents, which OpenAI told the committee it would welcome.
Aside from the incidents already publicly known, Kwon said OpenAI had not discovered any further cybersecurity events involving Australian websites and its AI agents, "but if we find more we will obviously adjust our approach".
OpenAI has informed more than 100 organisations worldwide of cybersecurity incidents involving agent 'misalignment' – a term used to describe AI systems which take actions their human users did not intend.
The company said last week that it is spending more than $US500,000 ($717,000) a day as its AI models help it review around 50 petabytes (about 50,000 terabytes) of data on potential misalignment incidents, using around 7,000 dedicated GPUs.

OpenAI's chief strategy officer, Jason Kwon, answers questions before the joint select committee on AI. Image: Parliament of Australia / YouTube
Kwon said the percentage of the company's total computing power now used to improve model alignment has “substantially increased” into a "low double-digit percentage".
He also suggested Australian organisations should "increase the level of investment or activity around website safeguards" to better protect against AI agents – including those operated by bad actors.
"[AI agents] can be used in an accidental way, which is what happened here, to do things that were not intended," he said.
"It could also be done intentionally – which we're not going to do – but, you know, others might if they have different intentions."
The federal government is reviewing OpenAI's Medicare portal breach and undertaking a review of government IT and cybersecurity systems, while also considering whether the hack breached Australian laws.
OpenAI has faced calls for legal repercussions over its recent Australian incidents, and publicly apologised to Australians in a blog post last week.
Anthropic has 'not found any [Australian] cases' like OpenAI's
Anthropic, a major competitor to OpenAI which has also seen misaligned AI agents hack other organisations' websites, told the inquiry it was not aware of any incidents involving Australian government websites.
The company's head of safeguards, Dave Orr, told Tuesday's hearing, "We have not found any cases where it interacted with Australian government systems in some sort of unauthorised way.
"We haven't found anything like this, and we have looked.”
Anthropic's international special envoy, Jeffrey Bleich, said recent AI agent incidents have reinforced that some AI-related risks "are no longer theoretical".
"As increasingly capable AI systems interact with sensitive information and with consequential decisions, the safeguards that we have around frontier AI need to advance alongside the technology itself," he said.
Orr said Anthropic would also welcome a mandatory reporting regime for AI-related incidents, and said the company would already notify Australian authorities "within a matter of days, or sooner" if the firm detected any misaligned AI activity.

Anthropic's Dave Orr (left) and Jeffrey Bleich (right) speak via video link to the joint select committee on AI. Image: Parliament of Australia / YouTube
Training and copyright
Both OpenAI and Anthropic said in written submissions to the committee that changes to Australia's copyright laws would be needed to encourage local investment in data centres and the domestic training of AI models.
Australian rights holder organisations have denied this is needed, and say the country's existing laws are enough and should be enforced, with AI companies made to pay for their use of all copyrighted material – not just some.
Several rights holder organisations have also accused AI companies of already using Australian material to train their models overseas without consent.
Labor is developing national AI standards which are expected to apply to both AI companies and data centre operators, and is considering allowing AI companies to use copyrighted Australian material for training.
Key cybersecurity departments and agencies have also called for Australia to allow frontier AI firms, such as Anthropic and OpenAI, to train their models locally so the government can gain "access and influence" over leading AI systems and protect national security.
The joint select committee on AI is holding four days of hearings in Sydney and Melbourne this week, and is also expected to hear from academics, unions, creatives, AI safety organisations, banks, and data centre operators.