OpenAI Executive Admits Australia Hack Response ‘Not Good Enough’

OpenAI's Jason Kwon told a parliamentary inquiry that the company's handling of the recent data breach was inadequate and pledged further measures to restore public confidence.

SYDNEY — OpenAI has acknowledged that its initial response to a significant data breach affecting the Australian government was insufficient, with a senior executive stating that the company’s handling of the incident was “not good enough.”

Jason Kwon, an executive at the San Francisco-based artificial intelligence firm, made the admission during testimony before a joint parliamentary committee in Canberra. The inquiry, convened to examine the security implications of advanced AI systems deployed in critical national infrastructure, focused heavily on the timeline of the breach and the subsequent communication failures between OpenAI and Australian authorities.

Kwon told the committee that while the technical containment of the vulnerability was achieved, the transparency and speed of the disclosure to affected agencies fell short of the standard expected of a partner in national security. He stated that the company recognized the severity of the trust deficit and that internal reviews had identified gaps in their incident response protocols.

The breach, which occurred in the preceding months, exposed sensitive data related to government operations. Australian federal officials had previously raised concerns about the opacity of OpenAI’s reporting mechanisms, noting that key details regarding the scope of the compromise were delayed. The parliamentary inquiry has since released preliminary findings indicating that the delay in notification hindered the government’s ability to implement immediate protective measures for other connected systems.

In his testimony, Kwon emphasized that OpenAI is implementing a new framework for security disclosures, which includes mandatory real-time alerts to government partners in the event of a critical vulnerability. He noted that the company is working with Australian cybersecurity agencies to align its protocols with local regulatory requirements and international best practices.

The admission marks a significant shift in the company’s public stance, which had previously maintained that the incident was a localized technical error that had been swiftly resolved. Critics, including several members of the parliamentary committee, argued that the initial minimization of the breach’s impact had undermined the government’s ability to assess the broader risks associated with integrating third-party AI models into state functions.

Experts in cybersecurity and data governance have pointed to the incident as a case study in the challenges of regulating proprietary AI systems. They note that the lack of standardized disclosure requirements for AI vendors has created a regulatory vacuum, leaving governments to rely on voluntary cooperation from private sector entities. The Australian government has indicated that it is considering legislative amendments to mandate stricter reporting obligations for critical infrastructure providers, including AI developers.

OpenAI has not disclosed the specific nature of the data compromised in the breach, citing ongoing legal and security reviews. However, the company has confirmed that no evidence of malicious exploitation of the vulnerability by external actors has been found to date. The parliamentary committee is expected to release its final report in the coming weeks, which will include recommendations for reforming the oversight of AI technologies in the public sector.

The incident has also drawn attention to the broader geopolitical implications of AI dependency. As nations increasingly rely on foreign-developed AI systems for administrative and strategic tasks, the security vulnerabilities of these systems have become a matter of national interest. The Australian inquiry is part of a wider global trend, with similar investigations underway in the United States, the European Union, and the United Kingdom.

Kwon concluded his testimony by reiterating OpenAI’s commitment to transparency and collaboration with government partners. He stated that the company is investing in additional security resources and is developing new tools to help clients monitor and manage AI risks. The executive acknowledged that rebuilding trust would require sustained effort and consistent adherence to the new disclosure protocols.

The parliamentary committee has invited further submissions from other AI providers operating in Australia, seeking to establish a comprehensive understanding of the sector’s security practices. The inquiry’s findings are expected to influence future policy discussions on AI regulation, both in Australia and internationally.

Sources & article transparencyAttribution, AI assistance and corrections

Sources and attribution

Source links and attributions appear within the report. Primary records and reporting from other news organisations are identified according to their role in the story.

AI assistance

AI tools assisted with synthesis or production. The newsroom remains responsible for source selection, review, attribution and publication.

Read our AI policy →

Corrections

Found an inaccuracy or a broken citation? Send it to the newsroom standards desk.

Advertisement