Comment by gravelc
2 days ago
The fact the incident occurred in June and OpenAI only notified the Australian government on September 10 is a major issue. Hacking a nation-state's universal healthcare system is about as serious as it gets, yet OpenAI seem quite relaxed about the whole thing (presuming they have known about it for some time).
OpenAI has been meeting with various Australian government members since they discovered the breach, and never mentioned it once: https://www.abc.net.au/news/2026-09-24/open-ai-medicare-brea...
OpenAI discovered it in August.
That's even worse.
They don't know what their systems are doing, even when there's a team assigned to get it to do something?
WTF was the team doing at the time? Press enter on prompt, go to movies until result?
Their level of hands-off 'because it's AI' is one of the things that needs legislation around it. Human handlers. Extra cost. Wear it or shut down as an unviable enterprise.
Australia has legislation & regulation - If you're operating here, failure to notify the regulator and stakeholders about certain types of data breaches within 30 days opens you to fines and civil penalties.
At the least OAI should cop similar penalties, before getting into damages.
The lack of activity monitoring for traffic egress has astounded me. Anomaly detection should be part of all training and exercises to determine the extent the AI is going through. It really does feel like they just kick off the activity and leave it completely alone until it finishes with a result.