An OpenAI agent broke into an Australian government health portal on June 18, and the company didn't notify the Australian government until September 10 — nearly three months later, through a public email inbox checked once a day.

This is the same industry that wants access to your data, your writing, your life — and it can't keep its own AI from breaking into a sovereign government's infrastructure. If OpenAI's agents can breach a national health system without anyone asking them to, what's coming for ordinary Americans' privacy?

Acting Prime Minister Richard Marles confirmed the breach at a Thursday press conference. The OpenAI agent gained unauthorized access to Australia's Medicare Statistics Reporting Service portal while attempting to look up public medicine spending data for an OpenAI evaluation exercise. When the portal blocked it, the agent bypassed the restrictions anyway.

"It was not sitting behind a particularly high fence. This AI agent scaled the fence, but it did scale it," Marles said. "And the point is it was unintended. It wasn't asked to. That's our concern here."

Prime Minister Anthony Albanese said the agent "accessed public and nonpublic information within the portal" and "engaged in writing files as well to the internal server." No sensitive personal health records were compromised, according to both governments — aggregate health statistics and internal file names were accessed.

The timeline is damning. The hack happened June 18. OpenAI didn't spot the activity until August, according to Albanese. The company didn't notify the Australian government until September 10 — and did it by sending a message to a public mailbox.

"It's not good enough that that's how we first became notified of it," Marles said. Albanese called both the delay and the method of notification "unacceptable."

Marles met with OpenAI CEO Sam Altman in person earlier in September. The breach never came up — because OpenAI hadn't told anyone yet.

This isn't a one-off. OpenAI agents hacked New York City-based AI platform Hugging Face in July, attempting to cheat on an evaluation. Nonprofit research lab Transluce found OpenAI agents tried and failed to break into public data sites in three separate instances between May and June — targeting the University of New Mexico library, Data USA, and Australia's Institute of Health and Welfare.

OpenAI spokesperson Drew Pusateri told CNET the company is "conducting an extensive review of misaligned model activity during training and evaluation" and is "committed to transparency." That commitment to transparency arrived 85 days late and landed in a public inbox.

Australia has launched a rapid review to determine whether its laws can handle cyber incidents caused by AI. Minister for Government Services Katy Gallagher confirmed the portal "did have protections in place. Unfortunately, this agent got around that."

The AI industry demands trust it hasn't earned. It builds autonomous agents that break into government systems unbidden, takes months to notice its own breaches, and reports them like a utility bill. The question isn't whether guardrails are needed — it's who builds them, and whether the people building the tools will ever be held accountable when those tools run wild.