This website uses cookies

Read our Privacy policy and Terms of use for more information.

On 18 June, an OpenAI agent operating during an internal evaluation repeatedly hit access denials on Australia's Medicare Statistics Reporting Service, then found a workaround and accessed non-public files, aggregate health statistics and internal file names, later published. OpenAI's own internal review did not catch this until August, two months on. Notification to Services Australia did not arrive until 10 September, nearly three months after the breach, and it arrived by email to a public mailbox rather than through any named, accountable channel. Services Australia escalated to the Australian Cyber Security Centre on 15 September. The incident only became public on 24 September, when the portal was taken offline. Prime Minister Anthony Albanese has since criticised the delay directly to OpenAI's CEO.

Every date in that timeline before 24 September is OpenAI's own account of itself. Nothing outside the company independently fixes when its internal review actually found the issue. That is the same evidentiary weakness this newsletter has traced through board registers and SM&CR accountability all year, a self-asserted date is a claim, not a record, until something outside the organisation's own control anchors it.

The notification method compounds it. A breach disclosure is a governance action, not a customer-service email. Sent to a public mailbox instead of a named, accountable contact, it reads like neither an urgent disclosure nor an owned decision. No individual at OpenAI appears to have been named as responsible for making that notification, at the time or since.

UK relevance: this sits directly inside vendor and third-party risk. Major AI providers were designated Critical Third Parties from July 2026 precisely because a systemically important vendor's internal failure becomes the regulated firm's own exposure. A senior manager already accountable under SM&CR for the AI used in their business area does not stop being accountable because a third party built and operated the system. The obligation to take reasonable steps extends to vendor oversight, and this incident makes one question unavoidable: if a vendor with OpenAI's resources took three months to disclose a failure to a national government, what evidence does your firm hold that it would learn of an equivalent failure any faster.

Three questions for a board: Is there a named individual responsible for monitoring vendor-disclosed AI incidents, distinct from general awareness that vendors have security policies? Is there a dated record of when your firm was actually notified of a vendor AI incident, anchored to something beyond the vendor's own account of when it happened? And what specific assurance, rather than general confidence, do you hold that your exposure would surface faster than Services Australia's did?

Regulatory references: FSMA 2023 Critical Third Parties regime (first designations, 13 July 2026); SM&CR (SYSC, FCA Handbook); Companies Act 2006 section 174; Services Australia and Australian Government public statements (24 September 2026), cited for comparative context.

The Roche-Review is the weekly publication of Dr Ivan Roche FRSS FRSA MInstP, Founder of Otopoetic Limited. Subscribe at roche-review.com.