OpenAI Chief Strategy Officer Jason Kwon apologized to members of Australian Parliament for the Medicare portal breach and detailed new internal measures to address rogue AI agents.
Lexie White
Staff Writer
IAPP
OpenAI strengthened its security protocols as it looks to restore the confidence of Australian officials and consumers following the recent breach of Service Australia's Medicare portal by one of the company's rogue agents. The changes were outlined by OpenAI Chief Strategy Officer Jason Kwon during an appearance with Anthropic before Australian Parliament's Joint Select Committee on Artificial Intelligence 6 Oct.
"We are sorry and we know we have work to do to rebuild trust with the Australian people," Kwon told lawmakers.
The appearance came after OpenAI and Anthropic declined to send executives to an Australian Senate hearing 1 Oct. because of short notice. That hearing was eventually canceled.
Australian Prime Minister Anthony Albanese previously announced an investigation into the incident, noting that while the breach occurred 18 June, the Medicare Statistics Reporting Service was only informed of the incident via email 10 Sept.
Responding specifically to lawmaker questions on the chosen means for incident notification, Kwon said, "on retrospect," it would have been more appropriate to report the incident directly to government officials.
"I think people were thinking about this as a technical situation, and they wanted to contact the technical counterparties," Kwon said, adding the internal communication about the breach "could have been much better."
In the aftermath of the breach, Kwon said OpenAI has made changes to make data security incident reporting immediate while implementing an "immediate intervention" system if it finds its AI agents are capable of unauthorized actions.
Anthropic Special Envoy Jeffrey Bleich also appeared before the joint committee to highlight business challenges posed by Australia's applicable AI rules. He pushed back at the AI committee's concern over Anthropic's AI training and copyright practices, stating it would be "technically impossible" to obtain copyright agreements for all content used to train AI models.
Lawmakers questioned if AI companies are receiving meaningful consent when implementing mechanisms requiring users to opt-out of data sharing for training purposes. In response, Bleich highlighted how Australia's regulations make it difficult for companies to develop AI models for the region.
"We've just shared information about how the training works, and then discussed what its implications would be with respect to our capacity to operate here," Bleich said.
The dialogue highlighted the ongoing work being done by lawmakers and AI developers to find common ground on ensuring sufficient safeguards and oversight. Kwon told the committee OpenAI seeks to increase its regulatory collaborations, noting ongoing advancements show AI is "powerful" and "(OpenAI wants) to ensure that lawmakers and policymakers and democratic societies have a say in how this technology develops."
During a recent IAPP LinkedIn Live, Australian Privacy Commissioner Carly Kind said while many AI companies are urging increased regulations, those calls raise concern that companies "don't know the extent to which they are regulated already.”
"There's been a bit of a disregard of those existing frameworks and their relevance to some of these frontier issues,” she said. "Even though cybersecurity frameworks are absolutely right front and center relevant to what is happening at frontier firms, and yet I do think that not only the lexicon but the reality of how they apply has been potentially largely ignored."
Kind joined the IAPP LinkedIn Live to provide insights into the Office of the Australian Information Commissioner's recently released guidance for transparency requirements around automated decision-making technologies that will take effect 10 Dec.
The guidelines detail additional obligations outlined within the Privacy and Other Legislation Amendment Act under the Australian Privacy Principle 1. They apply to entities that use computer programs to make significant decisions that could impact consumers.
Under the APPs, automated systems, including software, applications and AI tools, must remain transparent about how consumer data is processed for decision-making purposes. Organizations must also ensure automated systems are not making potentially biased or harmful decisions about consumers.
Kind noted the obligations only apply to programs that are a “key factor in facilitating the human's decision-making, so that means it's substantially related to the decision, and has a direct connection with making the decision in order to be in scope."
She highlighted how the new transparency requirements will be particularly important with informing users about AI training data use and more targeted AI and ADMT deployments, including those associated with dynamic pricing schemes.
"I think if we go back to the first principles about what privacy and data protection law is about, it's about providing people with choice and control and empowering them," Kind said. "And I think this transparency obligation will absolutely do that."
The requirements are likely to impact the number of complaints the OAIC receives. The authority continues to see a rise in complaints after a 60% increase from 2024-25 to 2025-26.
However, Kind said increased accountability and transparency could strengthen trust between consumers and organizations.
"It is a double-edged sword in many ways, and I don't want to be naive about that," Kind said. "But I think we have to move through this period of disillusionment with online services to something that is based more on trustworthiness and a stronger balance of accountability and transparency, and hopefully things like this can be the first step in that direction."
Kind will be a keynote speaker for the IAPP ANZ Summit 2026.
This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.
Lexie White
Staff Writer
IAPP
Tags:
24 Sept. 2026
14 Sept. 2026
12 Sept. 2024
6 Oct. 2026
The IAPP is a policy neutral, not-for-profit association founded in 2000 with a mission to define, promote and improve the professions of privacy, AI governance and digital responsibility globally.
Certification
Training
Membership
Conferences and Events
Community
News and resources
Certification
Training
Membership
Conferences and Events
Community
News and resources
North America headquarters
Portsmouth, NH, US
EMEA headquarters
Brussels, Belgium
ANZ office
Sydney, Australia
© 2026 IAPP. All rights reserved.