Sam Altman Asked the UN for "Speedy Incident Reporting.” Australia Would Like a Word.

OpenAI's agent broke into Australian Medicare in June. Canberra got an email in September. Now OpenAI wants to help write the rules for reporting incidents.

Yvette
Yvette CEO
September 24, 2026 5 min read
Sam Altman Asked the UN for "Speedy Incident Reporting.” Australia Would Like a Word.

On Wednesday September 23, 2026, Sam Altman told the UN Security Council the world needs "accurate and speedy incident reporting ... so the world can learn from failures."

Later that day, Australia's prime minister told the world about one of OpenAI's failures. His government had learned about it from a public inbox.

On June 18, an OpenAI agent went looking for statistics on Australian medicine spending. The Medicare statistics portal blocked it. The agent kept going. In Anthony Albanese's words, it "found a way around those blocks, didn't accept 'no' for an answer." It read public and non-public files and wrote files to the internal server.

OpenAI knew by August 11. It emailed on September 10, to publicdisclosures@servicesaustralia.gov.au, which is the email alias used by academics to flag website bugs.

From breach to public announcement: 98 days.

Altman asked the UN for "speedy incident reporting." His company took 30 days to send Australia one email.

Sam wants standards.

Sam does not want accountability.

Altman handed us the yardstick. Use it.

"The most important decisions cannot be made by labs in San Francisco alone," he said. On September 1, he met Deputy Prime Minister Richard Marles in San Francisco. Marles says the breach wasn't disclosed.

Altman also called for "secure channels among governments, critical infrastructure operators, and technical experts to share emerging vulnerabilities." Services Australia got a message in a general mailbox.

He fears AI moving so fast that "people can no longer follow what's happening or intervene when needed." Well, OpenAI knew for 30 days and Australia couldn’t intervene, because the company that tossed its salad didn’t disclose it.

OpenAI's own rulebook sets the pace it skipped. Its August 26 Hugging Face report expects responders to pause if they can't clear a severe alert "within 30 minutes of being paged."

The laws are missing it too

California's SB 53 gives frontier developers 15 days from discovery to report a "critical safety incident." My read, and again I’m not a lawyer although I’ve played one on TV is this: The Medicare hack would have never tripped it because the 4 notification triggers require death, bodily injury, catastrophic harm, or deception outside an evaluation. OpenAI says this happened during an internal evaluation.

Albanese promises "legal consequences," which may prove hard. UTS professor Nicholas Davis told ABC that Australia's computer-access laws "require intent," and so does holding a corporation to account. Without a smoking gun, intent is hard to prove.

Who finds it first

Hugging Face went public on July 16; OpenAI's own alert fired July 19.

Transluce, a nonprofit reading public logs, surfaced the agents' attempts on Australia's Institute of Health and Welfare, plus failed runs at a University of New Mexico library and Data USA.

Australian Medicare is the case where OpenAI found its own breach first, and didn’t tell the victim. The only party holding the facts was the party that caused the harm. As reported by Wire, Canberra ran slow too; Services Australia took 5 days to escalate, and an inquiry will ask why. One can only conclude that an email from a company like OpenAI via an open general inbox would be met with considerable suspicion.

The world learned from this failure because Australia's PM spoke up.

The world learned from this failure because Australia's PM spoke up. OpenAI remains, curiously, silent

The rulebook comes from the same hands

As reported by The Information, they obtained the plan. Google, OpenAI and Anthropic are building a self-regulatory body, tentatively the Standards Authority for Frontier AI, "on their own, without government oversight." Its jobs would include "laying out how AI developers should report safety and security incidents" and setting "qualifications for independent auditors of the models and labs."

Now, let’s bump that up against what happened with Australia. The company that took 30 days to email a government it hacked would help write the rules for reporting incidents.

Huh? Wait a minute, what?

Oh, but it gets better.

The labs would certify who is qualified to audit the labs. The shortlist of scientific advisers reportedly/allegedly includes METR founder Beth Barnes. Remember, OpenAI brought METR in to help investigate its Hugging Face incident. Others shortlisted report they were never approached.

At the UN, Altman said the most important decisions "must be shaped through democratic processes, by governments accountable to the people that they serve."

Ok Sam, if that’s the case, why is SAFA being designed behind closed doors?

Authorship, measurement and the clock each require an owner that is not the vendor. SAFA would place the reporting rules and the auditor qualifications under the same damn roof of the parties being graded. In my earlier post, "The Emergency Has a Vendor," the first offender hosted the call for collective defense; here, the late reporter is helping write the reporting rules. So, Sam, when you say OpenAI remains "committed to transparency," that lands more on word salad than honest because commitment carries a date and the one with Australia arrived 30 days late, addressed to a public mailbox. So, no Sam.

The Stopwatch Test

6 checks to run before any agent touches your systems.

  1. Put the clock in the contract. Require written notice within hours whenever a vendor's models touch your systems without authorization. GDPR asks data controllers to notify regulators within 72 hours where feasible. Treat that as your floor.
  2. Hold vendors to their own speeches. Altman asked the UN for "secure channels" to share vulnerabilities. Write a monitored security contact into every AI contract; notices sent elsewhere count as undelivered.
  3. Define the incident by what happened to YOU. Unauthorized access counts, whatever the injury, intent, or "evaluation" label. Breach, harm, production systems injected with malicious payload. They don’t get to define your harm – it happened to you; intentionally or unintentionally.
  4. Demand the first-signal date. Ask when the vendor first saw warning signs and who outside found the problem first. OpenAI's team saw warning signs "as early as late May," yet Hugging Face heard from OpenAI only after announcing its own breach.
  5. Watch your own front door. Log automated traffic that retries after a block; the agents chasing Australian health data tried proxies, screenshot services and guessed file names.
  6. Check who certifies your auditor. SAFA would set qualifications for auditors of the labs. Pick assurance that answers to you and treat lab-set thresholds as marketing until an outsider enforces them.

Speedy incident reporting stays a soundbite and speech fodder until it becomes a clause in your contract.

So, write the clause.

We can be your auditor. We can be your vendor. We cannot be both.

Related Articles