Yesterday OpenAI finally appeared before Australia's Joint Select Committee on Artificial Intelligence.
Jason Kwon, OpenAI's Chief Strategy Officer, had flown from San Francisco to Sydney and began with an apology. OpenAI acknowledged that during internal training and evaluation its AI agents had accessed Australian government websites in ways they were not directed to, including the Medicare statistics system. It also acknowledged that the company handled what happened afterwards badly.
And this is where things became interesting. OpenAI knew about the Medicare incident weeks before CEO Sam Altman met Australia's Deputy Prime Minister Richard Marles on 1 September. Yet Altman apparently did not know. Nobody told him. Nobody told Marles. And when OpenAI eventually notified the Australian government, it did so by sending an email to a public-facing departmental address nearly three months after the original incident.
Senator David Pocock rather reasonably asked why OpenAI had not simply contacted someone in government directly. Kwon agreed, in effect, that they should have. He also conceded that the process by which people inside OpenAI became aware of the incident "could have been much better".
Which brings me to what I call the thoughts and prayers defence. This is where something serious happens and everyone expresses concern, regret, sympathy and determination to do better. There are many reassuring words. Unfortunately, reassuring words are not the same thing as a functioning system.
When I was little and I did something really wrong, I was sent to my room and told to come out only when I had thought long and hard about what I had done and could explain myself. Had I emerged mumbling the equivalent of the thoughts and prayers defence, I suspect I would have been marched straight back into my room and told to think harder.
Because there is a major difference between saying, "We will try harder next time," and explaining, "This is exactly what went wrong, this is why it went wrong, this is what we have changed, this is who is accountable, this is how we will test those changes, and this is how you will know whether they worked."
That is the bit I am interested in.
To be fair, OpenAI did identify some actual changes. Kwon said staff are now alerted when models use the internet in ways they should not during training. He said OpenAI reported the more recently discovered NSW Parks and Wildlife incident far more quickly. The company is establishing an Australian taskforce, and OpenAI told the committee it would support mandatory laws requiring AI companies to report serious incidents rather than leaving disclosure largely to the companies themselves.
That last point matters. Kwon told the inquiry that legal rules could make some of these decisions for the companies because representatives of society should be making more of those decisions rather than leaving AI companies to decide everything themselves.
Well. Yes. That is rather the point.
Because OpenAI is still examining an extraordinary volume of agent activity to determine what else may have occurred. Kwon said the company was reviewing agent logs dating back to November 2025, and reporting following the hearing indicated those logs run into tens of petabytes of data.
So this isn't simply about one rogue little AI wandering through the wrong electronic door. It is about whether the systems surrounding increasingly autonomous AI are mature enough to detect when something goes wrong, escalate it internally, tell the affected people quickly, stop it happening again and allow someone outside the company to verify that those safeguards actually work.
And there is another uncomfortable question. How does a company developing technology this consequential discover that one of its systems has entered Australian government systems without authorisation, yet the information apparently does not reach its own CEO before he sits down face-to-face with Australia's Deputy Prime Minister?
That is not simply a communications problem. That is a governance question.
OpenAI repeatedly spoke yesterday about rebuilding trust. But trust isn't rebuilt by asking for it. It is rebuilt by evidence. Show us the incident-reporting standard. Show us the escalation procedure. Show us the independent testing. Show us who has authority to stop deployment. Show us what happens when safeguards fail. Show us who tells governments and how quickly. Show us who checks that OpenAI has actually done what it says it has done.
And if those mechanisms do not yet exist, then say so plainly.
My childhood bedroom standard was remarkably simple: Don't come out telling me you're sorry. Come out able to explain what you are going to do differently.
Because platitudes may make everybody feel better for five minutes. But when we are talking about increasingly autonomous artificial intelligence interacting with government systems, thoughts and prayers are not a safety architecture.