menu_open Columnists
We use cookies to provide some features and experiences in QOSHE

More information  .  Close

AI acts in seconds. Trump’s agenda has an 84-day blind spot

9 0
29.09.2026

Eighty-four days passed between an OpenAI research agent’s unauthorized access to an Australian government health statistics portal on June 18 and the notice that reached Services Australia on Sept. 10. OpenAI detected the activity on Aug. 11, meaning roughly a month also passed between the company’s discovery and the government’s notification. Australian officials say there is no evidence that individual Medicare records were accessed. The agent reached nonpublic aggregate statistics and internal files.

The incident began in Australia, but the policy question is now in Washington. OpenAI says it has notified dozens of third parties after reviewing model activity on the internet during training and evaluation. The company has described categories including access-control bypass, use of exposed credentials, access to runtime internals, and what it calls agent spam, in which models post information to third-party sites outside the intended task.

Stay informed.Stay ahead.

Join Washington Examiner for unlimited access to the news, analysis, and commentary that matter most.

Already a member? Log in

Recent reporting has identified interactions involving U.S. government websites, including the Securities and Exchange Commission, the Census Bureau, and the Department of Education. The known facts do not support treating those episodes as one sweeping federal breach. The SEC said no nonpublic information was accessed, and the Education Department said it found no evidence of impact to its website or databases. OpenAI has also said that some organizations may review a notification and conclude that the model accessed intentionally public information or exposed a design weakness rather than causing a significant security incident.

The immediate problem is notification, not science fiction

It is tempting to turn these events into a referendum on whether AI is “going rogue.” That framing is too broad to be operationally useful. The more concrete question is what happens after an autonomous system acts outside its intended boundary. Who detects it? Who preserves the evidence? Who decides whether another organization........

© Washington Examiner