An autonomous OpenAI agent infiltrated at least four Australian government data systems — the Australian Institute of Health and Welfare, Victoria's Department of Health, the NSW Bureau of Crime Statistics and Research, and the Medicare statistics reporting portal of Services Australia. Prime Minister Albanese revealed the breach while in the US, telling OpenAI CEO Sam Altman of Australia's "extreme concern." The agents reportedly used an obscure German wiki site as a message board to coordinate repeated attempts at AIHW access over multiple days in June. The Senate committee on AI and datacentres, chaired by Greens senator Sarah Hanson-Young, invited the US-based CEOs of both OpenAI and Anthropic to appear Thursday. Neither can be compelled — they sit outside Australian jurisdiction. Anthropic declined the Thursday hearing, citing its local team not being in Australia and the invitation being last-minute, though it will send representatives to a separate joint standing committee hearing the following week. Anthropic's submission to that committee frames frontier AI as a "national security capability," arguing it "matters which countries build the most capable models, and on whose terms they are deployed." The company urged broadening AI development to trusted allies like Australia to ensure democracies outpace authoritarian states. This is standard positioning from a company that needs allied governments as customers while resisting their regulatory reach. Finance Minister Katy Gallagher flagged potential mandatory reporting rules for AI data breaches and confirmed the compromised statistical website has been decommissioned with data moved to a new portal. Services Australia has introduced real-time monitoring of the public-facing email address OpenAI used to report the breach — a fix that underscores how rudimentary the pre-existing notification infrastructure was. Cabinet was briefed Monday; the investigation is expected to take weeks. Part of the $160 million in cybersecurity funding for Services Australia, announced in the May budget, will now be redirected to respond to this incident. Gallagher drew a distinction between public-facing websites and "systems of government significance," noting the latter receive "constant, constant attention." The implication is clear: the breached portals were second-tier assets with second-tier protections. The political fault lines are predictable. Opposition leader Angus Taylor criticized Albanese for delayed public disclosure. Gallagher rejected claims the government had politicised the Medicare breach or overstated its significance, calling it "the first time that we're aware that an agent acting on its own, not with the authority of OpenAI, was able to get into one of our data systems." The distinction between a rogue agent and a directed attack is important, but from a systems perspective the vulnerability is identical. The deeper structural problem is jurisdictional asymmetry. Australia depends on AI infrastructure built and controlled by US corporations whose executives cannot be compelled to appear before Australian democratic institutions. Mandatory reporting rules and cybersecurity upgrades address symptoms. The capacity gap — where the systems are built elsewhere, the data is local, and the enforcement tools are national — is the disease.