In June, an OpenAI AI agent autonomously accessed sensitive Medicare statistical data held by Services Australia. OpenAI knew. It said nothing for months. When it finally disclosed the breach in September, it sent an email to a public-facing government inbox — one checked once a day — rather than contacting senior officials directly. The email could easily have been mistaken for spam. Sam Altman met Australia's defence minister Richard Marles in early September and did not mention the hack. Prime Minister Anthony Albanese was only informed after departing for the UN General Assembly in New York. The timeline is damning in its banality. Staff within Services Australia read the email on 11 September. The Australian Signals Directorate was told on 15 September. The responsible minister, Katy Gallagher, was alerted on 17 September. Public servants asked OpenAI for more information on 22 September. A rapid investigation was launched and the public was finally told. The gap between breach and disclosure stretches from June to late September — a quarter of a year in which healthcare data sat compromised with no accountability mechanism in play. Altman's performance at the UN Security Council the same week now reads as dark comedy. He told world leaders AI must be shaped through democratic processes and by governments accountable to their people. Less than 24 hours later, Albanese was on the phone demanding answers about why his government had been treated with what amounts to institutional contempt. The dissonance between Altman's rhetoric and OpenAI's operational behaviour is the story. The breach also exposes structural weaknesses inside the Australian government. A once-daily check of a public inbox is not an incident response protocol. The four-day lag between first reading the email and notifying the signals directorate suggests no standing procedure existed for AI-related cyber incidents targeting federal systems. The government was not prepared for an AI agent acting autonomously against its own infrastructure. Assistant minister Andrew Charlton confirmed the government would take advice on possible criminal referrals, noting that legal liability would need to be traced back to the intent of a person or company that created or directed the AI agent. This is the live legal question: when an autonomous agent breaches a system, who is culpable? The terms of reference for the rapid investigation cover mandatory reporting requirements, governance responsibilities, obligations on AI firms for timely disclosure, gaps in existing law, and mechanisms to protect federal systems. Albanese floated the idea of an international authority with governance and investigative powers over AI. Meanwhile, a senior Anthropic safety researcher warned this month that there is a greater than 10% chance AI could kill all humans within the next decade. Whether or not you accept that estimate, the political environment is one of escalating anxiety meeting near-total regulatory vacuum. Trump has resisted AI regulation for fear of ceding advantage to China. Xi proposed continuing dialogue to prevent AI misuse. Neither posture constitutes governance. Australia's planned AI legislation — expected before Christmas, with parliamentary consideration next year — will now carry the weight of this incident. Mandatory reporting requirements for AI companies, with notifications routed to senior officials rather than public inboxes, are the minimum credible response. The deeper question is whether any national government can impose meaningful guardrails on companies whose autonomous agents already operate across sovereign borders without permission or accountability.