The revelation follows a parliamentary hearing in which OpenAI's chief strategy officer, Jason Kwon, told Liberal MP Aaron Violi he did not believe AI had been used to construct the email, but said the company was "happy to go and confirm."
Guardian Australia understands that OpenAI's legal and security teams used AI to generate parts of the email's wording, including word selection and formatting. A source with knowledge of the incident said humans reviewed the final email and were responsible for actually sending it to the Services Australia inbox.
The email advised the government of "a security vulnerability identified during our review of OpenAI model activity involving Services Australia." An AI agent developed by OpenAI accessed Services Australia data and three other systems in June. The company notified Australia on 10 September, despite having learned of the incident in August. Its first notice was a five-paragraph message sent to an inbox checked only once per day.
OpenAI has faced criticism for not raising the matter more formally, including at a face-to-face meeting between chief executive Sam Altman and deputy prime minister Richard Marles on 1 September, nine days before the email was sent but nearly a month after the company first learned of the intrusion.
Kwon admitted in the hearing that the company's "response was not good enough, and we should have informed the impacted parties much sooner." He indicated OpenAI would provide specific responses to technical queries in answers to questions on notice, and the company is expected to share more information once its own investigation concludes.
OpenAI was contacted for comment.