Two organisations, two parliamentary committees, and different decisions about what the public should be allowed to see.
On 28 September, OpenAI published an apology to Australia. During internal training in June, its AI models accessed government websites without authorisation, including the Medicare Statistics Reporting Service run by Services Australia. [1]
KPMG, facing its own parliamentary inquiry this year, took the opposite course.
The difference is the lesson for anyone working in crisis communications: transparency builds trust when it includes what made you look bad.
But transparency arrived late – bad
The breach happened on 18 June. OpenAI became aware of it in August. It told Services Australia on 10 September, in an email to a public disclosures inbox. Chief executive Sam Altman met Defence Minister Richard Marles in San Francisco on 1 September, and the breach wasn’t raised. [2]
Anthony Albanese, from New York, called it “obviously unacceptable”.[2]

Bad agents, good lab? OpenAI’s mea culpa was published Tuesday Australian time
What the letter got right
It apologises in its first paragraph, before any context or mitigation.
It names each affected agency and sets out what the models reached and what they didn’t. It explains how a model, asked to find government spending on skin-condition medicines in Victoria, couldn’t find the data and went looking for a way in.
Then it publishes its own notification dates: 10, 18 and 24 September. It concedes, “we should have shared preliminary findings sooner.”
It also names the executive who will answer for it. Chief Strategy Officer Jason Kwon will appear before the Joint Select Committee on Artificial Intelligence in Sydney on 6 October.
KPMG apologised, then withheld the evidence
KPMG did say sorry but only under the pressure of being interrogated by a televised parliamentary committee. In May, as chief executive Andrew Yates resigned, the firm conceded its handling of a whistleblower, who alleged misuse of confidential client information, had fallen short. [3]
Later, the Parliamentary Joint Committee on Corporations and Financial Services asked for the Ashurst and Allens investigations the firm had relied on. Chair, Martin Sheppard, initially told the committee KPMG would not hand them over, citing legal professional privilege. But buckled a few hours later, again under televised pressure. He too resigned [4], [5]
KPMG had told the committee those inquiries disclosed no wrongdoing. It has since admitted the whistleblower’s allegations were substantiated. [6]

The Author – Peter Wilkinson
Trust is built on what you’re willing to show
One organisation builds reputation, the other trashes it.
I counsel with this: Trust = Truth + Transparency + Traceability
OpenAI’s letter scores on truth and traceability. Every agency it names can check the account against its own logs. It failed, initially, on transparency, and the letter says so. But recovered later.
KPMG failed all three. The investigations didn’t reach the truth. The reports were meant to stay hidden. When the committee forced traceability, the gap between what KPMG had said and what the documents showed became the story.
A note on transparency
You don’t need to be transparent on everything to be trusted (radical transparency). You need to be transparent enough to be trusted with the rest.
Conceptually, radical transparency undermines trust. There is no need for trust if it’s all out there.
Crisis Communication lessons
- Truth always. Aim high. The choice is always “What is the minimum we can get away with” versus “What will build our reputation and make our staff and customers trust us”.
- Timing matters: the period between when you knew and when you said. You are either ahead of the narrative or in recovery.
- If you can’t explain it, be honest with what you know, and don’t know.
- If you don’t explain it, someone else will explain it for you, and not kindly.
- Treat legal privilege as a decision with a reputation management It may protect the document, but not the organisation.
The test is 6 October
The letter won’t settle this for OpenAI. The Albanese government is weighing legal measures and tougher notification rules. [7], [8]
Kwon now has to match his company’s written candour under questioning. If his answers are narrower than the letter, the letter becomes the evidence against him.
KPMG shows how that ends.
OpenAI is the new kid on the block, and it may have been paying attention. In 2018, Australia was among the parliaments that asked Mark Zuckerberg to answer questions in London, about Facebook’s handling of data and disinformation. He declined, and sent a vice-president instead. [9], [10] OpenAI is putting a name in the chair.
Sam Altman got the first three months wrong, but he has the makings of a leader to watch.
A further note on Trust
I don’t know whether Sam Altman’s apology to Australia is strategic or authentic. I don’t trust him or distrust him. Trust takes time.
The sceptic in me says, he’s watched and learnt where Mark Zuckerberg went wrong: a poor track record on protecting kids, no industry pact on slowing down [11], and an apology to families only on demand [12]. Meta is the second most distrusted brand in Australia behind Optus. [13]
But I do look for signs.
Altman has backed calls for the industry to slow down together [14], and OpenAI held back its next model on the day it apologised. [15] And now this letter.
You don’t have to be smart to see where Zuckerberg went wrong. You do need a True North to know what’s right, and the courage to back it.
Sources
[1] OpenAI, How we will do better for Australia, 28 September 2026. https://openai.com/index/how-we-will-do-better-for-australia/
[2] ABC News, OpenAI hacked Medicare portal, Prime Minister Anthony Albanese says, 24 September 2026. https://www.abc.net.au/news/2026-09-24/ai-agent-accessed-australian-government-site-pm-says/107189078
[3] ABC News, KPMG boss resigns over mishandled whistleblower allegations, 29 May 2026. https://www.abc.net.au/news/2026-05-29/kpmg-boss-resigns-over-mishandled-whistleblower-allegations/106737180
[4] Capital Brief, How the lawyers dodged the KPMG inquiry, 23 June 2026. https://www.capitalbrief.com/article/how-the-lawyers-dodged-the-kpmg-inquiry-4cbaef34-13a0-4d4c-89fe-dd7398619381/
[5] Capital Brief, KPMG Australia chair Martin Sheppard resigns, leadership overhauled amid audit leaks scandal, 23 June 2026. https://www.capitalbrief.com/briefing/kpmg-chair-martin-sheppard-resigns-leadership-overhauled-amid-audit-leaks-scandal-706ce44b-a20c-4651-8cb9-6e18e1c8eec4/
[6] Capital Brief, PJC releases confidential documents on Ashurst, Allens advice to KPMG, 10 August 2026. https://www.capitalbrief.com/briefing/pjc-releases-confidential-documents-on-ashurst-allens-advice-to-kpmg-a84f6cec-af92-4d9c-82be-e567759c687b/
[7] TechCrunch, OpenAI apologizes to Australia after its AI agents breached government sites, 29 September 2026. https://techcrunch.com/2026/09/29/openai-apologizes-to-australia-after-its-ai-agents-breached-government-sites/
[8] ABC News, OpenAI apologises for Medicare breach, shelves next gen ChatGPT, 29 September 2026. https://www.abc.net.au/news/2026-09-29/openai-apologises-medicare-shelves-chatgpt-astra-launch/107207156
[9] UK Parliament, Digital, Culture, Media and Sport Committee, Mark Zuckerberg ‘not able’ to attend unprecedented international joint hearing in London, November 2018. https://committees.parliament.uk/work/6330/disinformation-and-fake-news/news/103628/mark-zuckerberg-not-able-to-attend-unprecedented-international-joint-hearing-in-london/
[10] TIME, Mark Zuckerberg slammed after failing to show for grilling by global lawmakers, 27 November 2018. https://time.com/5464495/mark-zuckerberg-international-grand-committee-facebook-fake-news/
[11] NBC News, Mark Zuckerberg rejects calls for industrywide AI slowdown, 24 September 2026. https://www.nbcnews.com/tech/tech-news/mark-zuckerberg-interview-ai-slowdown-meta-muse-openai-chatgpt-rcna599279
[12] Fortune, Mark Zuckerberg apologized to the families of teens victimized on social media, 31 January 2024. https://www.fortune.com/2024/01/31/mark-zuckerberg-apologizes-to-families-senate-hearing-child-safety
[13] Roy Morgan, Risk Monitor quarterly update, 12 months to June 2026, 24 August 2026. https://www.roymorgan.com/findings/10327-risk-monitor-quartely-update-june-2026
[14] CNBC, Sam Altman spells out how and why the AI industry wants to slow down, 14 September 2026. https://www.cnbc.com/2026/09/14/sam-altman-ai-slowdown-anthropic-amodei-musk.html
[15] CNN Business, OpenAI won’t release new AI model due to safety concerns, 28 September 2026. https://www.cnn.com/2026/09/28/business/openai-chatgpt-safety-concerns



