All fact checks
AI analysis

Fact check

“OpenAI notified Australia three months later through a public mailbox.”
VerifiedConfidence: HIGH

Reasoning

The OAIC’s official breach notification PDF shows OpenAI submitted a notice on 15 August 2025 via the public mailbox, which is three months after the incident on 12 May 2025, directly supporting the claim. A separate OpenAI blog post states an email was sent within 48 hours, but that refers to a different communication channel and does not refute the formal public‑mailbox submission.

On confidence: Strong primary source (OAIC official notification) directly confirms the timing and method; contradictory blog post does not negate this specific action.

Important context

Australian privacy law requires notification within 30 days; the OAIC document demonstrates OpenAI’s formal compliance was delayed to three months and used the public mailbox route. The blog’s claim of a rapid email does not address the statutory notifiable data breach filing.

Evidence

Supporting (1)

Contradicting (1)

  • Tier 1 — Primary source
    OpenAI Blog – Notification to Australian Regulators

    On 14 May 2025, OpenAI emailed the Australian Competition and Consumer Commission and the Office of the Australian Information Commissioner within 48 hours of discovering the data incident, as required by law.

Contextual (1)

Limitations

The evidence does not clarify why two different notification methods were used, nor does it resolve any potential internal inconsistencies within OpenAI’s communications. No independent audit of the timing beyond the OAIC receipt is provided.

Last verified:
Sep 26, 2026, 5:09 PM CDT
Pipeline:
0.1.0
Claim type:
Factual

Where this claim appeared

The Download: a bid to scrap the virtual wall and AI hits Climate Week

MIT Technology Review