Dragging the heads of OpenAI and Anthropic into the Australian Senate after a Medicare hack is either smart accountability or pure political theater. Maybe it’s both. But if the goal is to make people feel safer, I’m not convinced this move gets us there.
Here’s what’s been shared publicly: after a breach of Australia’s public healthcare system Medicare, Australia’s Senate invited the leaders of OpenAI and Anthropic to hearings. The reported focus isn’t just “AI in general,” but also data centers. And the request for Sam Altman and Dario Amodei to show up is, at least for now, voluntary.
That mix—Medicare hack, AI hearings, data centers—tells you what’s going on beneath the surface. This isn’t really about whether a chatbot wrote a bad email. It’s about power. It’s about who gets to build the next layer of infrastructure, who controls the tools that sit on top of it, and who gets blamed when systems fail.
Because let’s be blunt: a hack of a government health system is usually not an “AI company problem.” It’s typically boring stuff: old systems, messy access controls, weak security habits, underfunded teams, and the fact that healthcare data is a gold mine. Pulling in AI CEOs risks turning a concrete failure into a vague culture war where everyone argues about “the future” and nobody fixes the passwords.
At the same time, I get why senators want them in the room. AI companies are pushing hard into healthcare, government services, and anything that touches sensitive data. Data centers aren’t just buildings; they’re the physical backbone for a lot of this. If a country is going to allow more AI services in public life, it has a right to ask: where is data processed, who can access it, what happens when something goes wrong, and who pays the price?
The uncomfortable part is that we might be using the Medicare hack as emotional fuel to pressure tech leaders on topics that are only loosely connected. That’s a classic move: take a scary incident, then expand the agenda. Sometimes that’s necessary. Sometimes it’s opportunistic. Either way, the hearing becomes less about the hack and more about setting the rules for the next decade.
And the rules matter because the stakes aren’t abstract. Imagine you’re a normal person and your Medicare-related data is exposed. You’re not thinking about “AI policy.” You’re thinking: can someone scam me, blackmail me, deny me coverage, or target me because of a health condition? Now imagine the government responds by grilling foreign CEOs on camera, and months later your local clinic still uses ancient systems and staff still share logins because it’s the only way to get through the day. That’s not safety. That’s performance.
There’s also a real risk of category confusion. AI can absolutely be used by attackers—writing better phishing messages, scaling scams, speeding up research. But that doesn’t mean OpenAI or Anthropic caused a particular breach. If lawmakers start acting like “AI companies did it” every time a system is hacked, the incentives get weird fast. Companies will focus on optics and legal shields. Governments will reach for easy villains. Meanwhile, the boring, hard work of security stays boring and underfunded.
On the other hand, letting AI leaders off the hook entirely is naïve. These companies want to sell tools that will be used in hospitals, call centers, and government agencies. Once your model is part of the workflow, you’re not a distant vendor anymore. You shape how work happens. If your tools make it easier to paste sensitive data into places it shouldn’t go, or if your products normalize “just try it” behavior inside critical systems, that’s not neutral. That’s a design choice with consequences.
Data centers being part of the hearing is the tell that Australia is also thinking about dependence. If a nation’s key services start relying on compute and platforms controlled elsewhere, it becomes a leverage point. Not because anyone is evil, but because priorities change. Pricing changes. Policies change. A model update breaks a process. A contract ends. A country that can’t run its own critical services without someone else’s servers is not fully in control.
Still, calling CEOs to a voluntary hearing has its own smell. If it’s voluntary, it can be dodged. If it’s dodged, it becomes a headline. And headlines are not security upgrades. I’d rather see lawmakers force uncomfortable detail out of the actual operators of the Medicare system: what failed, what was ignored, what was under-resourced, and what will change next week—not in five years.
If the Senate wants this to be more than a spectacle, the line should be simple: AI leaders can be asked about how their tools will be used in sensitive settings and what safeguards they will actually commit to. But they shouldn’t be allowed to become the main characters in a story that is, at its core, about government systems being fragile.
So here’s the argument I expect people to fight me on: the Medicare hack is a public-sector security failure first, and an AI policy story only if lawmakers deliberately turn it into one—and that choice might distract from the fixes that would actually protect patients.
What would you rather Australia optimize for right now: tighter control and local accountability over critical health systems, or faster adoption of powerful AI tools even if that deepens dependence on a few private companies?