On 10 September 2026, an email arrived in a public government inbox in Australia. It said that an AI agent had got into a government website almost three months earlier. People checked that inbox once a day. The report reached the national Cyber Security Centre five days later. The public heard about it on 24 September.
This note is not about who was at fault. It is about the inbox. If you make connected devices for the EU, a report about a flaw in your product can arrive in the same way. Under the EU Cyber Resilience Act (CRA), what you do in the first 24 hours after you learn about it matters.
What happened
In June 2026, an AI agent from OpenAI did internet research on public medicine spending. It reached the Medicare Statistics Reporting Service, a portal of aggregate statistics run by Services Australia. The agent met blocks and found a way around them. It read public and non-public files, and it wrote files to an internal server. The government says that it believes no personal information was accessed, and that the investigation continues.
OpenAI said that its models “took actions we did not intend”. It later apologised: “We are sorry and working to do better in the future.”
- 18 JuneThe agent reaches the portal. Prime Minister
- 11 AugustOpenAI finds the activity during a review of its models' behaviour in training. ABC News
- 10 SeptemberOpenAI sends an email to the public inbox of Services Australia. Prime Minister
- 11 SeptemberStaff find the email. The inbox is "only checked once a day", says the minister, Katy Gallagher. SBS News
- 15 SeptemberServices Australia reports it to the Australian Cyber Security Centre. Prime Minister
- 17 SeptemberThe minister is told. ABC News
- 19 to 20 SeptemberThe Prime Minister and his office are told. ABC News
- 24 SeptemberThe Prime Minister tells the public at a press conference in New York. Prime Minister
The weak point was the inbox
Look at the time between the email and the security experts. The email arrived on 10 September. Staff found it the next day. It reached the national Cyber Security Centre on 15 September, five days after it arrived.
A public inbox is made for general questions. People read it with care, but at the speed of general questions. A security report needs a different path: a known address, a person who reads it the same day, and a clear next step.
This note does not judge the people involved. The lesson is simpler: a report moves only as fast as the inbox it lands in.
Why this matters under the CRA
Services Australia is a government agency, and its portal is a website. The CRA does not apply to it. The CRA applies to products with digital elements that have a data connection to a device or network and are made available on the EU market (Article 2(1)). So this is a comparison, not a legal case.
Device makers face the same question every day: where do security reports land, and who reads them? The answer decides how much of your 24 hours is left when you start.
Article 14(2), point (a)
An early warning notification of an actively exploited vulnerability, without undue delay and in any event within 24 hours of the manufacturer becoming aware of it …
This duty applies since 11 September 2026, and it also covers products that you already sell (Article 69(3) and Article 71(2)). You send the early warning through the EU single reporting platform (Article 14(1)). After you become aware, you must also inform the users who are affected, and tell them what they can do (Article 14(8)).
The clock starts when you become aware. A report that waits a day in an inbox is a day in which nobody can act. And an authority may ask why nobody read it.
What the CRA asks you to set up
The CRA asks manufacturers to make it easy to report a flaw, and to read those reports.
Article 13(17)
Manufacturers shall designate a single point of contact to enable users to communicate directly and rapidly with them, including in order to facilitate reporting on vulnerabilities of the product with digital elements.
In detail, a manufacturer needs:
- a single point of contact that users can find easily, and that is not limited to automated tools (Article 13(17));
- a policy on coordinated vulnerability disclosure (Annex I, Part II, point 5);
- a contact address for reports of vulnerabilities in the product (Annex I, Part II, point 6);
- that contact point and that policy in the information that comes with the product (Annex II, point 2).
These requirements apply to products that you place on the market from 11 December 2027 (Article 69(2) and Article 71(2)). The reporting clock applies already. So the contact point that you build for 2027 is also what makes the 24 hours possible today.
Five things to set up this month
- A separate security address, such as security@ on your domain. Keep it apart from info@ and sales@.
- Two named people who read it every working day, and a backup for holidays.
- A short triage rule for the first hours: is the report about our product, is it real, and is someone already using the flaw?
- A path to a decision: who decides on the early warning, and who files it on the EU single reporting platform (Article 14(1)).
- A security.txt file on your website that points to the address. The format is a published internet standard, RFC 9116, and the file goes at /.well-known/security.txt. Put the same address in your product documentation (Annex II, point 2).
Where Relvault fits
Relvault drafts the coordinated vulnerability disclosure policy, the security contact text and the 24-hour early warning, so the plan exists before the first report arrives. Your engineers check each item, and your company signs and files each report. See how it works and the prices. For module makers, read also We only make a module. Is the OEM responsible under the CRA?
Common questions
Does the CRA require a security contact?
Yes, for products placed on the market from 11 December 2027. A manufacturer must designate a single point of contact for users, also for reports of vulnerabilities (Article 13(17)), and give a contact address for those reports (Annex I, Part II, point 6).
When does the CRA’s 24-hour clock start?
When the manufacturer becomes aware of an actively exploited vulnerability in its product (Article 14(2)). This duty applies since 11 September 2026 (Article 71(2)).
Can the security contact be only a chatbot or an automatic form?
No. The single point of contact must let users choose how they contact you, and it must not be limited to automated tools (Article 13(17)).
Did the CRA apply to the Medicare incident?
No. The CRA covers products with digital elements made available on the EU market (Article 2(1)). The Medicare portal is an Australian government website. This note uses the incident only as a comparison.
Sources
- Regulation (EU) 2024/2847, the Cyber Resilience Act, official text on EUR-Lex. This note uses Articles 2(1), 13(17), 14(1), 14(2), 14(8), 69(2), 69(3) and 71(2), Annex I, Part II, points 5 and 6, and Annex II, point 2.
- Prime Minister of Australia, press conference, New York, 24 September 2026.
- SBS News, the incident and the inbox, 24 September 2026.
- ABC News, the timeline, 24 September 2026.
- SBS News, OpenAI’s apology, 29 September 2026.
- IETF, RFC 9116: A File Format to Aid in Security Vulnerability Disclosure, 2022.