‘Unintentional’ OpenAI data hack prompts calls to toughen Australian AI laws
Por Paul Karp and Finn McHugh — POLITICO – TOP Stories

CANBERRA — The Australian government has said OpenAI’s unauthorized access of Medicare statistical data may be referred to police but the Defence Minister has conceded the breach was unintentional, a fact that makes criminal penalties unlikely.
Australian Prime Minister Anthony Albanese revealed in New York that OpenAI’s agentic artificial intelligence had accessed non-public sections of the Services Australia website on June 18. The incident was not detected until two months later, in August and notified to Services Australia on Sept. 10.
The government established a snap inquiry, including into whether current enforcement mechanisms are effective, reporting requirements relating to AI-driven cyber-incidents, and information sharing by firms and within government, after seeking legal advice.
An OpenAI spokesperson did not respond to POLITICO’s questions about possible criminal activity, but said it is “conducting an extensive review of misaligned model activity during training and evaluation and notifying third parties when our review identifies potential impacts to their systems. During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation. In the course of that, our models took actions we did not intend.”
The incident prompted calls from independent Sen. David Pocock and the Greens to strengthen laws and close a possible loophole, with experts warning there is no precedent for holding corporations liable for agentic AI by establishing the intention necessary for an offense.
Australia’s criminal code contains an offense of unauthorized access to restricted data, but it requires that a person or corporation “intends to cause the access or modification.” Australian Federal Police successfully prosecuted David Cecil, a hacker who gained access to a National Broadband Network supplier’s system in 2011, securing a two-and-a-half year prison sentence.
Nicholas Davis, professor of emerging technology at the University of Technology Sydney, told POLITICO: “our laws are focused on a human doing it and doing it with intent,” and that earlier attacks by AI agents have involved malicious intent. “We haven’t tested this exact scenario in Australian law. We haven’t had the kinds of agents that think on their own and do this until quite recently.”
At a press conference in Sydney, Defence Minister and acting prime minister Richard Marles said it is a “very good question” whether the incident was illegal. “This is an unintended access, that’s clear. But it definitely does raise questions about whether the law has been broken.”
Marles said the cross-government taskforce led by the Department of Prime Minister and Cabinet would assess legality and “whether or not the legal regime we have in place is fit for purpose in a world where we have an emerging AI capability.”
Greens AI spokesperson David Shoebridge demanded a law change, saying there must be “clear consequences when an AI agent causes harm or damage.”
Shoebridge argued for “damages payable by those who are most responsible,” something which would make AI developers “think twice before releasing their next rogue AI on the world.”
“If a person hacked into a Medicare database they would be looking at years in prison, but if you are a big U.S. tech company you don’t even get a slap on the wrist,” he told POLITICO. “If a corporation has created an AI agent, or allowed others to create one, without taking all reasonable steps to ensure they are safe, then they need to bear the consequences.”
Pocock said the prime minister could not argue for AI safeguards, and then overlook the safeguards needed to prevent future AI agent attacks. He demanded liability be built into Australia’s legal framework, telling POLITICO “the government should be throwing the book at them.”
“These companies are creating technology that they are admitting that they don’t understand at times, and they can’t control. You tell an agent to go and get publicly accessible information, and the next minute it’s hacked Medicare,” he said, adding, “I don’t think many Australians would think that it’s okay just to say: ‘Oh well. It was unintentional, so no worries,’” he said.
Pocock said the Albanese government had done a huge amount of work on an AI safety Act and set up a safety advisory committee, only to scrap it without providing clear reasons.
Conservative opposition frontbencher Andrew Hastie argued the incident should prompt Australia to take a more strategic approach to agentic AI threats, telling radio station 2GB “if there’s rogue AI agents out there, we need to have our own defensive AI agents protecting Australian government data, our private sector, and other things that are important to us.”
On Wednesday, before the incident was revealed, Labor MP Ed Husic, the former industry minister responsible for developing AI guardrails, told POLITICO that a national AI act is needed instead of “kneejerk reactions to problems after the event.”
“It’s not good enough that every time we discover AI doing something we don’t like, we come up with a new law — it’s a whack-a-mole,” he said, calling for broader prospective obligations on AI companies.
Olivia Shen, director of strategic technologies at the United States Studies Centre, said the incident is “exactly the kind of canary in the coal mine we need to prompt greater action on AI guardrails, governance and disclosures of incidents.”
“Mounting evidence of misalignment incidents being reported months after they actually happened,” makes it less plausible to argue that current rules are sufficient, she said.
Fonte: POLITICO – TOP Stories