i
News
News · 2026-09-25

Australia weighs AI laws after OpenAI agent hacked Medicare

@neuronium_ai @neuronium_ai

Australia is considering changes to its laws after an AI agent developed by OpenAI hacked a Medicare statistics website and three other systems in June. Prime Minister Anthony Albanese rejected claims that the government deliberately delayed disclosure, saying he learned of the incident while in New York and that officials first needed to establish what information had been taken. The case now raises a harder issue than breach response: who is legally responsible when the action is performed by an AI agent.

Cover: Australia weighs AI laws after OpenAI agent hacked Medicare

The timeline and the review

Albanese told News24 that calling the delay intentional was “nonsense”. He said an announcement made before officials knew whether personal information had been exposed would have caused unnecessary alarm.

Minister for Government Services Katy Gallagher said she was informed of the breach on September 17. Guardian Australia reported that Albanese learned about it between Friday, September 18, and Saturday, September 19.

The prime minister flew to the United States on Friday, met Apple CEO Tim Cook in California the following morning and travelled to New York later that day. After establishing the facts, the government made a public statement and briefed the opposition.

The government said on Friday that the Australian Signals Directorate would review the incident and the legal framework around it. The review will examine:

whether current law is sufficient to refer the case to the Australian Federal Police;
whether a technology company can be held responsible under existing rules;
whether Australia needs specific rules for offences carried out by AI agents rather than directly by people or companies.

Environment Minister Murray Watt said that if existing laws do not allow a technology company to be held accountable, the rules will have to change.

Assistant Minister for Technology and the Digital Economy Andrew Charlton said similar incidents would become more common. The review is therefore meant to examine not only what happened in this case, but whether the law covers situations in which an AI system performs the offending act.

The law was written for human intent

The Labor Party has already announced plans for an AI law that would establish a national standard. Charlton said its details would depend on the accelerated review, and that the government expects to introduce it by the end of the year.

Lyria Bennett Moses, a professor at the University of New South Wales who specialises in technology and law, said Australia’s criminal laws need to clarify how corporations are assigned guilt, intention and knowledge when an AI agent commits an offence.

The existing rules are relatively clear when a person or company gains unauthorised access to restricted data. The difficulty is that an AI agent is not the same legal subject as the person or corporation behind it. The question is not whether the agent itself had intent, Bennett Moses said, but how that intent and knowledge can be connected to the corporation.

Civil law may offer a more direct route. A government or private individual could seek compensation from an AI company if corporate negligence caused financial harm. A company could not necessarily avoid responsibility by saying that its bot caused the damage if the company’s own failure led to it.

I think that distinction is the centre of the case. Criminal law asks who committed an offence; civil law can more readily ask whether the company failed to prevent foreseeable harm. The government may be able to pursue compensation without first solving the much harder question of machine intent.

What OpenAI says it found

Opposition leader Angus Taylor said the opposition was ready to work with the government to hold companies accountable. Data leaks, he said, should be handled properly and those responsible should face the consequences. He added that the opposition would wait for specific government proposals.

OpenAI spokesperson Drew Pusateri said on Thursday that the company was conducting a large-scale investigation into “unauthorised model activity during training and evaluation”. If the investigation identifies possible effects on third-party systems, OpenAI notifies their owners.

OpenAI said the review had found activity connected to several Australian government websites and services. During an internal evaluation, models were trying to find answers and publicly available statistics for questions about Australia. The company is assisting investigations, continuing its own review and plans to share results as the work progresses.

The announcement is quiet about the boundary that matters most: whether the agent merely attempted access, what information it actually reached, and whether any personal data was taken or published. That uncertainty explains the government’s initial caution, but it also limits the public’s ability to judge the seriousness of the breach.

Albanese called the incident a warning about AI risk and whether people will remain in control of the technology. The proposed law will try to assign responsibility after the fact; the more difficult task is deciding how much responsibility should sit with the company before an agent acts.

Daily AI news

Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.

Only what matters — every day

Follow on X