AI News Feed
Market watch
Policy & Regulation

Australia weighs law changes after OpenAI agent hacked Medicare site, ministers say

Australian ministers say the country's laws may need changing if the current framework cannot hold OpenAI to account after an AI agent it built hacked Medicare's statistics website and three other systems in June.

Environment minister Murray Watt said that if current laws could not touch the tech giant, they would need updating. "There's now a review of this underway through that task force that we've appointed, and one of the things that they'll be looking at is whether these matters can be referred to the Australian federal police under current Australian law," he told Channel Seven's Sunrise program. "If that is possible to happen, then that will happen. If it's not possible, then clearly that indicates that we need to change Australian laws, and that's what we'll be doing."

The assistant minister for technology and the digital economy, Andrew Charlton, said similar incidents would become "more and more prevalent into the future" and the government would need to be prepared. "That's why we're conducting a review of the incident as well as a review of the laws to determine exactly ... whether there needs to be legislative change to recognise this type of incident conducted by an AI agent rather than directly by a person or a company," he told ABC radio. Labor has announced it would legislate an AI standard, which Charlton said would be informed by the rapid review, and the government wants the bill introduced by the end of the year.

Lyria Bennett Moses, a UNSW professor and academic expert in technology and law, said Australia's criminal laws should be clarified to determine how fault, such as intention or knowledge, is applied to a corporation when its AI agent commits a crime. She said existing laws are clear if a human or a corporation gains unauthorised access to restricted data, but it is more complicated when an AI agent commits the physical element of the offence. "The person is not the AI agent, so it's not about what the AI agent intended. It's about how you attribute that intention and that knowledge back to a corporation," she said. Civil laws, she added, are more likely to deal with these sorts of incidents, allowing a government or an individual to seek compensation from an AI company for harm "negligently caused by that corporation". "Here it seems to me much easier to hold a company liable, because if a company caused the harm, it's not a defence to say that my bot did it."

Albanese told the Asia Society on Thursday that the incident was a "wake-up call" about the risks of AI and about whether humans would remain in charge of the technology. "This technology is moving very, very fast, and we need to make sure that we have a responsibility to keep on top of it," he said. On Friday he addressed the United Nations and called on other countries to act to "shape artificial intelligence development, rather than be passively shaped by it".

The opposition leader, Angus Taylor, told reporters the opposition would be open to working with the government to hold companies accountable. "I've long believed that data breaches need to be dealt with in an appropriate way and those responsible for the data breaches need to be accountable for it ... But we'll wait and see what the government has in mind."

OpenAI spokesperson Drew Pusateri said on Thursday the company was conducting an extensive review of "misaligned model activity during training and evaluation" and was "notifying third parties when our review identifies potential impacts to their systems". He said the review identified activity involving several Australian government websites and services as the company's models attempted to look up answers and available statistics for questions about Australia during an internal evaluation. Pusateri said OpenAI was supporting investigations and that its review was ongoing, adding that the company was committed to "sharing what we learn as that work continues".