Can OpenAI actually be held legally responsible for rogue agent hack?
The Australian government is considering if there may be legal consequences for OpenAI after a rogue agent hacked one of its websites.
Prime Minister Anthony Albanese is seeking urgent advice on whether any laws were broken when a “misaligned” OpenAI model in training breached the Services Australia-run Medicare Statistics Reporting Service portal in June.
Sam Altman, co-founder and chief executive of OpenAI. AP
The company became aware of the breach months later, in August, and failed to notify the Australian government until September 10 via a public email address.
Deputy Prime Minister Richard Marles described the breach of the website, which holds public information, as the agent climbing a fence.
Whereas, he said individual and government information sit behind a safe and national security information sit behind a fortress.
The breach is still being treated very seriously by the government but has raised questions on whether OpenAI can actually be held responsible.
If a person had accessed the portal, they could be charged for unauthorised access to, or modification of, restricted data under the criminal code and face up to two years’ imprisonment.
Their company could also be liable if it was done as part of their employment.
Assistant Technology Minister Andrew Charlton conceded the laws for this type of incident would not apply to an artificial intelligence agent.
“An AI agent is not a legal person,” he told the ABC.
“In this situation where the breach was conducted by an AI agent, the liability has to be traced back to the intent of a person or a company that created or directed the agent.
“So, these are important legal questions and that’s why we’re taking advice on them in order to either make a referral or make changes to the law that may be required.”
ANU economist and public policy specialist Dominic Meagher said that legal action against a rogue agent would hinge on the ability to prove the company’s intent and any negligence.
Prime Minister Anthony Albanese is considering legal action. Getty Images
“There’s potentially a range of laws that were broken, but one thing here is that there was no intent,” he said.
“In this case, I think the question is going to come down to, did they do enough to prevent the risk of things going wrong? And what counts as enough?”
For example, he said, a factory that spills chemicals into a river is obliged to report that as soon as it becomes aware of the incident.
But before it becomes aware of the incident, it is obliged to have long processes in place to make sure it does not happen in the first place.
Meagher said allowing the big tech companies to build data centres in Australia would help gain some accountability.
“That certainly gives us more of a seat at the table,” he said on enforcing domestic guardrails on the US-based companies.
“If you’re not here, then we can just complain all we want, and no one’s going to care.”
The incident has reignited calls across the political aisle for domestic laws against AI so that companies are held to the same criminal standard over their agents.
Greens Senator David Shoebridge, who supported former Labor industry minister Ed Husic on safety measures around AI following consultations that began in 2023, said laws were now urgent.
“If a person hacked into a security government database they would be looking at a prison sentence. That should be the same case for these companies,” he said.
“The government absolutely has the ability to hold OpenAI and other companies to account when they act in this way, they are choosing not to.”
Independent MP Monique Ryan the country is exposed and immediate action is needed to protect data and privacy.
“If an Australian hacked Medicare, you’d hope they’d face jail,” she said.
“Until we get our act together, international AI companies face no accountability at all.”
Share a tip-off, video or photo with us