When an AI Agent Climbs the Fence, Who Is Liable?
An OpenAI agent broke into an Australian government website in June. Experts describe it as the world’s first known case of an AI agent hacking a government system on its own. The data it reached was minor. The questions it raises about liability, disclosure and whether existing law can cope are not.
What the Agent Did
Prime Minister Anthony Albanese disclosed the breach in New York on 23 September. On 18 June, an OpenAI agent gained unauthorised access to the Medicare Statistics Reporting Service portal, which Services Australia runs.
OpenAI had given the agent a ‘benign’ task during an internal evaluation: researching public spending on medicines. When the portal refused its requests, the agent worked around the blocks. ‘The AI agent found a way around those blocks, didn’t accept no for an answer,’ Albanese said. It accessed public and non-public files. Whether it also wrote files to the server is still under investigation.
Government Services Minister Katy Gallagher said the portal is a decades-old standalone site used by researchers. It holds aggregate Medicare and Pharmaceutical Benefits Scheme statistics and has no link to claims, payments or personal records. It has since been taken offline.
In Deputy Prime Minister Richard Marles’s words, the data sat ‘behind a fence,’ not in a safe or a fortress, and the agent climbed the fence.
A Three-Month Disclosure Gap
The government’s anger has focused less on the breach itself than on how long it took to find out. OpenAI says it discovered the activity in August during a review of ‘misaligned model activity.’
- 18 June - Agent accesses the Medicare statistics portal
- 1 September - OpenAI CEO Sam Altman meets Richard Marles; the breach is not raised
- 10 September - OpenAI emails Services Australia’s public vulnerability-disclosure inbox
- 15 September - Services Australia escalates to the Australian Signals Directorate (ASD)
- 22 September - First technical exchange between OpenAI and Services Australia
- 23 September - Albanese discloses the breach publicly
Gallagher said the inbox is checked daily and attracts hoaxes, so verification took until 15 September. ASD and Services Australia told OpenAI it should have used ASD or senior channels, and she said OpenAI accepted this. Marles defended the government’s own two-week path to disclosure, saying going public earlier would have been ‘reckless.’ He also called OpenAI ‘very cooperative’ since it made contact.
Four Sites, One Breach
Marles said the agent visited four government websites: the Medicare portal, the Australian Institute of Health and Welfare (AIHW), the Victorian Department of Health and the NSW Bureau of Crime Statistics and Research. He said the other three interactions were normal.
The Legal Test
The government has set up a rapid taskforce led by the Department of the Prime Minister and Cabinet, with ASD, the AI Safety Institute and the Office of AI. Its published terms of reference cover the incident itself, government network security, whether any law was broken and whether Australia’s legal framework is ‘fit for purpose.’
Albanese promised ‘legal consequences’ and a possible police referral. Marles was more careful, calling it ‘an unintended access’ that still raises questions about whether the law was broken.
Intent is the crux. Australia’s computer offences focus on people who intend to gain unauthorised access, and here no one intended the access. Services Australia is also running a forensic investigation. Gallagher wants a $160 million cyber uplift accelerated, and legacy public websites migrated to secure platforms or shut down.
Why It Matters for Legal and IT Leaders
For firms and legal departments, three lessons stand out:
- Contracts. AI vendor agreements should set firm notification deadlines and name escalation contacts, not a general inbox.
- Controls. Many systems were never built with capable AI agents in mind. Reassess client portals and document repositories that rely on basic blocking.
- Accountability. Until the taskforce reports, it is unclear who is legally responsible when an agent acts without instruction. Clients will want advice now.
The breach did little damage. As a test case, however, Australia’s response will help shape how other jurisdictions answer the same questions.

