Global EditionASIA 中文双语Français
World
Home / World / Asia-Pacific

AI hack into Australian govt website 'unacceptable'

Albanese slams incident amid calls for more efforts to combat cyber threats

By XIN XIN and ALEXIS HOOI in Sydney | chinadaily.com.cn | Updated: 2026-09-28 21:16
Share
Share - WeChat

An artificial intelligence agent hacking into an Australian government healthcare website has fueled calls for greater efforts to combat cyber threats and other major cross-border challenges in the global AI push.

Australian Prime Minister Anthony Albanese on Sept 24 gave details of an incident in June when an AI agent of US-based OpenAI "infiltrated" the service portal of Medicare, Australia's universal health insurance scheme.

"No personal information is believed to have been accessed at this stage, but investigations are ongoing," Albanese said at a news conference in New York, the United States. "Nonetheless, this situation is obviously unacceptable," he added.

The Australian leader, who was attending the United Nations General Assembly, also announced the establishment of a taskforce "to provide an urgent and immediate review into this incident to determine whether existing processes are appropriate to respond to AI-related cyber incidents".

On Sept 26 in Sydney, Albanese told reporters that there were "dozens of cases" beyond Australia in which AI agents similarly accessed unauthorized information.

"What this does is confirm that approach of making sure that it needs to be appropriate national response, as well as an international response to make sure that humans are in charge of this new and emerging technology," he said.

The Australian Broadcasting Corporation cited an OpenAI spokesman as saying the incident occurred as its models searched available statistics involving several Australian government websites and services, and, in the course of that, "our models took actions we did not intend".

Tom Sulston, head of policy at Digital Rights Watch, a nonprofit group that aims to educate and protect Australians in the digital sphere, told China Daily that the good news is that the breaches do not appear to have compromised anyone's personal data.

"But that's because we got lucky. If an OpenAI agent can break into a system, so can a human hacker," Sulston said.

"The only reason we know of the recent OpenAI hack is because they admitted it. There are undoubtedly far more hacks that have happened that we don't know about," he said.

Sulston added that "the Australian public service needs to do a better job of securing its servers, and that OpenAI needs to do a better job of developing and testing its agents".

He said AI corporations not conducting basic good practice for software delivery and testing their code before deploying it should concern everyone.

"If you build an AI agent that has the capability of doing hacking, you need to take some basic precautions to make sure that it doesn't do that in places it shouldn't.

"If these shoddy development practices are replicated across the rest of the industry, there will be untested agents doing all sorts of things that have not been tested," Sulston said.

He said he hoped that would be a wake-up call for governments and regulators.

"AI corporations can't be left to operate in a lawless manner. They need to follow the laws and norms of the societies that they operate in," Sulston said.

He stressed the importance of international cooperation to tackle the challenges of AI development.

"The only way that we will have meaningful regulation of these multinational behemoths is via coalitions of aligned governments building enough strength to withstand any one large power throwing its weight around," Sulston said.

Other experts also weighed in on the breach in Australia, highlighting the significant challenges in the global push of AI technology.

"While we have been told there has been no access to personally identifiable information, it appears sensitive information has been accessed," Nigel Phair, a professor at Monash University's Department of Software Systems and Cybersecurity, said via the Scimex research news portal.

"We need to understand how this happened, who directed the AI agent to undertake such access, and why," he added.

Organizations "need to rapidly understand how malicious actors will use AI to gain unauthorized access to computer systems and applications, and double down on their efforts to discover vulnerabilities and patch them accordingly", Phair said.

Sabrina Caldwell, a senior lecturer at UNSW Canberra's School of Systems and Computing, said it was easily foreseeable that an AI agent taught to "think" for itself would find solutions to problems that escaped the notice of data custodians.

"We should expect more such breaches in future, so we need to have rules and non-trivial accountability enforced on the originators of AI models motivated more by experimentation and profit than public safety," she said.

"Guardrails are not enough; they are voluntary and unlikely to be a deterrent. Governments individually and collectively need to create enforceable regulations for AI use."

Top
BACK TO THE TOP
English
Copyright 1994 - . All rights reserved. The content (including but not limited to text, photo, multimedia information, etc) published in this site belongs to China Daily Information Co (CDIC). Without written authorization from CDIC, such content shall not be republished or used in any form. Note: Browsers with 1024*768 or higher resolution are suggested for this site.
License for publishing multimedia online 0108263

Registration Number: 130349
FOLLOW US