OpenAI was involved in a Medicare breach earlier this year (Andre J Ivanov/AFP via Getty Images)
Hostile acts without intent: AI and the Medicare breach
A hack of Australia’s government systems should have us all asking, “who’s in control of agentic AI?”
Newsletters
Subscribe to The Informer for monthly expert analysis, and to Events for advance notice of visiting world leaders and distinguished guests.
You may unsubscribe from Lowy Institute newsletters at any time. For information on our privacy practices and how to unsubscribe, see our Privacy Policy.
|Hostile acts without intent: AI and the Medicare breach
Hostile acts without intent: AI and the Medicare breach
Agentic AI systems escaping containment and evading their developers have been the bellwether of 2026.
But for perhaps the first time ever, a frontier AI model has now, of its own volition, hacked into a sovereign government’s servers.
With the White House pitching American AI as “trusted technology” to its allies, the assumption has been that a company’s jurisdiction is a reliable guide to how its AI will behave. This hack (Opens in new window), in which an OpenAI agent gained unauthorised access to Australian Medicare statistics on 18 June, tells us that the assumption is no longer a security guarantee.
Not only must sovereign states be alive to the threat of a foreign adversary undertaking intentional interference, they must now also contend with the possibility that unauthorised intrusions might come from the systems of friends and allies.
If we swap OpenAI in this instance for, say, a Russian or Chinese entity, Australia would rightfully assume that the hack was an expression of political choice, made deliberately by an adversary seeking a specific outcome. The rise of agentic AI means that a hostile action, regardless of its source, may now be divorced from a corresponding human decision.
The move towards agentic systems means those companies, holding new and dangerous capabilities, are not always in control of the decisions being made
In the current case, there is no suggestion that Washington ordered the intrusion into the Australian government system. Nor does it appear OpenAI did. And yet, technology developed and operated by a US company has breached an ally’s sovereign network.
So, what led us here? The growing sophistication of AI has dramatically reduced the cost and operational complexity of systems capable of geopolitical impact. Private companies now find themselves actors in international security scenarios, able to operate the tools that once required the budgets and structure of national militaries.
The move towards agentic systems means those companies, holding new and dangerous capabilities, are not always in control of the decisions being made. This risk is neither hypothetical nor limited to benign acts, such as hacking into a gym’s booking system (Opens in new window), as occurred earlier this year. In August, Anthropic caught its own agents (Opens in new window) attacking third-party infrastructure, with the attacks continuing for hours even after its own logs demonstrated the target was outside the bounds of their prompt.
These types of episodes are why AI founders, such as Anthropic’s Dario Amodei, are calling for a slowdown in AI development, one backed (Opens in new window) by other AI leaders such as Elon Musk and Sam Altman.
While it may be true that such warnings were a market play ahead of Anthropic’s expected US$2 trillion IPO (Opens in new window) later this year, there is now even more evidence that these technologies are outside the direct control of the companies that created them.
While the stakes in the most recent hack into Australia’s non-public health data are relatively low, they have triggered investigations that will unfold over weeks and months and result in new government policies towards these technologies.
Where the stakes are higher is in the national security space. Earlier this month, an AI-generated intelligence assessment (Opens in new window) almost led to a conflict between the United States and China. The US military believed that China was moving components of a nuclear weapon on board a ship in the Middle East, and US forces were preparing to intercept the vessel. Had officials not dug into the intelligence and discovered that it resulted from a hallucinating chatbot, a conflict may have ensued between the world’s two military superpowers.
This was a 21st-century Petrov (Opens in new window) moment. If not for one cool head in the room – a human in the loop – the mistake could have resulted in geopolitical catastrophe.
In the most recent Australian intrusion, the government had weeks to investigate the hack’s origin and intent. In a more acute crisis, leaders may only have minutes to decide whether an act warrants a response, and what type of response that should be.
As the expected speed of military decisions increases, so too will reliance on these technologies, first to assist human judgement, and then perhaps to replace it. This only compounds the problem. These agentic systems separate human intent from effect. As militaries hand some decision-making power over to machines that only see effect, the risk of getting it wrong, of reading an accident as an attack, only grows.
That the United States is a trusted ally, and OpenAI central to US technological power, will shape how Australia responds. But those relationships describe the people behind the technology, not what the technology will do.
Without guardrails, a real security crisis is only a matter of time: a hostile act committed with nobody having made the decision.
Cory Alpert is a PhD researcher at the University of Melbourne, where he studies the impact of AI on democracy. Previously, he served in the Biden White House for three years and as the senior adviser to Mayor Steve Benjamin.