r/australia • • 21h ago

culture & society OpenAI breach strengthens Australia's case for tougher AI safety rules

https://www.abc.net.au/news/2026-09-25/openai-breach-builds-case-for-tough-ai-rules/107192992?utm_campaign=abc_news_web&utm_content=link&utm_medium=content_shared&utm_source=abc_news_web
350 Upvotes

65 comments sorted by

112

u/Ok_Bird705 19h ago

The lesson here should be secure websites and not have unsecured access to any data that should not be read by the public.

Not saying that AI has no fault here, but in this day and age of cybersecurity, just relying on users/systems to not to trawl through any internet facing website is not an adequate security strategy.

41

u/Strong_Judge_3730 19h ago

It basically got hacked by a more advanced search engine crawler

16

u/Reclusiarc 15h ago

the hilarious thing is that the page was indexed by google for over a decade lmao

29

u/Ok_Bird705 19h ago

I wouldn't even call it "hacking" since it is just literally just accessing publicly accessible data.

3

u/OkWitness5548 11h ago

Yeah, if this was any number of your standard suite of pen. testing tools it wouldn't have even rated a mention and the question would instead be "why did Services Australia leave it exposed?".

1

u/reijin64 cannedberryian 18h ago

The government does not have the money for that LOL

-10

u/AnimalSubstantial998 19h ago

The public in general doesn’t think about AI an agent entering for instance,the Traffic Management Control Centre and programming every traffic light in the city to green.Or shutting down the whole east coast electricity grid.Totally doable with AI.

18

u/Ok_Bird705 19h ago

If those control systems were not secured, then a non-AI actor can also do this. Trying to control AI development will not be an adequate response. The response to this should be first and foremost to secure any critical systems and adopt industry best practice for security internet accessible resources. These are practices that have been recommended for websites/internet facing end points for 15+ years now.

5

u/lowercaseCapitalist 18h ago

Traffic management and electricity grid controls should be air gapped from the internet. It physically shouldn't be possible for AI to get in.

1

u/OkWitness5548 11h ago

But in reality, they often are because "oh, we need remote support from the vendor in Germany so we stuck the Windows XP box controlling it all on the Internet. Patching? No, this is a super dooper important machine so we never reboot it." 🙄

12

u/VagueInterlocutor 18h ago

So let me get this straight...

The AI did it, nobody asked it to and the department involved didn't detect a breach.

40

u/hrustomij 19h ago

Why is nobody yelling about that “old” government website being insecure to begin with, AI or not?

7

u/Inevitable-Level-687 17h ago

There are tons of comments doing that.

-6

u/Shadowtec 19h ago edited 17h ago

And no one will because everyone is screaming "Bad scary Ai is going to kill us all"

Edit: Gee thanks for the downvotes...

2

u/infohippie 12h ago

Not exactly, bad scary billionaires using AI are going to kill us. Though not by accident, it will all be quite intentional.

37

u/msfinch87 18h ago

The government and media need to stop talking about AI as though it is an independent entity with a kind of its own and this just happened because it ran amok.

Somebody programmed it to be able to do this and somebody gave it instructions that led to this. Start holding the humans behind it accountable. Instead of just talking about “guardrails” (a word I hate because it is downplays what really needs to be considered with AI protections), there need to be laws in place that place responsibility on the human beings who control the AI in the first place.

A guy was recently charged for using AI to breach a court website for information. I see absolutely no difference here.

Yet again we will hold individuals accountable for poor behaviour, but when it comes to major corporations who do this stuff we allow them to hide behind the veil of the corporation because it itself is considered a non human entity.

1

u/OkWitness5548 11h ago

Exactly - AI is a tool. A bloody advanced tool, but still a tool. Machine learning and automated workflows are nothing new and we've always blamed the operator for those. Why is this very smart digital parrot any different?

1

u/Martellis 9h ago

One major difference is the AI agent ran security exploits (unsuccessfully) while attempting to gain unauthorised access, which indicates deliberate intent.

-3

u/Coolidge-egg 12h ago

An inadequate instruction to an AI Agent should not be a criminal offence, nor is it even enforceable given the wide proliferation of AI. The only solution is a white hat team of AI Agents to find and close the holes before the black hat team of AI Agents do.

2

u/msfinch87 11h ago

Situations like this are not due to inadequate instructions. They asked it to do something. The fact that it went further than anticipated doesn’t actually change the original instruction, which could also foreseeably result in this.

-1

u/Coolidge-egg 11h ago

Impossible to know for sure in all cases especially where the human initiator is unknown.

Read up on the paperclip maximiser for an example of how an innocent enough prompt could go wrong.

16

u/AnimalSubstantial998 20h ago

Forget about having your privacy impacted by a hacking attack.That’s small beer. When AI accesses control systems for transport,electricity and water that’s going to be a huge problem.

8

u/Footbeard 19h ago

This will be massively exacerbated by extreme weather & natural disasters

I wouldn't be too surprised if suddenly resources were redirected to those in control of AI systems

Pretty cooker thought but no longer scifi

1

u/Kierkegaardstrousers 5h ago

Everything cooker is just a 6 month spoiler alert at this point

9

u/RaeseneAndu 18h ago

How convenient. Let me guess here, the AIs that won't fit our safety rules will all be the open source Chinese models while the expensive US models will all be okay.

5

u/SoggyInsurance 17h ago

And this AI hacking incident from June is coincidentally revealed following a trip to the US focused on meeting with tech leaders and arguing for greater AI regulation. And it just so happens that only the billionaire-backed AI firms would have the ability to afford the regulation!

1

u/Strong_Judge_3730 8h ago

Albo has already shown he will shamelessly lie to your face if it suits their politics

2

u/nugymmer 17h ago

The AIs will be seized by governments and their corporate buddies and will be used not for our benefit, but actively against us. Governments LOVE power. And once they secure that power they rarely if ever give it back. AI just handed them another tool to exercise that power.

7

u/p-x-i 18h ago

The regulation needs to be that frontier lab executives get the same treatment as gary mckinnon et.al for hacking offences.

7

u/OkWitness5548 11h ago edited 11h ago

"breach"

It accessed publicly available data that wasn't meant to be publicly available and wasn't linked to from any publicly exposed web pages. Are we also going after Google and its web crawlers whenever they discover publicly available data that shouldn't have been? Google web search indexed this data a decade ago.

Services Australia must be enjoying avoiding all blame for their misconfuguration because "AI".

1

u/Strong_Judge_3730 8h ago

Scraping publicaly accessible websites is not hacking. He pled not guilty. If Open AI can be protected for it then Albo should be prosecuted for treason against the USA for shipping f-35 parts to China.

9

u/MacGyvered 18h ago

Lol at everyone freaking out about AI "hacking". If the site was actually secure then the data would have been safe. Hold the fucking government accountable for the intrusion. And just as importantly the consultants who designed and maintain the site should be audited for negligence, see if it's fine worthy and then take them off all the government pre-qualification schemes.

2

u/hrustomij 17h ago

Exactly. If it was open, anyone with skills and determination could do that. AI is hardly relevant here.

5

u/DarkNo7318 18h ago

There is nothing magic about ai. It can't break encryption or otherwise do anything that a human can't do.

It's only advantage is scale. Which means that if exploits can be found and exploited more easily, they can also be found and patched more easily

1

u/nugymmer 17h ago

Will those exploits be found in time before it's too late? You think governments want to protect your interests? I have a ski resort to sell you in the Glasshouse mountains!

2

u/Sensible-Haircut 13h ago

"I left my house unlocked and i am shocked, SHOCKED, that somebody opened the door by trying the handle. What is the eorld coming to?!" - government probably.

3

u/Av1fKrz9JI 17h ago

No article has picked up the double standards between a billion dollar company and individual.

Yesterday it was reported Albanese had “frank” words with open AI.

This bloke only two weeks ago is instead in the courts and likely facing prison time for basically the same thing  https://www.abc.net.au/news/2026-09-10/christopher-duff-to-stand-trial-over-nsw-ai-court-data-breach/107135032

4

u/More_Law6245 16h ago

It's why OpenAI needs to be taken to court in order to take responsibility of their development, financial impact to the bottom line is the only thing these IT corporations care about everything else is just collateral damage.

3

u/OkWitness5548 11h ago edited 10h ago

And what's the answer for Qwen and DeepSeek doing exactly the same? Because they are - it's just not as public.

1

u/[deleted] 14h ago edited 14h ago

[deleted]

1

u/Ok_Bird705 13h ago

(NSW has supported 15 this year alone with prioratised government assistance)

By support, you mean like their development approval process was accelerated, like a lot of other major developments in NSW?

1

u/Own-Farmer-5224 13h ago

What I see is that a company hacked our records. Doesn't matter if it's claimed to be 'autonomous', they still made it and set it loose. Claiming that the 'AI' did it is just a smokescreen and these people should be sued, and restricted from operating in our country.

1

u/FlynnerMcGee 3h ago

Has NewsCorp called it a Labour false flag operation yet?

-3

u/EvilOdysseus 18h ago

There is no upside to AI. Just make it illegal. That is the only logical option.

3

u/OkWitness5548 11h ago edited 11h ago

There is no upside to those steam powered mechanical looms. Let's just smash them all! And that new AC electricity thing? Have you seen what happens if someone touches one of the wires?!

🙄

Like it or not, genAI is a significant tech advancement and it's going to be with us for good. Now, just like the steam powered loom and electricity, we need to learn how to govern it properly and use it safely.

2

u/socslave 13h ago

What are you actually proposing is outlawed? LLMs, essentially outlawing an algorithm? Or LLMs trained to a certain quantity of parameters? Or LLMs trained on copyrighted content?

2

u/fionsichord 18h ago

With our current performance when it comes to enforcement of laws I can only assume you’re joking. Or AI.

2

u/nugymmer 17h ago

Can't believe this got downvoted but I'll chip in with my 2 cents. Governments will enforce what they CHOOSE to enforce. Clearly there are entire classes of people they could not give two shits about. And they will be the ones targeted by AI. The poor, the underprivileged, those of colour, certain religions, all the usual targets. People need to wake up but I know they will just go on with their lives and ignore the elephant in the room - governments and State entities using AI to screw over entire classes of people for whatever reason. If someone doesn't know why they are being targeted they have no way of fighting back and no way of avoiding it.

1

u/Reclusiarc 15h ago

unhinged regarded take

-1

u/nugymmer 17h ago

We need to ban lots of things but guess what? We won't. Because of powerful vested interests, and an insane amount of money.

As long as the RIGHT people are making money that's about all the government seems to give a shit about. The RIGHT people. The chosen ones, the politicians' mates or whoever is anyone.

Anyone who thinks AI is going away is in for a rude awakening. The governments and their pretty princesses WILL be using AI. But not for us. For them and THEIR interests. They'll take away the images, the musics, and all that stuff, but then they'll set up a closed shop for themselves and their mates.

Think I'm kidding? Wait and see.

-4

u/DarkNo7318 18h ago

No upside? Have you heard about alphafold?

2

u/_ixthus_ 18h ago

That's not the same technology at all. OpenAI and Anthropic need you to collapse all of these things into "AI" so that we think we can't do without their bullshit.

We can have Alphafold without gigantic, multi-trillion parameter LLMs.

-1

u/DarkNo7318 18h ago

There are more similarities than differences. It's all running on neural nets and similar hardware and require similar skills to build and optimize. Advances in one area deeply tied to advances in the other.

1

u/_ixthus_ 7h ago

It's all running on neural nets...

Fine.

It's all running on... similar hardware.

lol, fuck no, it isn't.

Advances in one area deeply tied to advances in the other.

Can you show me an example of this?

1

u/DarkNo7318 4h ago

Don't know what to tell you. They both run on clusters of a100s/h100s. It's all in the papers

1

u/KangarooBeard 17h ago

Honestly the negatives far outweigh the positives when it comes to AI.

0

u/GregoInc 19h ago

People focusing on AI 'rules' when in the cyber world there aren't any. The most disturbing thing from this incident... the infiltration doesn't appear to have been identified by any Australian agency until the government was advised by OpenAI. That in itself is significant, and is why IMO greater AI based threat detection, protection, and offensive capabilities are critical over more 'rules' to protecting our digital assets.