Comment
OpenAI agent's 'infiltration' of an Australian government website
Sep 24, 2026
A couple of brief thoughts regarding OpenAI agent’s ‘infiltration’ of an Australian government website:
-
In terms of responsibility, AI agents can be reasonably characterised as acting ‘on behalf of’ a particular individual or organisation. Therefore, the decisions and actions taken by an AI agent, and the conformance (or not) of these actions with law, norms and cultures can be reasonably attributed to that individual or organisation. If a human agent acting on behalf of an organisation had taken the same decisions and actions as the AI agent then attribution of responsibility would seem straightforward.
-
In terms of accountability, it seems that the AI agents at OpenAI can provide a form of account internally, which is likely to be how the incident was discovered. However, the systems for onward accountability, for instance to those who suffer harm from the decisions and actions of the AI agent seem underdefined and insufficient. It is unclear why it took OpenAI so long (around 2 months) to report the incident to an Australian Government agency. However, it seems reasonable to assume that it is some combination of inability and unwillingness to promptly detect, assess and communicate such incidents outside of the organisation.
Read the BBC article about the incident at: https://www.bbc.co.uk/news/articles/c6vgy0333dppo