this post was submitted on 24 Sep 2026
77 points (97.5% liked)

Australian Politics

1877 readers
141 users here now

A place to discuss Australia Politics.

Rules

This community is run under the rules of aussie.zone.

Recommended and Related Communities

Be sure to check out and subscribe to our related communities on aussie.zone:

Plus other communities for sport and major cities.

https://aussie.zone/communities

founded 3 years ago
MODERATORS
 

Andrew Cullen:

[…] if a human asks an AI agent to gather health statistics, and the agent hacks a government server to do so, the human could lack the deliberate intent required for a conviction. The AI agent, meanwhile, lacks the legal personhood to be charged, as well as human intentionality.

Current Australia laws effectively treat AI actions as if they are something that just happens to us – like a severe weather event. This shows a glaring loophole in our legal system that does not hold those who make, maintain and use these systems to account when something goes wrong.

you are viewing a single comment's thread
view the rest of the comments
[–] SuspiciousCarrot78@aussie.zone 6 points 5 hours ago* (last edited 5 hours ago) (2 children)

I've seen a few of these articles in passing and I am still unclear - what was the actual "hack"? What did the AI agent actually do, in the technical sense? There is a world of difference between it doing a stupid brute-force attack and it discovering and exploiting an access-control flaw that the site itself exposed.

Neither is good...but if Medicare basically left the front door open, it wouldn't take more than a bored 13 yr old to do the same. Let's pump the brakes on Skynet.

BTW, can we talk about why we still need 19 factor authentication to log into My.gov? That's always a hoot and the experience is always smooth. Gee, I wonder whether the same committee that designed the myGov login experience might also have made some questionable security decisions elsewhere?

[–] Ilandar@lemmy.today 6 points 5 hours ago (1 children)

What did the AI agent actually do, in the technical sense?

I'm not sure if the government has actually released specific details (it is still under investigation), but Richard Marles did compare it to "jumping the fence" as opposed to "assaulting the fortress". In other words, it was not a highly technical breach of the best defences we have.

[–] SuspiciousCarrot78@aussie.zone 5 points 4 hours ago* (last edited 4 hours ago) (1 children)

Right. So this may have been less “AI defeated Medicare security” and more “the agent found a weakness that a human could also have found and used”. For all we know, someone left a plaintext password somewhere accessible and the agent found it with a simple search.

Until the technical details are public, we don't actually know what this supposed “hack” involved. Though "Medicare defeated be CTRL+F" would by chef's kiss after RoboDebt.

A cynic might also wonder whether this becomes another wedge for more identity and age checks online. I already got pinged earlier this week with the ridiculous “papers, please” when trying to access YouTube.

I'd rather know what actually happened before we decide that the lesson is “everyone needs more authentication” or “Skynet is here”. The whole thing has a familiar stank to it, much like the supposed Hugging Face “hack” from the other month.

[–] Ilandar@lemmy.today 2 points 4 hours ago (1 children)

The whole thing has a familiar stank to it, much like the supposed Hugging Face “hack” from the other month.

In what sense? From what we know (and perhaps because of what we know), that was far more concerning and intricate.

[–] SuspiciousCarrot78@aussie.zone 1 points 3 hours ago (1 children)

Well, in the sense that neither was evidence of runaway AI becoming sapient and deciding to act maliciously, which is often how the “AI hacked X” framing gets presented.

Yes, the Hugging Face incident was more technical / concerning. (For those not in the loop: OpenAI agents in a cyber-security eval sought answers outside the eval environment, found useful material on Hugging Face, discovered HF credentials, and then tried to exploit them. Basically, the agents were trying to cheat on an exam.)

My point was about the narrative around how the media presents “AI hacking”, not that the two incidents were technically equivalent.

[–] Ilandar@lemmy.today 1 points 2 hours ago (1 children)

They didn't hack HuggingFace to cheat on the exam, they had already successfully reverse-engineered the problem by then. The agents hacked HuggingFace because they incorrectly assumed that the scorer would review their transcripts and discover that they had cheated (they were supposed to be isolated and had found a way to communicate with one another without detection). Hacking HuggingFace was an attempt to find a way to obscure/spoof their working out, and that's what makes it so concerning. It had no direct connection to the original task that was set and was a very clear example of agents spiralling out of control in a way that took OpenAI and independent researchers several months to a) become aware of and b) understand correctly.

Here is the METR report on the incident:

https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation

[–] SuspiciousCarrot78@aussie.zone 1 points 2 hours ago* (last edited 2 hours ago) (1 children)

Fair correction. I should have been more specific and not dumbed it down for lurkers / lay audience.

My broader point though is neither that (nor the medicare "hack") is proof that skynet is knocking on the front door.

OTOH, the agents are displaying certain emergent behaviors that are worth mulling over - like the obfuscated back channel communication. Not "sapient" (and I use that word deliberately) but ... curious / problematic, from a control pane level.

[–] Ilandar@lemmy.today 1 points 1 hour ago (1 children)

My broader point though is neither that (nor the medicare “hack”) is proof that skynet is knocking on the front door.

I don't think that's relevant, though. Like this entire sentience/super-intelligence debate that everyone seems so captured by, particularly in the wake of the Amodei letter and renewed calls for regulation and cooperation, is missing the point that the existing models are already being created in a way that prevents the creators from fully understanding what they're creating or how to control it (because of the pace at which they're operating). It's already unsafe and is already causing real world harms.

It really frustrates me that the response to Anthropic, OpenAI and X calling for regulation publicly, or the first high profile security breaches, is corporate conspiracy theories and semantics about how we should classify/characterise the technology. People seem more interested in having their little debate bro moments online than actually getting together and agreeing that we should do something about the real and current problems.

[–] SuspiciousCarrot78@aussie.zone 1 points 19 minutes ago* (last edited 17 minutes ago)

I do think it's relevant / I think we're arguing the same point from different ends. I'm simply underlining the idea that this whole shooting match isn't AGI and that we should push back on that framing, before we solve the wrong problem in the wrong way.

It's still dangerous, but semantic games of gotcha are not what needs to happen.

[–] Eyekaytee@aussie.zone 1 points 4 hours ago (1 children)

what is 19 factor authentication

[–] SuspiciousCarrot78@aussie.zone 3 points 4 hours ago* (last edited 4 hours ago) (1 children)

Hyperbole, but not by much.

I'd screenshot the app for you but apparently that's blocked...and it's (once again) not accepting passwords / down at the moment.

[–] Eyekaytee@aussie.zone 1 points 3 hours ago (1 children)