Ministers have confirmed that the federal government may amend Australian legislation if existing laws prove inadequate to address the unprecedented OpenAI breach of Medicare.
On Friday, the government announced that a review led by the Australian Signals Directorate would assess whether new legislation is required, following the prime minister’s disclosure that an OpenAI‑developed AI agent compromised Medicare’s statistics website and three additional systems in June.
Environment Minister Murray Watt stated on Friday that if existing laws cannot reach the tech giant, they will need to be updated.
“We now have a review underway through the task force we’ve appointed, examining whether these matters can be referred to the Australian Federal Police under current law,” Watt told Channel Seven’s Sunrise program. “If that’s possible, we’ll proceed; if not, it will clearly indicate that we need to change Australian laws, and that’s exactly what we’ll do.”
Assistant Minister for Technology and the Digital Economy Andrew Charlton noted that such incidents would become increasingly common in the future and that the government must be prepared.
“That’s why we’re reviewing both the incident and the existing laws to determine exactly whether legislative changes are needed to address offences carried out by an AI agent, rather than by a person or company directly,” Charlton told ABC radio.
Labor has announced plans to legislate an AI standard, which Charlton said will be shaped by the rapid review. The government aims to introduce the bill by year’s end.
UNSW Professor Lyria Bennett Moses, an academic specialist in technology and law, argued that Australia’s criminal statutes should be clarified to specify how culpability—such as intent or knowledge—applies when a corporation’s AI agent commits a crime.
Existing laws clearly address cases where a human or corporation gains unauthorised access to restricted data, she noted, but the situation becomes more complex when an AI agent carries out the physical act of the offence.
“The person is not the AI agent, so it’s not about what the AI agent intended. It’s about how we attribute that intention and knowledge back to the corporation,” Bennett Moses explained.
Bennett Moses added that civil laws are more likely to handle such incidents, enabling a government or individual to seek compensation from an AI company for harm negligently caused by that corporation.
“If a company’s systems suffer harm resulting in financial loss, and that harm was caused by the corporation’s negligence, there is a potential for litigation to obtain compensation for that harm,” she said.
“Here it seems to me much easier to hold a company liable, because if a company caused the harm, it’s not a defence to say that my bot did it.”
Prime Minister Anthony Albanese told the Asia Society on Thursday that the breach was a “wake‑up call” regarding AI risks and the question of whether humans would remain in control of the technology.
“This technology is moving very, very fast, and we need to make sure that we have a responsibility to keep on top of it,” Albanese said.
On Friday, the prime minister addressed the United Nations, urging other nations to act to “shape artificial intelligence development, rather than be passively shaped by it”.
Opposition leader Angus Taylor told reporters that his party would be open to collaborating with the government to hold companies accountable.
“I’ve long believed that data breaches need to be dealt with appropriately and that those responsible must be held accountable… But we’ll wait and see what the government has in mind,” he said.
OpenAI spokesperson Drew Pusateri said on Thursday that the company was conducting an extensive review of “misaligned model activity during training and evaluation” and was “notifying third parties when our review identifies potential impacts to their systems”.
“During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers and access statistics for questions about Australia during an internal evaluation,” Pusateri said in a statement.
Pusateri added that OpenAI was supporting investigations, that its review was ongoing, and that it was committed to “sharing what we learn as that work continues”.
Also Read
- The 50 Best Bars Unveils Extended 2026 List, Featuring 18 European Standouts
- Bitget Says Suspected North Korean Hackers May Be Behind $352 Million Breach
- Japan Tightens Immigration Rules, Sparking Uncertainty Among Long-Term Foreign Residents
- India’s Tata Conglomerate Entangled in Boardroom Power Struggle


