The hacking of a Medicare website by an OpenAI bot could mean a slew of regulatory issues are on the horizon for Prime Minister Anthony Albanese, whose government has labelled the incident as "fundamentally unacceptable".
A rapid task force led by the Department of the Prime Minister and Cabinet, along with the Australian Signals Directorate, the AI Safety Institute and the Office of AI, was launched on Thursday to investigate.
Deputy Prime Minister Richard Marles called the incident "very serious" with a "relatively minor" impact.
Central to the incident is an AI agent going beyond its parameters, or "scaling the fence", as Marles put it.
Dennis Desmond, of cybersecurity firm RAVINN and an adjunct senior industry fellow at the University of the Sunshine Coast, said blaming a "rogue" agent wasn't enough.
Raffaele Fabio Ciriello from the University of Sydney Business School agreed, saying the agent is "not a legal person", so responsibility turns on OpenAI and the people who "authorised, configured, or supervised the system".
The task force will examine whether any laws were broken, Marles said, but experts are divided on whether this is a matter for criminal law at all.
Professor Toby Walsh, chief scientist of the AI Institute and scientia professor of AI at UNSW, said OpenAI should be prosecuted.
Ciriello said Australian computer-offence laws can apply to unauthorised access, even when conduct occurs offshore.
Whether OpenAI broke Australian law and should be penalised will be up to a review into reporting requirements, incident response, sharing information of AI, legislation and beefing up cybersecurity announced on Thursday.