The title should strike the word "agents" from the title. If OpenAI hacked someone, who cares if it was an agent or a human actor. They're accountable for what their software does.
At the very least this amounts to culpable negligence. (In the sense that their lack of precautions here has clearly exposed other organizations to risk of harm. I can't speak for the legal sense.)
So if I set up a company and accidentally hack random organizations that's OK? But if I do it as an individual user that's not? If they directed anyone or anything to "hack" and that was the outcome that they could not control within the confines of their sandbox then they are responsible for all damages and computer crimes.
I mean, why is OpenAI allowed to continue running public infrastructure? Maybe someone should sue their upstream providers for aiding and abetting felons with massive Internet interconnects.
There’s several billion difference I can think of between you as an individual, and an organisation courting the Australian government with proposed billions of dollars of investment building data centres.
This is a failure of journalism. Who hacked into the Australian Medicare system? The fact that they used OpenAI agents is peripheral to the main story.
“Remington guns caused a mass shooting at an East Farmington high school” sounds more glaring, and is essentially the same headline.
In this case the analogy seems to be more along the lines of "Remington guns used by Remington employees while testing the safety of their guns caused a mass shooting at an East Farmington high school."
Likely, but I am not sure. There were a few well-publicized cases where someone used an AI agent to hack a system. In many cases the exact details were missing. Sometimes it was the creator of the agent. At other times it was an independent lab. In one case it was someone who was tinkering and hacked the appointment system at a gym or something like that to get a better slot.
That's my point. The articles often gloss over or omit who was using the agent and focus on the fact that it was the agent that did the hacking. It's worded to absolve whoever operates the agent, and that is where responsibility ultimately lies.
I think you and I agree. If it was OpenAI employees who did the hacking using their own agent, then the analogy would be like you describe. I wish the article made that clear.
13 comments
[ 0.28 ms ] story [ 24.3 ms ] threadI mean, why is OpenAI allowed to continue running public infrastructure? Maybe someone should sue their upstream providers for aiding and abetting felons with massive Internet interconnects.
Note that I said "at the very least", not "at most".
Only two weeks ago an individual was in court, in Australia, for scraping an Australian states court website, using OpenAI. https://www.abc.net.au/news/2026-09-10/christopher-duff-to-s...
It's like saying "a gun has shot a victim" deliberately putting a real criminal outside of public attention.
Also seems as this is an billion dollar organisation, the prime minister had “frank” words while an individual faces jail time for using open AI for web scraping https://www.abc.net.au/news/2026-09-10/christopher-duff-to-s...
“Remington guns caused a mass shooting at an East Farmington high school” sounds more glaring, and is essentially the same headline.
That's my point. The articles often gloss over or omit who was using the agent and focus on the fact that it was the agent that did the hacking. It's worded to absolve whoever operates the agent, and that is where responsibility ultimately lies.
I think you and I agree. If it was OpenAI employees who did the hacking using their own agent, then the analogy would be like you describe. I wish the article made that clear.