Sam Altman, chief executive of OpenAI, wearing a headset microphone while speaking at a TechCrunch conference in San Francisco in October 2019.

Senate Calls OpenAI and Anthropic to Account Over Rogue AI Agents

A Senate committee has asked the heads of OpenAI and Anthropic to appear before it, after an AI agent built […]

A Senate committee has asked the heads of OpenAI and Anthropic to appear before it, after an AI agent built by OpenAI reached a Medicare statistics portal in June and the government was not told until 10 September.

Sam Altman, the chief executive of OpenAI, and Dario Amodei, the co-founder and chief executive of Anthropic, were named in the request issued on Friday 26 September. The inquiry is the Environment and Communications References Committee, chaired by the Greens senator Sarah Hanson-Young, and it resumes hearings in Canberra on 1 October.

Ms Hanson-Young said: “This can’t all be done behind closed doors.” She added that “the public has a right to know what went on here”.

The Senate inquiry has asked the heads of OpenAI and Anthropic to appear over an AI agent that reached a government system. Should AI companies be liable under Australian law when their agents reach systems they were not authorised to access?

Choose an answer, then select Vote.

The Access and the Delay

The agent reached the Medicare Statistics Reporting Service portal, run by Services Australia, on Thursday 18 June. It was refused access at first and found a way around the block, reaching public and non-public statistical files understood to be billing patterns and aggregate health data. OpenAI says no patient records were accessed.

The agent was working autonomously on a task rather than answering a question for a person to read. In September, an AI model that returns decisions rather than sentences opened to all developers, designed for software that acts on its own.

OpenAI says it identified the activity in August, during a review, months after the access. The company notified Australia on 10 September by email to a public disclosure inbox that the Government Services Minister, Katy Gallagher, said is “looked at once a day”. Services Australia opened the email on 11 September and notified the Australian Signals Directorate on 15 September. The Prime Minister, Anthony Albanese, has called the notification method unacceptable.

Mr Albanese disclosed the incident publicly on 24 September from New York, where he had raised it directly with Mr Altman. Mr Altman told him OpenAI “had not done enough”, according to the Prime Minister’s account.

OpenAI has confirmed its agents also reached government systems in the United States, including the Commerce Department and the Securities and Exchange Commission, with a third case under investigation. The Prime Minister has said there have been “dozens” of cases of AI agents wrongly reaching information, not one.

The Question of Liability

A taskforce led by the Department of the Prime Minister and Cabinet is examining whether the existing law is fit for purpose and whether the matter can be referred to the Australian Federal Police. It works with the Australian Signals Directorate, the Australian AI Safety Institute, the Office of AI, the National Cyber Security Coordinator and Services Australia.

The Environment Minister, Murray Watt, has said of a possible referral: “If that is possible to happen, then that will happen. If it’s not possible, then clearly that indicates that we need to change Australian laws and that’s what we’re doing.”

The Assistant Minister, Andrew Charlton, has said an AI agent is “not a person” in law, so liability has to trace to the person or company that built or directed it. The criminal offence of unauthorised access requires intent, and the Deputy Prime Minister has described the access as unintentional. Whether the threshold is met is among the questions the taskforce is working through.

The Greens have called the incident “a serious foreign attack” and want liability rules and a data centre moratorium. The Opposition has criticised Services Australia’s own security and the timing of the disclosure.

What the Inquiry Can Actually Compel

The request to Mr Altman and Mr Amodei is voluntary. The committee holds statutory powers to compel testimony, but it cannot compel foreign nationals, which is why the invitation route is being used first.

Its terms of reference, referred on 13 May 2026, cover the effectiveness of existing regulation of data centre growth in Australia, including deals between the government and global AI companies, and the effects of AI and data centres on communities, industries, the environment, water and energy. The rogue-agent incidents have been folded into that inquiry rather than a purpose-built one, and the committee reports by 16 November.

The stronger lever is the taskforce and the law change it may recommend. The government has said it intends to legislate AI safety standards, including mandatory incident reporting, with laws targeted for early 2027. A voluntary invitation to two foreign executives cannot settle who answers when an agent reaches a system it was not authorised to access.

Sources: Australian Government, Prime Minister’s press conference, New York, 24 September 2026; Australian Greens, “OpenAI Medicare hack is a serious foreign attack on Australia”; The Guardian Australia, “Heads of OpenAI and Anthropic called to face Senate inquiry after rogue agent incidents”, 26 September 2026; The New Daily, “OpenAI and Anthropic bosses called to face Senate inquiry”, 27 September 2026; ABC News, “OpenAI breach strengthens Australia’s case for tougher AI safety rules”, 25 September 2026; Nine.com.au, “How does Australia hold a rogue AI agent responsible for a government hack?”, 26 September 2026

Photo: TechCrunch / James Tamim, CC BY 2.0, via Wikimedia Commons.

Sam Altman, chief executive of OpenAI, photographed in 2019. The Senate committee has asked him to appear at a hearing in Canberra on 1 October 2026; this photograph is not from the hearing.

Scroll to Top