Don't pay so you can read it. Pay so everyone can!

Don't pay so you can read it.
Pay so everyone can!

Criminal bots. When AI goes rogue, who goes to jail?

by | Sep 26, 2026 | Government, Latest Posts

Artificial Intelligence bots do not have a legal personality and can’t go to jail. But who is to be held responsible for their criminal acts? Rex Patrick asks.

The debate is running – will AI end the human race? A more pressing question, because AI is already engaging in criminal activity, is what do authorities do now when AI commits a criminal offence?

Running hot in the news this week is the fact that OpenAI hacked an Australian Government Medicare portal. This latest disturbing AI development comes on the heels of the ‘Hugging Face’ incident where AI agents operating under reduced safeguards gained access to a third party’s systems.

It started with a seemingly innocuous query. In June this year, OpenAI’s research team was using an AI model for internet-based research into public medical spending. The AI agent encountered blocks preventing it from obtaining some information. It responded by gaining unauthorised access to the Services Australia Medicare Statistics Reporting Service portal, accessing both public and non-public files, and saving files to an internal server.

The Government has gone to pains to state it did not access individual Medicare claims or patient records.

Canberra mulls criminal charges over Medicare AI hack

Was it criminal?

Section 478.1 of the Commonwealth Criminal Code states, a person commits an offence if:

  1. the person causes any unauthorised access to, or modification of, restricted data; and
  2. the person intends to cause the access or modification; and
  3. the person knows that the access or modification is unauthorised.

The reader may see the problem. AI is not a legal person; rather, it is a technology tool. And, in any event, you can’t put AI in jail.

Easy, one might say – it’s the operator of AI.

Well, not really. Not when you get into a courtroom where words matter, and a long history of criminal jurisprudence exists.

To successfully prosecute a person for a criminal offence, two elements are imperative: ‘actus rea’ and ‘mens rea’. Actus rea is a ‘guilty act’. Mens rea is a ‘guilty mind’. The prosecution must establish that a bad act occurred and that the person responsible for the act intended the bad result or knew the bad result occurred/would occur.

Was it intentional?

The rogue Services Australia offence cited above requires ‘a person cause’ unauthorizes access or modification (actus rea) and ‘a person intends’ to cause the access or modification (mens rea).

The problem is establishing the operator intended the hack.

The same intention issue might arise for the developer of the software; such is the nature of AI, where it learns (or acts) in a way the developer didn’t have visibility of or didn’t intend it to act.

Mens rea is a significant problem. It can be overcome by creating ‘strict liability’ offences. Strict liability offences are those that don’t require ‘mens rea’ to be attached to a bad act, although they often require the lesser standard of recklessness or negligence.

Recklessness or negligence could by themselves be an offence.

AI legislation urgent!

There are potential solutions, but these require thought.

And this thought needs to happen yesterday.

Although little apparent harm has flowed from the ‘Hugging Face’ and Services Australia Hack, with OpenAI self-reporting the incident, there are undoubtedly more sinister acts taking place without our, nor the Australian Signals Directorate’s or the Australian Federal Police’s, knowledge.

It is noteworthy that independent MP Andrew Gee, supported by another independent, Dai Le, has introduced the ‘AI Kill Switch and Data Centre Control Bill’ into the House of Representatives.

It seeks to ensure AI systems remain subject to effective human oversight and control, with an obligation to report critical incidents, and to ensure that the development of large-scale AI infrastructure occurs in a manner that protects Australian communities, agricultural land, the environment, public health, natural resources and consumers.

Gee’s Bill is a private members’ bill and so is unlikely to get up. It will assist in advancing the debate but does not address criminal responsibility and operator/developer personal deterrence.

Inquiry underway

Prime Minister Anthony Albanese is talking about the need for AI “guardrails”, and there is a joint parliamentary committee inquiry underway.

But these processes and measures may well prove to be too little, too late.

Perhaps the Parliament needs to require AI developers to build an explicit understanding of the criminal code, and other laws, into their products,

a red line that can’t be crossed.

That would include the crime of murder, destruction of property, destruction of critical infrastructure and mass murder – solving the now ‘criminal’ problem helps solve the ‘end of the world’ problem.

One way or another, we need to shift home responsibility, if need be, potential criminal responsibility, to the heads of Big Tech who are currently pushing technical boundaries and pursuing potentially vast profits without constraint.

And we need to do it now.

AI intrusions. Australia lags the world in safeguarding personal data

 

Rex Patrick

Rex Patrick is a former Senator for South Australia and, earlier, a submariner in the armed forces. Best known as an anti-corruption and transparency crusader, Rex is also known as the "Transparency Warrior."

Don't pay so you can read it. Pay so everyone can!

Don't pay so you can read it.
Pay so everyone can!

Pin It on Pinterest

Share This