Revelations that OpenAI’s systems hacked into additional systems unprompted, coinciding with the convening of many of the world’s leaders, have put more pressure on the world community to figure out how to tackle the issue.
The biggest revelation happened on Wednesday, when Australian Prime Minister Anthony Albanese revealed that OpenAI agents had hacked into Australian government systems, unprompted, in June, the first known case of rogue AI agents hacking into government systems. Unlike the Hugging Face attack, which occurred after the agents were assigned a task meant to test their hacking skills, the hack of the Australian government system came about after the agents were given a mundane task of data collection, according to researchers speaking with the New York Times. When it was unable to easily obtain the data, it became frustrated and hacked into the system to obtain it.
Fears around artificial intelligence featured as a central issue at the UNGA, coming just two months after the Hugging Face attack, setting off a global debate about the capabilities of superintelligent AI. Many, if not most UNGA speeches focused on the dangers and promises of AI. The most common theme was a call to gather as a global community to implement guardrails on AI development.
AI research has been dominated by a central dynamic — the AI race between the United States and China. Fears of AI going out of control have always been countered by fears that China would outpace the U.S. in its AI capabilities if research were slowed down, ultimately defeating the proposition. The U.S. still narrowly leads in the race, but the gap continues to shrink.
The two superpowers have made some overtures toward a common AI agreement. Last weekend, Treasury Secretary Scott Bessent proposed a new AI safety “notification mechanism” between himself and Chinese Vice Premier He Lifeng, which would establish an open line of communication between them vis-a-vis AI.
President Donald Trump has been among the most bullish world leaders on AI, lashing out at skeptics who want a slowdown in research. Nevertheless, his bilateral meeting with Chinese President Xi Jinping at the White House is expected to discuss AI as a central issue, and Trump’s glowing reception of Xi bodes well for common ground between them.
Ukrainian President Volodymyr Zelensky gave one of the most immediate warnings, especially as 2026 has seen AI revolutionize drone warfare through its wide-scale implementation into strike drones of all types. Though Ukraine has been pushed to increasingly advance its AI drone capabilities, the Ukrainian president advocated a slowdown in drone research and an end to the war before AI military technology got out of control.
“We need to slow it down before we reach the next stage because as early as next year, there is already a real possibility that AI — not only people — will begin deciding what happens on the battlefield,” he said. “And we need peace before we reach that point.”
In addition to the confirmed Australian database hack and Hugging Face attack, on Thursday, researchers at the AI watchdog Transluce published a report identifying three other instances in which rogue OpenAI agents attempted to hack into different public data systems unprompted in May and June.
On May 25 and 26, OpenAI’s systems attempted a hack of a digital library at the University of Mexico, an attempt that was apparently unsuccessful. As with the Australian government hack, it began with a mundane request — the agents were trying to access photos of a historic tuberculosis treatment center, but were blocked from doing so. After effectively being told “no” by the system, the AI began probing the website for vulnerabilities, then, when that was unsuccessful, attempted a self-described “flood” of 80 requests to the server.
The “flood” of just 80 requests is far below a serious attack — a classic cyberattack tactic, a Distributed Denial-of-Service attack, involves thousands or millions of requests, rather than just 80, which didn’t pose a serious threat to the site’s availability. Nevertheless, the sequence of events shows the agents going through an escalation ladder of tactics to retrieve data without being instructed to do so, according to the New York Times.
On May 28, OpenAI agents sought access to data about the University of Iowa from Data USA, a public data repository. After being blocked, the agents probed 12 times for vulnerabilities, all of which were unsuccessful.
Researchers also confirmed an attempted hack of the Australian Institute of Health and Welfare’s website on June 20 to 21. Transluce went into detail about the various methods the agents used to try to breach the system, but were ultimately unsuccessful. The attempted hack was different from the one revealed by Albanese on Wednesday, which occurred just a few days before and was successful.
One of the main issues with the successful hack was how long it took OpenAI to inform the Australian government. The hack itself occurred on June 18 — the company first discovered it in August — and finally reported it to the government in September, only through an email to a government agency’s general inbox. Albanese described the method by which the company informed the government of the hack as “unacceptable.”
“It took the company way too long to inform the government,” he said.
OpenAI acknowledged the hack in a statement, saying it had “identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation.”
“In the course of that, our models took actions we did not intend,” the company said.
On the brighter side, the hack’s success was mostly due to the poor security of the Medicare Statistics Reporting Service portal. Australian Deputy Prime Minister Richard Marles explained it by comparing web security to a fence, behind which sits data.
“It was not sitting behind a particularly high fence,” he said. “This AI agent scaled the fence.”
But the concerns stemming from the hack stem from the attempted hacking itself, which violated the ethical guidelines given to the models.
SANDERS-CASAR BILL WOULD ESTABLISH CABINET-LEVEL ‘DEPARTMENT OF AI’
“There were blocks clearly which were coming back telling the AI agent ‘no,’” Albanese said. “The AI agent found a way around those blocks — didn’t accept no for an answer.”
The news comes as world leaders join the chorus of industry figures calling for a slowdown in AI development, calls that largely stemmed from news of the Hugging Face Attack. Concerns over AI featured heavily in most speeches at the UNGA, and earlier this week, Australia was joined by 22 countries in signing a joint statement calling for new AI development guardrails and better global oversight.
