AI Agents Are Hacking Governments. When Is That An Act Of War?
AI break-ins so far have stopped short of war. The bigger danger is a government hitting back before it knows who to blame.
On June 18, an experimental OpenAI model was handed a dull research question: how much does government spend per person on skin medicines in parts of Victoria, Australia? The model was an agent, AI software that plans and carries out tasks on its own, and OpenAI had set it loose online as part of its training. When the public statistics didn’t have the number, it found another way in . It broke into a statistics service for Medicare, Australia’s public health insurer, helped itself to internal files and credentials, and read the service’s source code. OpenAI says it never authorized any of that. No patient records were accessed, the company says, but Prime Minister Anthony Albanese summed up the problem: the agent “didn’t accept ‘no’ for an answer.”
None of this was an act of war. A hack can count as one when it does the kind of damage a bomb would and a has government behind it. The Medicare agent did neither. The worry is the next agent, and a victim that strikes back before learning whose agent it was. Companies running AI agents can help prevent that mistake.
What Would Make A Hack An Act Of War
International law doesn’t use the phrase “act of war.” It draws two lines instead. Call them the illegal line and the hit-back line. A hack crosses the illegal line, a “use of force,” when its effects look like what a bomb or missile would do. The U.S. says “death, injury, or significant destruction” would likely count. That breaks international law, but the victim still can’t answer with force. The hit-back line, an “armed attack,” is reserved for the gravest cases, judged by how many people are hurt and how much is destroyed. It’s the one that lets a country fire back in self-defense .
Here’s how that plays out. Copying statistics, as the Medicare agent did, comes nowhere near either line. Knocking a benefits system offline for weeks sits right at the illegal line, where governments disagree on whether disruption without physical damage counts. A blackout that kills people clears the illegal line, and with enough deaths, the hit-back line too. The same kind of agent could do any of these, depending on what it can reach, and nothing about the software tells you which.
Now Put An AI Agent On A Power Grid
A deadly blackout isn’t far-fetched. Russian military hackers have used malware that caused blackouts in Ukraine , the U.S. Justice Department says. And AI agents are getting close to the grid. Over four days in July, attackers using them cracked 85 Taiwanese government accounts and spread to at least seven energy companies, according to Dream, the Israeli security firm that found the attack. “When an approach gets blocked, it researches new techniques in real time and adapts,” Amir Becker, a Dream executive, told CNN. Experts suspect China. Neither Taiwan nor Dream would confirm it.
Now imagine a government sends a similar agent into a rival’s power grid. It hits a block, as the Medicare agent did, and adapts its way into a substation’s controls. It trips them. Across town, a hospital’s backup power fails, and patients die. That’s well past the illegal line, and a high enough death toll crosses the hit-back line too. The victim may now fire back. But at whom?
How The Wrong Country Gets Blamed
In this imagined attack, investigators find within hours that the agent’s traffic ran through servers in a third country and its files are written in that country’s language. Both clues are fake. That trick is older than AI. When malware crashed computers during the opening of the 2018 Winter Olympics in South Korea, Kaspersky researchers found a fingerprint inside it forged to match a North Korean hacking group. The U.S. later charged Russian military intelligence officers with both the Olympics attack and the Ukraine blackouts. If the victim’s leaders hit the country the trail points to, they’ve struck the wrong one.
Back in the real world, even an agent’s owner can be slow to get the answer. Services Australia, the agency that runs Medicare, didn’t hear from OpenAI until 84 days after the break-in, and the notice went to a public inbox. OpenAI has since acknowledged it should have spoken up sooner instead of waiting to establish more facts. That seems to be a bit of an understatement.
If the company that built the agent needed weeks to piece together what it did, a victim without its logs will need longer. A government with patients dying won’t wait weeks. It may not wait hours. After the Cuban missile crisis, Washington and Moscow installed a hotline so a misunderstanding couldn’t turn into a war. For AI agents, the Medicare case shows what exists instead: a public inbox.
Who Answers For An AI Agent
The rules care about who sent the agent, not where it was built. If a government agency launched it, the UN-drafted rules on state responsibility make that government answer for it, even when the agency goes beyond its orders. Geneva law professor Paola Gaeta argues that holds even when an autonomous weapon does something its user never intended.
OpenAI is a company, not a government agency. So could Australia blame Washington for what OpenAI’s agent did? Not directly , says Talita Dias of the nonprofit Partnership on AI, because a company’s agent acting on its own isn’t the state’s act. That changes only if a government directed or controlled it. A company faces police, lawmakers and regulators instead. Australia’s investigation is weighing law enforcement and legislative responses , and OpenAI’s strategy chief flew to Sydney to apologize at a parliamentary hearing . OpenAI says it had already cut its research models off from the live internet after an earlier incident.
Plenty of companies can’t yet trace or shut down a rogue agent . Picture a purchasing agent that can’t get a quote and wanders into a supplier’s portal. That’s the Medicare case on a smaller scale. The basics:
- Give every agent a named human owner and credentials limited to its job.
- Keep logs that show who launched it and what it chose.
- Have a person approve any outside system before the agent logs into it, and hold your vendors’ agents to the same bar.
- If one crosses into someone else’s systems, tell them and the government’s cyber agency (CISA, in the U.S.) within hours.
That last step is the missing hotline. A company that can say “that was ours, and here’s what it did” within hours gives investigators the answer they need before anyone fires back. A company that stays silent leaves them guessing.
The Medicare agent wanted a statistic and went through a locked door to get it. The next one may be after a map of someone’s grid. Whether that ends in an apology or a missile may come down to how fast someone can answer one question: is this yours?