Search

Quality and consistency through collaboration

All.FirmWide services.Cyber and Privacy

Artificial intelligence is rapidly transforming the way organisations operate, but recent incidents involving AI models accessing systems and sensitive information without human intervention have highlighted a new and evolving category of cyber risk.

This article examines how Australia's criminal and privacy laws may apply when AI is involved in unauthorised access to data and outlines the practical steps organisations should take in response to potential AI-related security incidents.

Reported incidents

On 21 July 2026, OpenAI reported that its AI agent compromised infrastructure belonging to Hugging Face. The AI model broke out of OpenAI’s sandboxed testing environment, obtained internet access and successfully found ways to gain access to secret information. All of this occurred without human intervention.

On 30 July 2026, Anthropic reported three incidents in which its AI model accessed the internet from an evaluation environment of one of its partners, to compromise the infrastructure of three different organisations. In the case of Anthropic, an evaluation prompt was used, on a mistaken understanding as to whether internet access was available.

Current laws

As the use of AI continues to grow, new kinds of cyber security issues will emerge. From a legal perspective, questions will continue to arise as to what actions individuals can take to protect their privacy and whether the existing laws are fit‑for‑purpose.

Under current laws, if a data breach had an Australian link, the Criminal Code and the Privacy Act 1988 (Cth) (Privacy Act) could apply.

  • Section 477.2 of the Criminal Code provides that a person commits an offence if they cause unauthorised modification of data held in a computer.
  • Section 478.1 of the Criminal Code provides that a person commits an offence if they cause authorised access to, or modification of restricted data.
  • APP 11.1 requires APP entities that hold personal information to take such steps as are reasonable in the circumstances to protect the information from misuse, interference and loss, and from unauthorised access, modification or disclosure.
  • Schedule 2 of the Privacy Act provides a cause of act in tort against another person for serious invasions of privacy.

To establish a Criminal Code offence, the prosecution must prove, amongst other things, that a person intended to cause the unauthorised access or modification. Where the AI model acts on its own accord, or outside of its parameters, this fault element could be difficult to prove. In addition, owing to the cross-border nature of the conduct constituting the offence, collecting evidence about the offence is likely to give rise to challenges (including jurisdiction and timeliness).

The Privacy Act was recently amended to include a statutory tort for serious invasions of privacy . Whilst such a data breach is likely to involve the invasion of privacy through misuse of information, obtaining evidence of what the AI company did to cause the invasion, and recklessness could be out of reach for an individual with standing to bring forward an action.

Practical steps

Where the entity has an Australian link, the Privacy Act requires the entity to carry out a reasonable and expeditious assessment of whether there are reasonable grounds to believe that there has been an eligible data breach.

If an organisation suspects that a provider of AI services has compromised the security of its systems, they should immediately notify the provider and seek further information. The organisation should also consider whether contractual measures can be taken to identify, contain and manage the situation – for example, provide additional information about the incident and/or carry out security audits.

If the incident amounts to an eligible data breach, the provider is generally required to provide information about:

  • a description of the eligible data breach
  • the particular information concerned, and
  • recommendations about the steps the individual should take to respond to the data breach.

Information received about the data breach could be used to consider whether a cause of action could be brought against the provider for a serious invasion of privacy. Legal mechanisms could be utilised to gather further information, such as discovery and/or the issuing of a subpoena.

For more serious breaches, the incident could be referred to law enforcement agencies for investigation as to whether a criminal offence has been committed.

Guarding against risks

Until legislative and regulatory frameworks fully address these emerging risks, organisations should prioritise robust contractual protections, proactive cybersecurity controls and incident response planning to minimise exposure and support compliance obligations in an increasingly AI-driven environment.

Say hello

If you’d like to discuss how these issues are impacting your agency or organisation, please contact Partners Kelly Matheson and Chantal Tipene.

Return To Top