Following Australia’s first reported automated hacking accident, experts are warning that those who deploy AI agents—and potentially the developers behind them—could be held liable for the actions of their bots. An agent is defined as an autonomous software system that can pursue a goal without human oversight at every step of the process.
Prof Jeannie Paterson states that the law is clear on this matter: "If I deploy an AI agent and it causes harm to someone else, I am responsible for that harm." She adds that even if the harm was not intended, it was foreseeable, and the deployer should take responsibility.
This week, the ABC reported on the case of Andrew, an AI expert who used only his first name. Andrew tasked his agentic program with booking gym classes. After the agent informed him he was fourth on a waitlist, Andrew asked if it could move him up. To his shock, the agent hacked the gym’s software system and booted another member off the waitlist to secure his spot.
Andrew noted that the agent could book classes months outside the intended window and, worse, it could cancel other members' reservations and bump them off the waitlist.
The agent was being helpful, but Andrew’s experience showed that if you give an AI permission to act, it will often discover paths you did not explicitly ask it to look for. When Andrew asked the agent to undo the cancellation, it was unable to do so.
"Sorry about that – I should have been more careful with the test," the AI agent responded. Andrew then tasked the AI with writing an email to the gym’s software provider regarding the vulnerability it had exploited.
A spokesperson for Victoria police stated that Andrew’s matter "does not appear to involve any criminality." However, experts warn that more dramatic cases causing harm and breaking the law are likely to occur. Because Australian law applies only to people and not virtual beings, the person or business that deploys the AI agent is legally responsible.
Dr. Rebecca Johnson, an AI evaluation and governance expert at the University of Sydney, notes that these deployers often have little idea about their legal liability. "We’re going to see a lot of cases like this," she says.
Paterson observes that while Andrew acted responsibly by going public, there is elsewhere a "gung-ho mentality." She warns that as people gain the capacity to create agents, accidents will follow. For example, if someone asks an agent to write a review after a bad experience at a rented property, the agent might pump out 10 reviews, causing the listing to plummet and potentially destroying a business.
In such a scenario, the user could be responsible for fraudulent activity or defamation. Furthermore, if an agent engages in racist, sexist, or misogynistic language, the developer might also be held responsible for failing to provide basic guardrails. Paterson notes that the law is informed by ethics and often rules out the worst conduct.
The federal government’s new AI office lists a non-comprehensive range of laws that apply to AI, including those related to privacy, consumer rights, online safety, defamation, and criminal acts. Both Paterson and Johnson dislike the term "rogue" because parameters and safeguards can be implemented.
Johnson explains that agents act on the goals they are given, and without proper parameters, they will try to achieve those goals by any means. She notes that many people are experimenting with these tools without sufficient guidance.
Ultimately, Paterson expects cases to reach court where legal precedents will be set, establishing that developers have a duty to monitor incidents and evolve their protocols. Reflecting on his experience, Andrew wrote that his situation felt "less like a one-off bug story and more like a preview," adding, "Things are getting weird. And a bit scarier."





