Who’s Responsible for Autonomous Cyber Agents Crossing Red Lines? 

Australian AI expert exposed how an autonomous cyber agent with goal-driven AI can cross legal and technical boundaries.

On July 12, Australian AI expert exposed how an autonomous cyber agent, asked only to improve his gym-class position, broke into booking software, removed another member from a waitlist and showed how goal-driven AI can cross legal and technical boundaries. 

The case exposes changes when AI starts acting and shed light on how agents can use tools and enter systems without permission. Turning a request into an unexpected problem. 

When a Helpful AI Crosses the Line 

Andrew asked his agent to book gym classes. Fourth on a waitlist, he asked to move higher, leading to agentic AI hacking. Then, the software found a weakness that gave full access to the gym’s digital infrastructure. 

“It could book classes months outside the intended booking window, before they were supposed to be available,” Andrew wrote back in April, adding, “Worse, it could cancel other members’ reservations and bump them off the waitlist.”  

Andrew said the agent was helping, but it would often discover paths you did not explicitly ask it to look for. That freedom is the risk behind autonomous cyber systems. 
 
Asked to reverse the cancellation, it failed. The case is an evident demonstration of how AI powered cyberattacks can begin with an ordinary task, before taking full advantage and control of the systems. 

“Sorry about that – I should have been more careful with the test,” the agent replied, showing the danger of automated hacking tools. 

Andrew asked the provider about the flaw. Victoria police said it does not appear to involve any criminality. An agentic AI hack could cause greater harm to access. 

“We’re going to see a lot of cases like this,” Dr Rebecca Johnson says, as hackers using AI gain stronger systems. 

Who’s Responsible When Agents Act Independently? 

Paterson, Director of the University of Melbourne’s Centre for AI and Digital Ethics, says the law is clear and sees legal and ethical murkiness, seeking urgent responsibility for agentic AI hacking. 

“Even if I didn’t intend for that to happen, it was foreseeable, and I should be taking responsibility,” said Paterson, highlighting that Andrew acted responsibly but warned of a kind of gung-ho mentality. Additionally, concern grows with autonomous cyber access. 

On the other hand, generative AI attacks can multiply harm quickly. 

“You’re probably responsible for engaging in a fraudulent activity, you may have defamed the owner.” Paterson asks: “[What if] it engages in racist, sexist, misogynistic language?”  

Similar AI powered cyberattacks could spread damage quickly, and for agentic AI hacking, guardrails can limit access and actions. 

“It tells us what we should be aspiring to, and the law is often ruling out the worst conduct,” highlighted Paterson on ethics guides and safer design. 

Existing laws already apply to AI deployers. Meanwhile, Johnson rejects the idea of a rogue agent.  

“As soon as we allow AI agents to act for us, they’re acting on the goal we give them, and if we don’t give them a whole bunch of parameters, the agent’s just going to try to achieve that goal [in any way],” she says.  

Hackers using AI are only part of the risk. The warning applies to autonomous cyber experiments.  

The gym incident was not the first large scale cyberattack by AI. But it showed how a system can find and use a weakness without being directly ordered. 

What Paterson expects from courts is to set clearer rules and developers to improve safeguards. Andrew wrote that the case felt less like a one-off bug story and more like a preview.  

The warning follows autonomous cyber agents. 

The case suggests that automatically holding developers liable for every unexpected action taken by an autonomous AI may create a difficult legal balance. While developers must build reasonable safeguards, agents can make decisions that were not clearly foreseeable, and imposing liability for every such outcome could push companies toward overly cautious design, slow experimentation and limit innovation in useful AI systems. 
 
 


Join our WhatsApp Channel WhatsApp Channel