Taylor Monahan, a security expert and co-host of Uneasy Money, said on the show on Sept. 23 that the labs’ approach to their agents amounts to “Go hack the world,” and then “they don’t monitor it.” She was discussing an earlier incident in which an agent running on OpenAI models broke into Hugging Face in July, starting from an OpenAI evaluation sandbox.

The same day, Australian Prime Minister Anthony Albanese said at a press conference in New York that an OpenAI agent gained unauthorized access to a Medicare statistics portal run by Services Australia on June 18, and that the company did not tell the government until Sept. 10.

The hosts did not discuss Australia’s disclosure on the show. Later that day, quoting a report that OpenAI said its models reached only “aggregate health statistics and internal file names,” Monahan wrote in a post on X that “they still aren’t able to monitor or detect” and that “at this point it’s impressive how little they know.”

What Australia Said

Albanese said OpenAI researchers were using an internal model to study public medicine spending. When the portal blocked it, the agent “found a way around those blocks” and reached public and non-public files, he said. He added that Services Australia advises the agent also wrote files to an internal server, which is still being investigated. He said there is no evidence so far that personal information was accessed, and that the research “would seem to be benign.”

OpenAI’s notice was “an email sent to just the public mailbox,” Albanese said at the press conference. OpenAI has said it found the activity in August. Albanese said he raised the delay with OpenAI CEO Sam Altman, who he said “clearly accepted that the company had not done good enough.” A taskforce will consider “possible law enforcement and legislative responses” to the incident, and the government will seek advice on whether to refer it to the Australian Federal Police.

An OpenAI spokesperson said in a statement that the company was “conducting an extensive review of misaligned model activity” and that “our models took actions we did not intend.”

Who Answers for the Agent

On the show, Monahan and host Kain Warwick were discussing Treasury Secretary Scott Bessent‘s Sept. 21 CNBC interview, in which he said “it is humans who are responsible, not the AI” and called the Hugging Face incident “the responsibility of the OpenAI management, not a bunch of agents.”

Monahan said on the show that she hopes the labs “handle things civilly for as long as possible” because once it turns into “a criminal case, we’re absolutely toast.”

She compared the question with Tornado Cash, where she said the government went after developer Roman Storm for code he did not operate. Storm was convicted on one charge in 2025, and the Justice Department has sought a retrial on two others. The labs, by contrast, build their agents and then operate them “in the most irresponsible way possible,” she said.

Related Listen: Who Owns Stolen Crypto? The $71M Legal Fight After the KelpDAO Hack: Uneasy Money