The Weekly Cybers logo

The Weekly Cybers

Archives
Subscribe
July 24, 2026

The Weekly Cybers #126

Open AI’s AI hacks another AI company but everyone’s friends now, Australia lists some priorities for AI safety, and the US sooks about China’s shiny new AI model.

24 July 2026

Welcome

The two big stories this week connect in a curious way: Australia lists some priorities for AI safety just as an AI company’s AI hacks another AI company. It’s a lot to think about.

We’ve also got a shiny new AI model from China, which the Is claims uses stolen technology because of course they do. And much more.

REMINDER: AusAlert will sent a test critical alert to nearly every mobile device in Australia this coming Monday 27 July at 2pm AEST. If you have a secret “safe phone” squirrelled away, remember to turn it off.

“New” AI safety priorities seem oddly familiar

In further policy by press release, and following the announcement last week of a national AI framework, the Australian government has outlined a set of priorities for AI consumer safety.

Once more, your writer has the impression that this series of announcements is really about placating the many Australians opposed to the rapid rollout of AI datacentres. I’m sure you’ve noticed too.

As noted in The Conversation, “These priorities are mostly old policy initiatives that have until now been de-prioritised for months or even years. They sit uneasily under the umbrella concept of AI safety”.

Nevertheless, here are those priorities, copy-pasted straight from the press release:

  • Duty of Care: Legislate a Digital Duty of Care that puts the onus on AI companies to build in safety by design and proactively address potential harm, led by the Minister for Communications.
  • Privacy: Consulting on a second tranche of privacy reform to responsibly strengthen, modernise and simplify Australia’s personal data protection laws, led by the Attorney-General. A robust framework for personal data protection is crucial for both conventional and AI-driven services.
  • AI Safety in the Workplace: Pursue AI safety in the workplace as one of the five agreed priority areas of the tripartite Artificial Intelligence Workplace and Employment Forum, led by the Minister for Employment and Workplace Relations.
  • Consumer Protections: Examine options in Australian consumer law to address consumer risks, such as retail surveillance pricing and agentic commerce, led by the Assistant Minister for Productivity, Competition, Charities and Treasury.
  • Framework for automated decision-making: Develop a framework to better regulate the use of automated decision-making within federal agencies, led by the Attorney-General, recognising the importance of ensuring fair, accurate and transparent government decision-making, including in the context of emerging technologies such as AI.

The ABC’s Cam Wilson made these observations of the prime minister’s speech last week:

“No doubt Albanese hopes that one of the messages that people take away is that Australia is being tough on big tech, dictating our demands if big tech companies want to come Down Under,” he wrote.

“But Albanese’s speech also made another message very clear: Australia wants and needs major AI companies to make major investments here. Assuming you tick a few of these boxes, we’re ready to roll out the red carpet.”

BONUS LINK: John Birmingham has an interesting take on all this.

OpenAI’s AI hacks another AI company, WTF?

Last week American AI company Hugging Face — no really — detected a cyber intrusion on its systems that was clearly being driven by AI. That’s a thing now, as the spooks warned us.

Turns out Hugging Face was being hacked by OpenAI, specifically their new model GPT-5.6 Sol as well as some newer pre-release stuff, which had supposedly gone rogue, as the media put it.

OpenAI was testing their new models in what they thought was a restricted test environment. But a model designed to hack systems ended up hacking the system it was running on, and escaped onto the open internet.

“While operating in our sandboxed testing environment, our models spent a substantial amount of inference compute finding a way to obtain open internet access, in pursuit of solving the evaluation problem [it had been set],” wrote OpenAI in a blog post.

“The primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities,” they wrote.

“The incident also makes clear that advanced models can discover and exploit novel attack paths in real-world systems without source-code access. It highlights that advanced cyber capabilities must be developed alongside stronger safeguards and defensive tools.”

Indeed, Hugging Face deployed their own AI to defence against the attack. And now, as that blog post explains, the companies have teamed up to analyse exactly what happened. Watch this space.

Of course one does wonder why OpenAI’s “highly isolated environment” still had a physical connection to the internet.

And as the Financial Times reports, syndicated via Ars Technica, “Some OpenAI employees also fear it demonstrates that the lab is losing control over the powerful systems it is building, according to multiple people familiar with the situation.”

Scimex has quite a bit of expert reaction too.

WHY NOT SUPPORT THIS NEWSLETTER?: You’re more than welcome to forward these emails to your colleagues, friends, families, and secret intermittent companions. However The Weekly Cybers is currently unfunded. It’d be lovely if you threw a few dollars into the tip jar at stilgherrian.com/tip. Thank you to those of you who’ve already done so.

Also in the news this week

  • Following the recent Telstra outage, which we wrote about last week, the Australian Communications and Media Authority (ACMA) is seeking stronger investigative powers.
  • I haven’t been covering state-level issues, but this one caught my eye. Victoria is introducing laws to force social media companies to reveal the identity of anonymous users accused of “online vilification”. The Conversation looks at how it’ll work.
  • Victoria also wants to protect workers from “inappropriate and unfair uses” of AI in the workplace. This could also be a win for bosses.
  • Queensland will be trialling AI-powered traffic lights later this year, but who will get priority?
  • It’s slightly sideways from the focus of this newsletter, but the Australian government now has a Statement on Space, a “vision for an enduring space ecosystem that supports Australia’s economic resilience and security”.

NEW PODCAST: CHECKING ON THE BINGO CARD: Back at the start of the year, my good friend Snarky Platypus and I created a bingo card for 2026. A set of 25 things that might happen. Well, we’re half-way through the year, so we’ve recorded The 9pm Half-time Bingo Card Update 2026. Look for The 9pm Edict in your podcast app to see how accurate we were.

Elsewhere

  • Beijing-based Moonshot AI has announced a new model called Kimi K3 which it claims can rival OpenAI and Anthropic, except it will be “the world's first open-source model in the three-trillion-parameter class”. Donald Trump’s tech adviser says they stole technology from Anthropic, but experts have pushed back on this sookage, pointing to a lack of evidence. As DW notes, US-China AI rivalry is heating up, and why not have some more strategic analysis from the Australian Strategic Policy Institute (ASPI)?
  • Meanwhile China is trying to ban AI relationships with humans, or as Information Age describes it, introducing “laws preventing AI chatbots designed for companionship from encouraging users to develop emotional dependence on them”. In my experience with humans, they don’t need any encouragement.
  • France is to introduce a social media ban for under-15s, as well as a ban on mobile phones in high schools.
  • “Why are OpenAI and Anthropic cheering on regulation in Australia?” Because certainly leads to better share prices when they eventually float on the stock market.
  • Google has been hit with a €890 million fine for steering users of Google Play and its search engine towards its own services and apps at the expense of others.
  • “Politicians are trying to change what chatbots say about them,” reports the New York Times (gift link), and it looks to be easier than you might think. I’m guessing that also means it’d be just as easy for someone else to change what the AI regurgitates.
  • Someone used AI to make a biography of tech journalist Kashmir Hill, and it’s amusingly wrong. But it also led her to check out the people churning out all those garbage books. (New York Times gift link.) Interesting stuff.
  • Via Pivot to AI, “AI vendors are destroying rare books to feed the chatbot”. Nom nom nom.
  • A hacker has wiped Romania’s entire land registry database, but I’m sure they can just type it back in. As Risky Business explains in that story, they’re not the first European country to have its land registry hacked.
  • American leftist masthead Jacobin presents the socialist case against nationalising AI, a reaction to Bernie Sanders wanting to do so.
  • My attention has been drawn to The Human Consent Registry, “a public, machine-readable record of how AI may use a person's likeness, voice, and movement”. Which is all well and good, but it relies on AI companies actually paying attention to your stated wishes. Still, the Robots Exclusion Protocol is followed by the major web-indexing companies, so maybe it’ll help?

Inquiries of note

Nothing new for us today.

What’s next?

Parliament is currently on its usual long winter break until 11 August, which is two and a bit weeks away.

DOES SOMETHING IN THE EMAIL LOOK WRONG? Let me know. If there’s ever a factual error, editing mistake, or confusing typo, it’ll be corrected in the web archives.


The Weekly Cybers is a personal weekly digest of what the Australian government has been saying and doing in the digital and cyber realms, on various adjacent topics, and whatever else interests me, Stilgherrian, published every Friday afternoon (nearly).

If I’ve missed anything, or if there’s any specific items you’d like me to follow, please let me know.

If you find this newsletter useful, please consider throwing a tip into the tip jar.

This is not a cyber security newsletter. For that that I recommend Risky Biz News and Cyber Daily, among others.

Don't miss what's next. Subscribe to The Weekly Cybers:
Older → The Weekly Cybers #125
Bluesky
Web
Authory
Mastodon
Powered by Buttondown, the easiest way to start and grow your newsletter.