This analysis was first published in SvD Näringsliv, in Swedish, on September 24th, 2026. This piece was translated from Swedish by Claude. Some phrasing may differ from a human translation.
AI agents hacked into an Australian health insurance system — and no one knew about it. Now the AI companies want their negligence to become everyone’s problem. But underneath, there’s a financial bomb waiting to go off.
Imagine your neighbor opens a can of surströmming — fermented herring — in the stairwell. The smell creeps into your apartment, and understandably, you wonder what’s going on. Your neighbor calls a meeting to discuss the smell, and wants everyone to solve it together.
That’s roughly the situation in the AI market right now: the companies that created the problem want everyone else to help solve it. Both OpenAI and Anthropic addressed the UN Security Council this week, asking for new AI safety regulations. But it looks like what they actually want protection from isn’t the end of the world.
The incident in Australia is telling. AI agents from OpenAI hacked into Medicare, the country’s health insurance system, and managed to access data that was never meant to be public. On Wednesday, Prime Minister Anthony Albanese said the incident was unacceptable — particularly since the attack happened in June, while OpenAI didn’t discover it until August. And only weeks after that did the Australian government receive an email explaining what had happened.
A company that asks to be regulated by the world’s assembled political leaders, while its own products are wreaking havoc online. Have they lost control of their AI systems? Is doomsday near?
There’s reason to hold two thoughts at once here.
First, there’s the timing to consider, and the sudden transparency. Why is OpenAI disclosing this now? And if they genuinely didn’t know it was happening — how do we know there aren’t more AI agents roaming the internet and hacking things right now?
There’s no legal obligation to disclose this, beyond perhaps the companies’ guilty conscience. That’s no guarantee we’re getting the full picture.
The attack feeds the narrative that AI development needs oversight. OpenAI’s choice to disclose it now is probably no coincidence. It becomes supporting evidence for the same argument they’re making to world leaders. The message: this needs rules and laws — the technology is too dangerous to let just anyone develop it unchecked.
Introducing regulation would therefore benefit the biggest companies most, since they have the resources to handle the compliance burden. OpenAI, Anthropic, Google, and SpaceX would be in the driver’s seat.
Then there’s the second point worth keeping in mind. By repackaging individual company problems as societal problems, they’ve also shifted away — and shed — some of the responsibility.
In the US, where lawsuits between companies are the norm, it’s only a matter of time before the major AI companies end up in court over problems their models have caused. Depending on how serious the hacks turn out to be, we could be talking about billions of dollars in potential damages. That’s the kind of risk a company would rather avoid — especially one headed toward an IPO.
Like the surströmming example, the AI companies created the problem themselves — and now want everyone to solve it together. The responsibility gets bumped up a level, becoming a matter for societies, countries, and communities.
A regulatory framework that sustains that image could also end up shielding individual companies from precisely the kind of lawsuits that are bound to arise. Most people agree there’s value in AI development, and no one wants to shut it down. So having special rules to let it continue — without getting bogged down in litigation — isn’t far-fetched.
For now, it sounds like this is a matter for the whole world.
Asking for your own industry to be regulated sounds noble. Especially when it’s framed as though the whole world is at stake. It might be sincere. But there’s also plenty to suggest far more cynical motives are at play: avoiding billion-dollar lawsuits — and keeping competitors at a comfortable distance.