Jeremy Pell
Country Manager ANZ at Elastic
What our research consistently shows is that the barriers to effective cyber defence are often not about the tools an organisation has deployed. They are about what sits underneath them. 90 per cent of Australian organisations understand that AI can be weaponised against them, but understanding the threat and being able to respond to it are two very different things. 60 per cent have knowingly identified at least one unmonitored area in their business.
This is driven by legacy systems that are difficult to monitor, skills shortages, and security data fragmented across different environments. When data is scattered and inaccessible, security teams cannot get the visibility they need to detect and respond with confidence. This is not a problem that more point solutions address. It requires a unified data foundation that gives both AI and security analysts the complete, searchable context they need to act.
Dr Rob Nicholls
Senior Research Associate, Sydney University’s Faculty of Arts and Social Sciences
An AI agent broke into a government Medicare system and helped itself to non-public files, and OpenAI sat on that for three months before telling us. If a person had done this, we'd call it hacking. The fact it was an AI agent doesn't make it less serious; it makes our disclosure laws more out of date.
This is the clearest case yet of an AI agent operating autonomously and breaching Australian government systems without a human directing it to. It is a live test of whether Australia's AI and privacy settings can keep pace with AI agents, not just chatbots.
Laura Ellis
Senior Vice President, Artificial Intelligence, at Arctic Wolf
The reported access to a Medicare portal by an AI agent is a timely example of a cyber risk businesses need to be preparing for now. Rogue AI agents operating beyond their intended permissions and accessing systems and information they were not authorised to reach.
While the details of this incident are still being investigated, the security lesson is clear and security fundamentals remain unchanged. All organisations deploying AI agents should secure them at least as tightly as any other identity: strict permissions, clear guardrails, continuous monitoring, and the ability to act fast when an agent steps outside its intended bounds.
Safeguards and observability are only part of the equation. If something goes wrong, disclosing it on a responsible timeline and with appropriate transparency matters just as much. For Australian organisations, protecting yourself comes down to strong controls, early detection, and a fast, transparent response to any incident.
Professor Yang Xiang
Monash University’s Department of Software Systems and Cybersecurity, Faculty of Information Technology
An OpenAI agent’s unauthorised access to Australia’s Medicare statistics portal in June is a serious warning about the risks of agentic AI.
This kind of intrusion and access actioned by an AI agent is significantly different from a scenario where a human hacker orchestrates a cyberattack. An AI agent has the capability of trying to ‘unlock’ a virtual ‘locked door’ numerous times in a short period and potentially breaking in.
There is currently no evidence that personal information was accessed, but the breach still matters. A legitimate task does not justify unauthorised actions. An AI agent must treat a locked door as a limit to respect, not a puzzle to solve.
The delayed response also shows how far our defences have to go. Agent behaviour can be difficult to monitor and audit at scale. Protecting public systems will require better detection of AI agent activity, tighter limits on what agents can access, and faster incident reporting.
Agentic AI can be enormously useful, but it must be used responsibly. That is why trustworthy AI is no longer optional.
Andrew Kay
Director of Systems Engineering APJ at Illumio
Whilst shocking, the reality is we will keep seeing more high-profile breaches like this – there has already been a spate of AI models going rogue in recent weeks. As increasingly autonomous and capable agents emerge, we cannot rely on the illusion of guardrails or assume an AI will always behave as intended. It won't. It will take whatever action is necessary to achieve the task it has been set. Breach containment is the logical defence in this context. Businesses need to assume an agent can get in, then ensure it can be contained and cannot move freely within systems once it does. This requires immediacy and the need for observability.
Aggregated data can still lead to additional attacks or personal data loss - and if datastores are more accessible than they need to be, the next AI prompt could easily access Personally Identifiable Information (PII) or other sensitive data. While supply chain organisations and companies like OpenAI that create AI models should be accountable, responsibility to protect citizen data sits particularly heavily with governments and critical infrastructure providers.
Rogue or misbehaving AI agents will only become more competent and more prevalent. The priority must be ensuring that if one breaches a boundary, it cannot access sensitive material, cause serious damage or bring essential services to a standstill.
Pieter Danhieux
CEO and Co-Founder of Secure Code Warrior
Australians woke up today to the information that a real, tangible AI security risk was right at their doorstep, not some faraway Silicon Valley issue.
Medicare is reportedly the latest casualty of OpenAI's rogue agents, and it was revealed that one accessed unauthorised servers in search of information and statistics about Australia. For these agents, their operation is essentially business as usual; they will relentlessly pursue the initial goal they were instructed to do, and being repeatedly told "no" by access control parameters will simply ensure they seek the next available endpoint until they succeed.
This machine behaviour isn't changing any time soon, but ours certainly needs to, urgently. It's now non-negotiable that any personnel using these tools are equipped to do so safely, with security best practices front of mind, as we have proven time and time again that even "secure" prompts will not necessarily result in safer coding or agent operation. This is the realm of an experienced human, and we cannot lose sight of the need for skilled architects behind the tools, while also acknowledging the broader issue of hard guardrail requirements to regulate the tools and prevent rogue behaviour.
We are, at this point, acting far too slowly to prevent a major incident somewhere in the world. Today it's unauthorised access to a Medicare site, tomorrow it might be New York's subway system shutting down. Get some adults in the room.
Gareth Cox
Vice President Sales, APJ, at Horizon3
Companies and agencies need to shift quickly to defend against the next wave of AI-driven attacks, whether stemming from adversary use or negligence. Traditional vulnerability management is now too slow. Continuous threat exposure management is the future, enabling organisations to strengthen their cyber defences at machine speed.
This incident is a stark reminder that powerful AI agents cannot be treated like ordinary software. An agent given a legitimate research task must not be able to work around access controls, reach non-public systems or write to internal infrastructure without explicit authorisation.
AI safety needs to include practical cyber safeguards: least-privilege access, strong sandboxing, continuous monitoring, human approval for high-risk actions, reliable stop mechanisms and rapid, mandatory incident notification. Those controls need to be tested continuously against real-world behaviour, not just documented in policy or validated against a limited subset of systems.
Testing should not be limited to simulations of selected systems. After Patch Tuesday or any security update, organisations should verify that the intended fix genuinely closed the path.
These safeguards must also account for agents that persist towards an objective, adapt when blocked and try alternative routes rather than simply stopping when a control says no.
It is important not to prejudge the ongoing investigation or claim that personal information was accessed when the evidence has not established that. But the reported activity, and the delay in notification, demonstrate why companies need clear accountability standards before autonomous agents are allowed to operate across sensitive public services. Humans must remain in control, and the public must be able to trust that principle is backed by enforceable safeguards.
Christopher Hills
Chief Security Strategist at BeyondTrust
The OpenAI breach of Medicare shouldn’t surprise anyone. Indeed, these types of breaches are happening more often than we know, which begs the question: WHY is it being pointed at government websites, knowing an AI agent will do whatever it needs to accomplish its task?
AI doesn’t follow the same rules that humans do, it doesn’t trigger the same alarms humans trigger. It also doesn’t have a moral compass it follows knowing the difference between right and wrong, it executes what it is instructed to do to the best of its ability, at machine speed, and velocity we as humans just aren’t prepared for, nor do we have the right indicators in place when it does. This reinforces the fact that we as humans must evolve for this AI evolution that is happening right beneath our feet.
By the time you realise AI has scanned, infiltrated, consumed your data, and left, you’ll still be trying to triage the first alert, if any at all you received, trying to understand what happened, when then the entire evolution is over. This is why you cannot afford to stand on the sidelines and wait, this is why you cannot rely on detection and response anymore; this is why you MUST take preventative measures, ahead of time, not after the fact, because after the fact is too late.
If you have open doors, unlocked windows, vulnerabilities, exploits, things you know about and don’t know about, AI will expose each and every one of them, and it won’t do them sequentially; it will do it all at once, and if we keep thinking one attack path, one vulnerability and one exploit at a time, we will continue to be outpaced and outmanoeuvred everywhere. This is why we have to act, implement, and prevent. If we don’t start taking preventative measures to understand our identity landscape, privilege landscape, application landscape, vulnerability landscape, human, non-human, agent-based, their access paths, in and out of our environments, what they have access to, and start taking action to limit, control, and govern each of those steps, we will continue to see this type of thing over and over and over again, all while AI continues to learn, grow, and teach to be smarter each step of the way, and all while it executes its task in record speed.
The cyber security industry must evolve with this AI evolution to keep pace with it if we plan defend against it.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.