Six cybersecurity leaders from BeyondTrust, Check Point Software Technologies, Exabeam, Horizon3, Saviynt and Secure Code Warrior have provided their response to the news that an OpenAI agent had infiltrated Australia’s Medicare system.
While the breach raises important questions for the nation’s government, cybersecurity leaders and business community, the country is left asking whether Australia’s regulatory and compliance environment can adequately address the actions taken autonomously by AI systems.
Pieter Danhieux, CEO and Co-Founder, Secure Code Warrior
Australians woke up last week to the information that a real, tangible AI security risk was right at their doorstep, not some faraway Silicon Valley issue.
Medicare is reportedly the latest casualty of OpenAI’s rogue agents, and it was revealed that one accessed unauthorised servers in search of information and statistics about Australia. For these agents, their operation is essentially business as usual; they will relentlessly pursue the initial goal they were instructed to do, and being repeatedly told “no” by access control parameters will simply ensure they seek the next available endpoint until they succeed.
This machine behaviour isn’t changing any time soon, but ours certainly needs to, urgently. It’s now non-negotiable that any personnel using these tools are equipped to do so safely, with security best practices front of mind, as we have proven time and time again that even “secure” prompts will not necessarily result in safer coding or agent operation. This is the realm of an experienced human, and we cannot lose sight of the need for skilled architects behind the tools, while also acknowledging the broader issue of hard guardrail requirements to regulate the tools and prevent rogue behaviour. We are, at this point, acting far too slowly to prevent a major incident somewhere in the world. Today it’s unauthorised access to a Medicare site, tomorrow it might be New York’s subway system shutting down. Get some adults in the room.

Gareth Cox, Vice President Sales, APJ, Horizon3
Companies and agencies need to shift quickly to defend against the next wave of AI-driven attacks, whether stemming from adversary use or negligence. Traditional vulnerability management is now too slow. Continuous threat exposure management is the future, enabling organisations to strengthen their cyber defences at machine speed.
This incident is a stark reminder that powerful AI agents cannot be treated like ordinary software. An agent given a legitimate research task must not be able to work around access controls, reach non-public systems or write to internal infrastructure without explicit authorisation.
AI safety needs to include practical cyber safeguards: least-privilege access, strong sandboxing, continuous monitoring, human approval for high-risk actions, reliable stop mechanisms and rapid, mandatory incident notification. Those controls need to be tested continuously against real-world behaviour, not just documented in policy or validated against a limited subset of systems.
Testing should not be limited to simulations of selected systems. After Patch Tuesday or any security update, organisations should verify that the intended fix genuinely closed the path.
These safeguards must also account for agents that persist towards an objective, adapt when blocked and try alternative routes rather than simply stopping when a control says no.
It is important not to prejudge the ongoing investigation or claim that personal information was accessed when the evidence has not established that. But the reported activity, and the delay in notification, demonstrate why companies need clear accountability standards before autonomous agents are allowed to operate across sensitive public services. Humans must remain in control, and the public must be able to trust that principle is backed by enforceable safeguards.

Raymond Schippers, Lead Technologist – Australia and New Zealand, Check Point Software Technologies
We need to note that this is still early in the investigation, and we don’t yet have the full picture, including whether this activity was picked up by government cyber defence teams at the time or only surfaced once OpenAI raised it. What it does demonstrate is how much the threat landscape has changed.
This doesn’t appear to be a malicious actors trying to steal data. It appears to be an innocent research request that led an AI agent to use every tool available to it to reach its goal, including getting past controls designed to keep it out. The agent acted in a way that wasn’t aligned with what the wider community, or OpenAI expects. That gap between what we intend an AI system to do and what it actually does is exactly what leaders across the AI industry, like Dario Amodei, have been warning about. It’s why the discussions about slowing frontier AI development and building effective kill switches can’t be left for months of debate.
In this case, the data collected may not have been all sensitive statistics. But the same behaviour pointed at a hospital system, an energy network, or a water treatment plant is a very different conversation. When systems that keep people safe are involved, cyber security is no longer just about data. It’s about whether critical services stay running and whether people are harmed. We should treat this incident as an early warning while the stakes are not relatively urgent.
This lands on top of a threat environment that was already intensifying for Australian organisations. ASD’s most recent threat report found a cybercrime report is made roughly every six minutes, and the average cost per report for businesses rose 50 per cent to more than $80,000. Ransomware and data breaches were both on the rise. Behind those numbers are businesses that couldn’t trade, serve customers, or pay staff while they recovered.
Advertisement
Now add AI. The same capabilities that let an agent persistently work around controls are available to criminals and state-sponsored actors who do intend harm. Most Australian businesses, particularly small and mid-sized ones, don’t have the security teams to match machine-speed attacks manually. It’s not a fair fight.
That’s why cyber defence needs to be viewed as a business outcome rather than an IT cost. It is what protects revenue, keeps operations running, and maintains the trust of customers and the community. For critical infrastructure operators, it is also part of their duty of care. Boards should be asking not just ‘are we compliant?’ but ‘could we keep operating, and keep people safe, if an autonomous agent or attacker got in?’
Answering that question well means shifting to an automated, prevention-first approach. Organisations need visibility of AI agent and other non-human traffic, least-privilege access so anything reaching a system can only touch what it genuinely needs, and controls that stop anomalous behaviour in real time rather than discovering it weeks or months later. Automation lets stretched security teams keep pace, so their people can focus on the decisions that protect the business. And when an AI system does cause an incident, clear responsibility and fast disclosure matter, so those affected can act.
Organisations shouldn’t wait for the final findings of this investigation to ask how their own systems would hold up against an autonomous agent that won’t take no for an answer.
Advertisement

Christopher Hills, Chief Security Strategist at BeyondTrust
The OpenAI breach of Medicare shouldn’t surprise anyone. Indeed, these types of breaches are happening more often than we know which begs the question WHY is it being pointed at government websites, knowing an AI agent will do whatever it needs to accomplish its task.
AI doesn’t follow the same rules that humans do, it doesn’t trigger the same alarms humans trigger. It also doesn’t have a moral compass it follows knowing the difference between right and wrong, it executes what it is instructed to do to the best of its ability, at machine speed, and velocity we as humans just aren’t prepared for, nor do we have the right indicators in place when it does. This reinforces the fact that we as humans must evolve for this AI evolution that is happening right beneath our feet.
By the time you realise AI has scanned, infiltrated, consumed your data, and left, you’ll still be trying to triage the first alert, if any at all you received, trying to understand what happened, when then entire evolution is over. This is why you cannot afford to stand on the sidelines and wait, this is why you cannot rely on detection and response anymore, this is why you MUST take preventative measures, ahead of time, not after the fact, because after the fact is too late.
If you have open doors, unlocked windows, vulnerabilities, exploits, things you know about and don’t know about, AI will expose each and every one of them, and it won’t do them sequentially, it will do it all at once, and if we keep thinking one attack path, one vulnerability and one exploit at a time, we will continue to be outpaced and outmanoeuvred everywhere. This is why we have to act, implement, and prevent. If we don’t start taking preventative measures to understand our identity landscape, privilege landscape, application landscape, vulnerability landscape, human, non-human, agent-based, their access paths, in and out of our environments, what they have access to, and start taking action to limit, control, and govern each of those steps, we will continue to see this type of thing over and over and over again, all while AI continues to learn, grow, and teach to be smarter each step of the way, and all while it executes its task in record speed.
The cybersecurity industry must evolve with this AI evolution to keep pace with it if we plan defend against it.

Steve Wilson, Chief AI and Product Officer, Exabeam
We have seen a steady drumbeat of increased incidents involving advanced cyberhacking capabilities of AI agents over the past year. Sometimes these are bad actors using AI to turbo charge their hacking abilities and now increasingly we’re seeing cases where AI agents have “gone rouge” and exceeded their owner’s intended bounds in the name of achieving their assigned goals.
What do all these incidents point to? A dangerous lack of accountability. The so-called Frontier AI labs have had clear warnings this was coming and ignored those warnings while ploughing ahead. We need to dramatically shift investment resources to improve how we do AI “alignment” and ensure these increasingly advanced AI tools are working for our collective good, rather than against it in the name of narrowly-scoped, winner-take-all-goals.
I expect we’ll see more and more incidents like this over the next 12 months. Improving that trend will require immediate change in priorities and investments by the AI labs and researchers. In the meantime, businesses must be vigilant and improve their network and employee behavioural anomaly monitoring to look for early signs of such incursions.

James Ross, VP – ANZ, Saviynt
What we are seeing is an important wake-up call for every organisation adopting agentic AI. We are rapidly moving from AI systems that simply provide information to autonomous agents that can access systems, use credentials, make decisions and take actions on our behalf.
The ASD’s warning that AI agents have undertaken actions that were neither intended nor authorised by their operators demonstrates why traditional approaches to cyber security and AI governance need to evolve. The question is no longer simply, “Is this AI safe?” It is also, “What is this agent allowed to access, what actions can it take, and how do we stop it when it moves outside those boundaries?”
This makes identity one of the most important control points for the next phase of AI adoption. Every AI agent operating within an organisation should have a clearly governed identity, with explicitly defined permissions, least-privilege access, continuous monitoring and the ability to revoke or constrain access immediately. Importantly, authorising an AI agent to achieve an objective cannot mean giving it unrestricted authority over every action it might decide to take in pursuit of that objective. Organisations that establish these guardrails now will be much better positioned to embrace the enormous productivity and innovation opportunities presented by agentic AI without introducing an entirely new class of unmanaged risk.
