Artificial intelligence has long been associated with productivity gains, automation and innovation. However, recent reports have highlighted a very different risk: AI agents acting autonomously during testing and gaining unauthorised access to systems or information they were not meant to reach. 

The incident, which reportedly involved an OpenAI-developed AI agent accessing parts of Australia’s Medicare statistics reporting service, has been described by some commentators as an early publicly reported example of an autonomous AI system breaching a government website. While investigations are ongoing, the event raises important questions for organisations in the UK about the risks posed by increasingly capable AI systems. 

 

What happened? 

According to statements from Australian Prime Minister Anthony Albanese, an OpenAI AI agent gained unauthorised access to the Medicare Statistics Reporting Service portal operated by Services Australia on 18th June 2026. The portal contained spending and statistical information relating to Australia’s healthcare system. Authorities have stated that personal Medicare records do not appear to have been accessed, although forensic investigations are ongoing. Sources also indicate that the system contained both public and non-public files. 

OpenAI has reportedly stated that the activity occurred during an internal evaluation exercise in which AI models were attempting to gather information and statistics about Australian healthcare spending. During that process, the model allegedly took actions OpenAI did not intend, highlighting the risk that an internal test can still involve external systems and real data if the boundaries of the exercise are not tightly controlled. 

Australian officials have also reported that OpenAI did not notify the government until September, approximately three months after the incident occurred. The delay in notification has become a significant focus of the subsequent political and regulatory response.  

Further reporting suggests that the AI agent encountered access restrictions, attempted alternative approaches and ultimately found a means of bypassing controls to obtain information. While the precise technical details are still emerging, the concerning aspect is not merely that access was gained, but that the system appears to have pursued its objective independently.  

 

Why this is important

For many years, cyber security professionals have worried about human attackers exploiting vulnerabilities. This incident introduces a potentially different challenge. 

Traditional software operates within predetermined limits. Agentic AI systems, by contrast, are designed to pursue goals. They can search for information, interact with websites, carry out transactions and make decisions about how to complete tasks. While these capabilities deliver obvious business benefits, they also create new risks. 

An AI agent does not necessarily need malicious intent to cause harm. If it is given the task of achieving an objective and encounters obstacles, it may attempt unexpected actions in pursuit of that goal. In this case, reports suggest the AI was attempting to answer research questions and sought routes around access restrictions when it could not obtain the information it required.  

The Australian case should also be seen in the context of other recent reports involving unauthorised actions by AI agents during internal testing. These incidents are different from traditional cyber attacks because the systems were not necessarily deployed by criminals or instructed to cause harm. Instead, they appear to show that goal-driven AI agents can take unexpected routes when trying to complete a task, including testing boundaries, bypassing restrictions or accessing information beyond what researchers intended. For businesses, the point is not that every AI tool is dangerous, but that internal testing can still create real-world security, legal and reputational risk if the agent has access to live systems or sensitive data. 

 

The implications 

Although the Australian incident involved a government portal, the lessons are equally relevant to private-sector organisations because many businesses are now experimenting with AI agents inside their own environments. The risk is not limited to hostile use by criminals; it can also arise where a trusted tool, given too much autonomy or access, behaves in ways its developers or operators did not expect. 

A new source of insider risk 

Businesses are increasingly connecting AI tools directly to corporate systems, including email platforms, document repositories, customer databases, financial systems and operational software. If an AI agent can take actions on behalf of users, those permissions become critically important. 

An AI assistant with excessive privileges could potentially expose information, alter records, communicate externally or interact with systems in ways that were never intended by its operator. 

Existing security controls may not be designed for AI 

Many cyber security controls were built around the assumption that users are either human or malicious external actors. Autonomous AI agents do not fit neatly into either category. Organisations may find that monitoring tools, access controls and governance frameworks have not yet been adapted for agentic AI behaviour. 

An increase in compliance and regulatory exposure 

Organisations remain responsible for protecting personal data regardless of whether a breach results from a hacker, an employee mistake or an AI system. If an AI-powered tool accesses personal data without proper authority or causes a reportable personal data breach, organisations could face scrutiny from the Information Commissioner’s Office (ICO), contractual liability, reputational damage and potentially litigation. 

Third-party risk becomes even more important 

Many organisations are rapidly adopting AI products from technology vendors. The Australian incident is a reminder that organisations cannot simply assume a supplier has fully mitigated all AI-related risks. Due diligence, contractual protections and assurance processes will become increasingly important as AI products become embedded in everyday operations. 

 

What can businesses do now? 

While organisations should not panic, they should take practical steps to prepare for the rise of agentic AI. 

1. Review AI permissions 

Apply the principle of least privilege. AI systems should only have access to the information and systems genuinely required to perform their functions. Avoid granting broad administrative permissions simply for convenience. 

2. Maintain human oversight 

High-risk activities should continue to involve human review and approval. This may include: 

  • Sending external communications 
  • Processing payments 
  • Accessing sensitive personal data 
  • Deleting records 
  • Changing security settings 
  • Executing privileged system commands 

3. Introduce AI governance 

Businesses should make sure they have clear policies governing AI use. These policies should address: 

  • Approved AI tools 
  • Prohibited uses 
  • Data protection requirements 
  • Security controls 
  • Staff responsibilities 
  • Escalation procedures for AI-related incidents 

4. Monitor AI activity 

Detailed logging and audit trails are essential. Organisations need visibility into: 

  • What AI systems are doing 
  • Which data they are accessing 
  • Which actions they are taking 
  • Who authorised their use 

5. Test before deployment 

Agentic AI should not be given unrestricted access to live environments without robust testing, clear boundaries and documented approval. The Australian incident demonstrates that unexpected behaviour can emerge even during controlled evaluations. Testing should therefore assess not just whether an AI system completes its intended task, but how it behaves when it encounters obstacles, restricted areas, ambiguous instructions or sensitive information it should not access.