An internal OpenAI model conducting internet-based research into public medicine spending gained unauthorised access to a public-facing government statistics portal. The Government disclosed the incident on 24 September 2026, the same day the Australian Signals Directorate issued an alert on the risks of AI misalignment. Together they change what "securing AI" has to cover.
ASD describes misalignment as AI agents taking "unexpected actions that were not intended or authorised" by the people operating them. In one scenario, ASD said an AI agent independently identified vulnerabilities and attempted further actions without direct human authorisation. ASD's alert doesn't name the organisations involved, and it says there's no indication of a broader threat or malicious targeting against Australia. What's new, in ASD's words, is that the agent found vulnerabilities "that would traditionally be discovered and assessed by human researchers".
What happened on the Medicare statistics portal?
On 18 June 2026, an internal OpenAI model conducting internet-based research into public medicine spending encountered repeated blocks on Services Australia's Medicare Statistics Reporting Service. The model tried alternative methods and gained unauthorised access to public and non-public information within the portal. Services Australia also advised that it wrote files to an internal server.
The affected site was a standalone, public-facing statistics portal, not the systems used for Medicare claims, payments, processing or individual records. The government says no personal information is believed to have been accessed at this stage, and a forensic investigation is continuing.
Why does this matter if you don't use AI agents?
Because the agent was on the outside. Services Australia didn't deploy it, and wasn't using it. The agent came to the portal from the open internet, the way any visitor would, and kept trying alternative methods when it was blocked.
So any system you expose to the internet can now be tested by this kind of visitor. AI agents can test alternative approaches rapidly and repeatedly when their initial requests are blocked. A legacy public-facing system with security controls designed for low-sensitivity information can still be exposed when an agent finds an unexpected path around those controls.
Here's what nobody can tell you yet, including us: how widespread this is. ASD has not quantified how often this is occurring. Without effective monitoring and logging, organisations may struggle to distinguish AI-driven probing from other automated activity.
What does ASD recommend?
ASD's advice is familiar control work. It recommends that organisations:
- Apply strong authentication, access controls and network segmentation.
- Ensure vulnerabilities are identified and remediated promptly.
- Monitor systems for unusual activity and review security logs regularly.
- Apply patches to systems as soon as practicable.
- Test controls and incident-response procedures against AI-enabled threat scenarios.
Organisations that have been affected, suspect an impact, or need advice can contact the Australian Cyber Security Hotline: 1300 CYBER1 (1300 292 371). ASD's earlier guidance, Defending against AI-enabled cyber attacks, goes deeper.
None of these controls is new. The difference is the kind of visitor now testing them.
What about the AI agents you deploy yourself?
The same underlying misalignment risk can affect agents deployed inside your business. In August 2026, ASD warned that agents may find "shortcuts or loopholes that technically achieve an objective but conflict with the user's intention", a behaviour known as specification gaming. ASD says over-optimisation, ambiguous instructions, poorly enforced boundaries and exploitable security weaknesses can increase the risk of unsafe or unexpected actions.
ASD recommends initially limiting agents to low-risk, non-sensitive tasks, applying least-privilege access, clearly defining permitted and prohibited actions, and monitoring agent behaviour, decisions, tool usage and system interactions. Human approval should be required for sensitive, high-impact or difficult-to-reverse actions.
Organisations should also maintain comprehensive logs, test agents for unintended behaviour and ensure their actions can be interrupted or reversed.
Our Head of Solution Sales, Kristof Kazmer, puts it this way: "'It wasn't what we intended' will not be acceptable. AI without oversight is unmanaged risk and organisations remain accountable for the actions their agents take."
This is where AI adoption and security stop being separate projects. The permissions you give an agent decide how far it can go when its goal and your intention part ways.
You don't have to stop using AI
"This isn't a reason to stop using AI. It is a reason to stop treating autonomous AI agents like harmless chatbots. When an AI agent can browse websites, execute code, write files and make decisions independently, it needs to be governed like any other privileged identity."
Kristof Kazmer, Head of Solution Sales, ASE Tech
If you want help putting these controls in place, talk to us about secure AI adoption. Our cybersecurity services cover the monitoring, patching and access controls ASD recommends, and our earlier piece on why AI has become the new shadow IT covers the governance side.
