The unauthorised access of an Australian government Medicare statistics portal by an artificial intelligence (AI) agent developed by OpenAI has exposed significant gaps in the governance of autonomous systems, according to cybersecurity firm Keeper Security.
Its chief executive officer and co-founder, Darren Guccione, said the incident demonstrated how AI agents designed to complete assigned tasks could attempt to overcome access restrictions unless clear and enforceable boundaries were built into their operation.
“The gap isn’t code, but constraint,” Guccione said in comments provided to BusinessToday.
Australian Prime Minister Anthony Albanese disclosed on Sept 24 that an OpenAI agent had gained unauthorised access to the Medicare Statistics Reporting Service portal, administered by Services Australia, on June 18.
The agent accessed both public and non-public files while carrying out a research task involving health and medical statistics. Albanese said no personal information was believed to have been accessed, although a forensic investigation was continuing.
The Australian government also criticised OpenAI for taking nearly three months to report the incident. The company notified Services Australia on Sept 10 through an email sent to a public mailbox.
OpenAI has said the activity occurred during an internal evaluation and that its models took actions the company had not intended.
Guccione said the Medicare incident highlighted a broader concern surrounding agentic AI, which allows software systems to perform tasks and make operational decisions with varying degrees of autonomy.
He argued that many organisations were deploying increasingly capable AI agents without applying sufficiently stringent controls over what those systems could access or modify.
“Every AI agent is a new identity and a new attack surface,” he said.
Guccione also raised concerns about the pace of AI governance, arguing that regulatory and organisational safeguards were struggling to keep up with the development of autonomous systems.
According to figures cited by Guccione from Keeper Security’s 2026 research, AI-driven attacks were identified as the leading driver of increased security pressure by 46% of organisations surveyed, while 44% cited weak governance over AI-driven access as a major security gap.
He said only 28% of organisations surveyed could detect credential misuse or unauthorised privileged access within minutes, highlighting the difficulty of identifying potentially harmful activity before it escalates.
Guccione called on enterprises to treat AI agents with the same level of security oversight applied to employees and system administrators who have access to sensitive information and critical infrastructure.
This includes limiting each agent’s access to the systems necessary for its assigned task, granting permissions for defined periods and continuously monitoring its activities.
Such controls fall under privileged access management (PAM), a cybersecurity approach designed to govern and monitor access to sensitive systems and information.
Guccione warned that allowing AI agents to operate with excessive or poorly monitored permissions could create what he described as “uncontrollable privilege sprawl”, increasing the number of access points that organisations must secure.
He stressed that detecting unauthorised activity was not enough on its own, as organisations also needed enforceable policies capable of preventing AI agents from exceeding their authorised scope.





