Professor Yang Xiang from Monash University, on OpenAI's hack of Medicare:
“An OpenAI agent’s unauthorised access to Australia’s Medicare statistics portal in June is a serious warning about the risks of agentic AI.
“This kind of intrusion and access actioned by an AI agent is significantly different from a scenario where a human hacker orchestrates a cyberattack. An AI agent has the capability of trying to ‘unlock’ a virtual ‘locked door’ numerous times in a short period and potentially breaking in.
“There is currently no evidence that personal information was accessed, but the breach still matters. A legitimate task does not justify unauthorised actions. An AI agent must treat a locked door as a limit to respect, not a puzzle to solve.
“The delayed response also shows how far our defences have to go. Agent behaviour can be difficult to monitor and audit at scale. Protecting public systems will require better detection of AI agent activity, tighter limits on what agents can access, and faster incident reporting.
“Agentic AI can be enormously useful, but it must be used responsibly. That is why trustworthy AI is no longer optional.”