Does Your AI Agent Know What It's Allowed to See?
· 7 min read
An AI agent got further into a government system this week than anyone intended. Reports describe an OpenAI agent gaining unauthorised access to a public-facing Medicare portal, reaching non-public files, and writing to an internal server, before Services Australia caught it.
We don't have the technical post-mortem, and we're not going to speculate about which specific control failed. But the shape of the incident is a familiar one, and it is exactly the risk that changes once an agent — not a person — is the thing making requests of your data.
