On 18 June, an OpenAI agent doing what it was told, looking up statistics about Australia, decided the fastest route to the answer ran through a private government statistics portal holding Medicare data. So it went in.

Nobody in Australia knew. OpenAI itself didn’t know until August, when a review of misaligned model activity surfaced it. The company then emailed a generic government inbox, where the message sat for five days before anyone escalated it. Australia’s cyber authorities were briefed on 10 September. Prime Minister Anthony Albanese called the delay “way too long.” We agree.

Let’s dig deeper on what really happened though, which is more concerning. The breach wasn’t detected by the Medicare security team. It was disclosed by the intruder’s owner, and not until almost three months later. Strip away the novelty of an AI agent and that’s the oldest failure in security: someone else tells you that you were breached.

The part that should worry you isn’t the agent

Most of the commentary has focused on misalignment. On the fact that an autonomous system decided the rules were an obstacle rather than a boundary. That real problem belongs to the model builders.

Defenders have a different problem. Security experts told the BBC that the protections around the Medicare portal simply weren’t strong enough, and that a skilled human attacker could have walked through them too. The agent didn’t defeat a control. It found a path that was open and took it.

This is exactly the problem that Skyhawk Security solves with our AI Red Team. The exposure existed before 18 June. It was sitting there, reachable, attached to data the government cares about. Any adversarial assessment of that environment would have surfaced it. The question is whether anyone was running one.

Every configuration in this chain was probably legitimate

We don’t know the internals of the Australian environment, and this isn’t a post-mortem of it. But the shape of the problem is familiar to anyone who runs cloud infrastructure: a portal described as private that is reachable from somewhere it shouldn’t be, an identity with more access than its purpose requires, a data store that is one hop further than anyone drew on the architecture diagram.

None of those is a critical vulnerability. None of them trips a severity-based alert. Each one passes review in isolation. Chained together, they’re a route to Medicare data.

This is exactly what Skyhawk’s AI Red Team is built to find. It runs continuously against a digital twin of the live cloud environment, IAM relationships, network topology, workload configuration, security controls, and the connections between them, and asks the only question that matters: given the way this environment is configured right now, wat will a threat actor do? Not which findings score highest on CVSS, but which combination of legitimate settings adds up to a path to something valuable.

The digital twin updates as the environment changes, so a new permission or a modified security group is reflected in minutes and the attack paths are recalculated. The exposure window closes to the time between a change and its validation, rather than the time between a change and someone’s next scheduled assessment.

Skyhawk Security takes this analysis one step further and prioritizes based on the business value of the at-risk asset. Skyhawk would never have a path ending at a national healthcare dataset in a queue behind a hundred findings on a marketing sandbox.

Machine speed cuts both ways

There’s a second half to this. Skyhawk doesn’t only map the paths, the same adversarial simulations pre-train the SOC on how those attacks look when they’re live in your cloud.

That matters a great deal here, because an AI agent is a gift to behavioral detection. Human operators pause, retype, take coffee breaks, etc. An autonomous agent enumerates endpoints at a rate no human session produces, in a pattern no human session produces. It is, in behavioral terms, loud. What it isn’t is loud in the ways traditional tooling watches for: no malware, no exploit signature, no known-bad indicator. Just an identity doing things faster than a person could.

That’s the shift. The dangerous non-human identity is no longer a service account with a stale key. It’s an autonomous agent making its own decisions about how to accomplish a goal, and legacy IAM has nothing to say about it.

The honest conclusion

Would Skyhawk have stopped OpenAI’s agent? No one can promise that about another organization’s environment, and anyone who does is selling badly.

Here’s what can be said. The path the agent used existed before the agent found it, and continuous adversarial simulation is designed to find exactly that kind of path, the one made of legitimate pieces that nothing flags on its own. And in the environments Skyhawk runs in, the finding arrives in minutes, not as an email from the intruder’s employer twelve weeks later.

Dr Raffaele Fabio Ciriello of the University of Sydney put the lesson well: the immediate harm here appears limited, but the governance lesson is not. As agents get more capable, their capability has to be matched by real-time monitoring and much faster incident reporting.

We’d add one word to that: proactive. Monitoring tells you an agent is already inside. Knowing which paths it could take tells you before it tries.

Want to learn more?