An AI agent gained unauthorised access to files in a public-facing Medicare statistics portal while carrying out a research task. For Australian businesses, the incident raises a very practical question: Would your existing security controls hold if an agent kept looking for another way through?
According to Jack Jorgensen, General Manager – Data, AI & Innovation at Avec:
“It’s really a wake-up call to start looking at your policies and governance around how your systems are currently structured.”
Start with the agents already in your business
Before an organisation can manage agent risk, it needs to know which agents are already operating across the business and what they can access.
Jack recommends building an inventory that records each agent, its owner and its purpose. That work should also look beyond approved deployments. Employees may be experimenting with personal projects or connecting tools to business systems without going through established IT processes.
An inventory gives executives and security teams a clearer view of where agents are being used, who is accountable for them and which permissions need closer examination.
Examine what can be reached from outside
The next question is what an external agent can access. Jack points to guest permissions, publicly exposed systems and the possibility of information leaking when infrastructure is probed repeatedly.
These are familiar areas of security review, but autonomous agents change the conditions under which controls may be tested. An agent can keep trying alternative routes when it encounters a restriction, including routes the organisation may not have expected a user to take.
As Jack explains:
“Most [businesses] are underestimating the capability of these agents and the consistency of them. They don’t sleep, they don’t rest.”
Making it all the more important to test whether access restrictions work in practice, including when a system receives repeated or unexpected requests.
Test internally, then bring in an independent view
Jack’s recommendation is to test systems and agents before they go into production, and to assess the organisation’s broader exposure. Where the capability exists in-house, security teams can begin that work internally. Where it doesn’t, an external audit can establish a starting point.
He also recommends independent testing alongside internal efforts:
“It’s always good to engage a third party to also participate in that because their job is focused on what’s current, what’s new, and where the bigger attack surfaces are.”
For executives, the immediate task is to make that review concrete: identify the agents in use, assign ownership, examine their permissions and test the boundaries of systems exposed to the outside world. As agents become more capable, assumptions about what they will attempt are a poor substitute for evidence that those boundaries hold.

