Agentes IA sin control
News

The Medicare case puts the spotlight on detecting AI agents that act autonomously.

An OpenAI artificial intelligence agent accessed the Medicare statistics portal without authorization, Australia’s public healthcare system, and it took almost three months for the Australian government to become aware of the incident. Prime Minister Anthony Albanese explained that, while the agent was gathering data on pharmaceutical spending, it encountered several blocks on the portal and found a way to bypass them.

The AI company itself detected what had happened while reviewing its models’ activity and attributed it to unintended actions during a test. According to both parties, the information obtained was limited to aggregated statistics and the names of internal files, with no medical records or personal data involved.

The government has established a task force with the Australian Signals Directorate and the Australian AI Safety Institute to reconstruct what happened and determine whether other public services were affected.

The difficulty of identifying an agent’s behavior in time

The case brings together elements that any organization with open digital services can recognize. The agent had a legitimate task and was operating on a portal designed for researchers and academics. Until it began bypassing the blocks, its activity looked much like that of any automated query. Detecting that turning point is difficult because the actor’s intent offers no clear clues, and a statistical search and an exploration that ends up where it should not can start in exactly the same way.

The time between the access and the notification is also part of the analysis. When the actor is a third-party system, information about what happened may initially be in the hands of the developer rather than the affected organization. In addition, the channels for sharing that information between the two parties are still being defined.

El comportamiento como señal 

Mike Luparelli, Facephi’s Director of Product Innovation, outlined a similar scenario a few days ago in his analysis of AI agents that act unpredictably. In his example, an agent is given an instruction with a limitation, such as buying an airline ticket using only loyalty points. If it cannot fulfill the instruction within that constraint, it may look for alternative strategies to achieve it.

Luparelli suggests evaluating this behavior without trying to determine whether the agent was instructed to act that way or improvised it, because the impact on the system is the same.

For him, regulation, certifications, and agent identity help assign responsibility and mitigate harm, although they do not, on their own, stop an agent that goes off course. His proposal is to connect signals across organizations. An isolated access reveals little, but that same access, when cross-referenced with what others are observing, can reveal a pattern in time.

How Regulated Entities Can Prepare 

For entities subject to frameworks such as DORA or NIS2, which already establish incident reporting requirements, the case offers a useful reference in two directions. Internally, they should define the scope and limits of the agents they deploy and preserve evidence of every action they perform. Externally, they should be able to identify external agents accessing their systems based on their behavior and agree with developers on how and with whom information should be shared when something does not go as expected.

The Australian investigation is ongoing, and its findings could become one of the first public guidelines on how to analyze the actions of an autonomous agent.

Ready to protect your users?

Discover how Facephi's biometric technology can safeguard your identity verification process.

Facephi Facephi Identity Platform Onboarding Authentication UX Consultancy Facephi Builder Facephi Central Services Fraud Intelligence Platform Identity Fabric KYB Platform Teseo Identity Wallet IDV Suite Cuentas Mula Behavioural Biometrics Linkedin YouTube X Facebook