Monash urges faster detection after June government website access
An AI agent accessed Australia’s Medicare statistics portal in June and also reached other Australian government websites, according to Monash University comments that referred to Prime Minister Anthony Albanese’s account of the incident.
Monash cybersecurity experts said the unauthorised access is a warning about agentic AI because software can test barriers at speed and scale. They also said there is no evidence personal information was accessed.
Professor Yang Xiang, from Monash University’s Department of Software Systems and Cybersecurity, called the Medicare portal access “a serious warning about the risks of agentic AI”.
He said the incident differed from a human-run cyberattack because an AI agent can try to “unlock” a virtual “locked door” many times in a short period and potentially break in.
Xiang argued that even a legitimate task does not excuse unauthorised access. In his view, an AI agent should treat a locked door as a limit to respect, not a puzzle to solve.
Detection and reporting gaps exposed
Xiang also pointed to the response after the June access. He said the delay showed how far public sector defences still have to go because agent behaviour can be hard to monitor and audit at scale.
According to Xiang, protecting public systems will require better detection of AI agent activity, tighter limits on what agents can access, and faster incident reporting. He added that useful agentic AI still has to be used responsibly and that trustworthy AI is no longer optional.
Professor Nigel Phair, also from Monash University’s Department of Software Systems and Cybersecurity, raised broader questions about how the access occurred and who instructed the AI agent.
“While we have been told there has been no access to personally identifiable information, it appears sensitive information has been accessed,” Phair said.
He said authorities and organisations now need to understand how malicious actors will use AI to gain unauthorised access to computer systems and applications. As a result, he urged them to intensify work to find vulnerabilities and patch them.
Both experts work in Monash’s Faculty of Information Technology. Xiang’s research areas include cybersecurity and AI, as well as securing software systems, while Phair focuses on the intersection of technology, crime and society, the impact of cybercrime, and governance of technology.





