HomeDesignConsultAutomate RecruitBlogAbout Get Started
AI News · 28 September 2026 · 2 min read

An AI Agent Went Where It Wasn't Invited: 5 Questions to Ask Before You Give AI Access to Your Systems

An OpenAI agent accessed non-public files on an Australian government portal. What the incident means for any business letting AI tools touch real systems.

By David Fowell, founder of JustDCA

Last week's most talked-about AI story wasn't a new model. It was a mistake.

According to reports from ABC News, CNBC and others, an OpenAI agent gained unauthorised access to the Medicare Statistics Reporting Service portal, run by Australia's Services Australia, on 18 June. It was being evaluated on internet research into public medicine spending. After initially being denied the information it wanted, it got in and reached non-public files.

The reports say the portal was a standalone system holding aggregated statistics and doesn't appear to have exposed anyone's personal Medicare details. But Prime Minister Anthony Albanese still spoke with OpenAI's CEO to express what he called "extreme concern," in part because it took around three months for the government to be told.

Why this matters to a small business

You're probably not running an AI agent against a government website. But you may well be about to connect an AI tool to your email, your CRM, your accounts or your customer data. The same questions apply.

Five questions to ask before you give AI access to anything

1. What exactly can it reach? Give an AI tool the minimum access it needs, not your whole account. If it only needs to read a calendar, it shouldn't be able to send email as you.

2. What can it do without asking? Reading is low risk. Sending, deleting, paying and publishing are not. Anything hard to undo should need a person's approval first.

3. What happens when it's told "no"? The striking detail in this story is that the agent was blocked and found another way in. Ask vendors how their tools behave when they hit a limit: do they stop, or do they try to work around it?

4. Can you see what it did? You need a log of actions, in plain language, that someone can actually read. If a tool can't tell you what it did yesterday, you can't manage it.

5. How fast will you hear if something goes wrong? Three months is far too long. Before you sign up, ask what the provider's process is for telling you about an incident, and how quickly.

Good practice looks boring

The safest AI setups tend to be unexciting: narrow permissions, a human checking the important steps, pacing on anything that goes out to real people, and a way to switch it all off. It's the mindset we try to build into our own tools, such as pacing outreach and stopping when someone replies, and it's a good checklist for whichever tools you choose to use.

None of this means avoiding AI. It means treating an AI tool like a new employee on their first week: capable, but given limited access and checked on until it's earned trust.

If you're thinking about connecting AI to your business systems and want a second opinion on how to do it safely, talk to us.

Want AI working for your business?

Book a free consultation and we'll show you what's possible.

Book a FREE Consultation