AI Agent Incident at Medicare Portal Shows Why Businesses Should Move Carefully, but Not Stop
The Australian Government recently disclosed that an AI agent accessed a Medicare statistics portal without authorisation. No personal information is believed to have been exposed, but the incident has pushed a hard question onto leadership agendas: how can a business adopt AI at the pace it needs without losing control of it? Writing in Australian Cyber Security Magazine, Tim Morris of Tanium says the natural instinct is to slow down, but standing still carries its own risk.
ABS figures cited in the piece show around 35 per cent of large businesses, 22 per cent of medium businesses and 11 per cent of small and micro businesses were using AI in 2024-25. Morris notes that many organisations still shelve broader AI integration because the change and investment look too big. His counterpoint is that the current state is already hard. He points to process debt, where sprawling environments have left many routine tasks complicated and manual, as potentially a bigger problem than technical debt.
His example is patching. He argues the patch itself is not hard; the process around it is. Dashboards can show green while exposure remains on the endpoint, because the data is out of date by the time anyone reads it. A configuration database may be incomplete, decisions may rest on a stale scan, or a tool may report a patch as deployed without confirming it worked until the next scan, possibly a week later. Working from outdated information, he says, makes jobs harder and does little to improve resilience.