Once upon a time, the general consensus around AI was that if you don’t give them too much access, you won’t have any problems.
Unfortunately, this week showed why that advice is no longer enough.
Reports from the Australian government and Google have raised an unsettling possibility. AI agents may not only misuse the permissions they are given, but also find unexpected ways around barriers that were supposed to stop them.
Add a major customer-data breach at Manchester Airport and fresh guidance on cloud identity tokens, and it’s been another highly eventful week for the world of security and compliance.
The general lesson appears to be that the systems holding customer data, authorizing automated actions, and powering AI need to be treated as one connected risk.
As Australian Prime Minister Anthony Albanese put it after an AI-related incident involving Medicare:
“There were blocks clearly which were coming back telling the AI agent ‘no’. The AI agent found a way around those blocks – didn’t accept no for an answer.”
Here are the biggest security, privacy, and compliance stories from the past seven days:
Australia Reviews AI Security After Medicare Portal Incident
Australia has launched an urgent review after an autonomous OpenAI agent accessed a statistics portal linked to Medicare, the country’s public healthcare scheme.
The incident took place in June, but OpenAI became aware of the potential breach during a later review and notified Services Australia on September 10. The notification was then reported to the Australian Cyber Security Centre on September 15.
OpenAI said it found “no record of patient data being accessed.”
Nevertheless, the event has prompted a rapid government review into whether existing laws and governance arrangements are suitable for AI-led cyber incidents.
The concern is not simply that a system was accessed. It is that the agent reportedly encountered barriers, adapted its approach, and continued trying to complete its task.
That changes the security conversation for enterprises deploying AI into customer-facing environments. A standard chatbot with limited access presents one type of risk; an autonomous agent that can plan actions, use tools, and keep probing after a failed attempt presents another.
The delay in notification has also become part of the story. Albanese said he told OpenAI CEO Sam Altman that the company took “way too long” to inform the Australian government.
For CX leaders, if an AI agent can access customer records, billing systems, claims information, or service workflows, incident response plans need to account for agent behavior, not only human error and external attackers.
Google Says Gemini Accessed Three Company Systems During Security Testing
Google has said its Gemini AI model autonomously accessed systems belonging to three companies during a controlled cybersecurity test.
According to the BBC, Gemini used publicly available information and guessed credentials to enter websites it believed were part of the exercise. Google said the model stopped in each instance, while the affected companies were informed.
The incidents occurred in May during testing by independent cybersecurity evaluation company Irregular. They were not malicious attacks, and there is no suggestion that Gemini was deployed against organizations outside the test environment.
In discussing the incident, Heather Adkins, Vice President of Security Engineering at Google, said:
“These events highlight the importance of training powerful AI models to act responsibly.”
They also highlight the limits of relying on intent alone. In a security test, an AI model may be expected to look for weaknesses, but when the same capabilities are paired with broad access to customer systems, weak passwords, exposed credentials, or poorly configured APIs can quickly become a business problem.
The Medicare incident and Gemini testing are not identical. One involved a government health portal and an urgent public review; the other was a controlled assessment.
Still, together they suggest that AI security is moving beyond theoretical prompt-injection concerns and toward practical questions of access, autonomy, and escalation.
Manchester Airport Breach Shows Customer Data Can Be Hiding Everywhere
The recent Manchester Airport cyberattack remains a reminder that customer data risks are rarely confined to a core CRM or a single customer service platform.
The breach reportedly exposed personal data linked to around 8.7 million people.
The information was collected through services including airport parking, Wi-Fi, and Fast Track. It was later published online after Manchester Airports Group reportedly refused to pay a ransom.
For affected customers, it may not matter whether their information came from a parking booking, a loyalty profile, or a digital-service interaction. It is all airport data, and the organization is accountable for protecting it.
However, the operational challenge is much harder when information sits across legacy systems, third-party applications, APIs, and separate business units.
This is where security becomes a customer experience problem. If an organization cannot quickly establish which data was accessed, whether the records are current, and which customers are affected, its communications will inevitably become slower and less certain.
CISA and NIST Put Cloud Identity Tokens Under the Spotlight
CISA and NIST have released guidance aimed at protecting federal cloud identity systems from token theft, forgery, and misuse.
It may sound like a technical issue, but identity tokens sit at the heart of modern customer technology. They authorize applications; APIs; cloud services; and, increasingly, AI agents to access data and take actions.
If an attacker steals a valid token, they may not need to crack a password or defeat a login screen. They can potentially impersonate a trusted user, service, or application.
That is why the guidance is timely. Customer service agents, automated workflows, CRM integrations, and AI platforms are all being connected through identities and permissions.
Every additional integration can improve the customer experience, but it can also extend the attack surface.
This week’s security news points to the same conclusion. Enterprises need to know what their AI agents can access, which systems trust them, and how quickly those permissions can be revoked when something goes wrong.