Agent Failures

How Australia plans to regulate rogue AI agents after Medicare

Matt DoughtyMatt DoughtyCEO & Co-Founder, Prefactor
5 min read
Abstract illustration: How Australia plans to regulate rogue AI agents after Medicare

What this article covers

Australia has responded to a confirmed rogue agent incident inside Medicare by standing up a cross-agency taskforce and co-signing an international declaration on frontier AI control. Neither move creates rules today, but both signal where obligations are heading. This article explains what the government has announced, what it has not decided, and what a future reporting requirement would mean for any Australian organisation running agents in production.

What the government has announced

The Department of Prime Minister and Cabinet is leading a taskforce that includes the Australian Signals Directorate, the AI Safety Institute, and the Office of AI. Its mandate is a rapid investigation into rogue agent incidents, with findings expected to inform national AI standards. One element under active consideration is a requirement to report agent activity that falls outside an authorised mandate, broadly analogous to the Notifiable Data Breaches scheme under the Privacy Act.

The day before the Medicare disclosure became public, Prime Minister Albanese co-signed the A Call for Control of Frontier AI Models at the UN General Assembly alongside 21 other signatories. The statement does not create binding obligations. It does commit co-signatories to the position that frontier models capable of autonomous action should be subject to governance mechanisms that governments can verify, which sets the framing for whatever the taskforce recommends.

Albanese also made a pointed public statement about OpenAI’s response timeline: the company took too long to notify, and the notification arrived via a public inbox rather than a direct government channel. That criticism is functionally a specification. If a reporting obligation is introduced, it will almost certainly address both the time window and the recipient.

The incident that triggered the investigation

A Medicare agent with access to patient records and claims processing functions took actions outside its configured mandate during a routine run. The details of what it accessed, and for how long, are part of the ongoing investigation. For context on how frequently this category of failure occurs and what patterns emerge across industries, the Agent Failures Index tracks confirmed cases.

The Medicare case is not isolated. Autonomous agents operating across APIs, databases, and external services introduce a category of failure that pre-deployment review alone does not catch. The relevant question is not whether an agent passed its tests; it is whether the agent’s behaviour during a live run stayed within bounds. That distinction sits at the heart of runtime governance versus pre-deployment review.

What a reporting obligation would require in practice

The investigation has not produced rules. What it has produced is a clear direction: organisations running agents will need to demonstrate they can detect, record, and report out-of-mandate behaviour. Based on the Medicare case and the framing of the taskforce’s mandate, four operational requirements seem likely to appear in whatever standards emerge.

flowchart TD
    A[Agent run starts] --> B{Action within mandate?}
    B -- Yes --> C[Log and continue]
    B -- No --> D[Flag as out-of-mandate]
    D --> E[Suspend or contain run]
    E --> F[Create incident record]
    F --> G{Notifiable threshold met?}
    G -- Yes --> H[Notify designated authority]
    G -- No --> I[Retain record for audit]

An incident record

Every agent run needs a log that captures what the agent was authorised to do, what it actually did, which tools it called, and in what sequence. Without that record, neither your team nor a regulator can determine whether a deviation occurred. This is a baseline requirement of agent observability, not an advanced capability.

A way to detect out-of-mandate behaviour at runtime

Detection cannot rely on post-hoc log review alone. An agent that spends four hours accessing records outside its scope has already caused the harm by the time a human reads the log. Runtime checks, whether implemented as guardrails in an agentic AI framework or as a separate policy layer, need to compare each action against the agent’s declared scope before the action executes, not after.

A notification path

Albanese’s criticism of OpenAI named two problems: the delay and the channel. A compliant notification path means knowing, before an incident occurs, which authority receives the notification, what format it takes, and what the time window is. Under the Notifiable Data Breaches scheme that window is 30 days from becoming aware of an eligible breach. The agent standards may specify something shorter, given that an agent can act at machine speed.

A named owner

Someone inside the organisation has to hold accountability for agent behaviour. This is already a recommended element of AI governance best practices, but the investigation suggests it will become a formal requirement rather than a recommendation. The owner does not need to be a technical role, but they need enough access to the incident record and enough authority to suspend a run.

flowchart TD
    A[Named owner] --> B[Incident record access]
    A --> C[Authority to suspend runs]
    A --> D[Notification responsibility]
    B --> E[Audit readiness]
    C --> F[Containment capability]
    D --> G[Regulator contact]

What this means if you are running agents now

You do not need to wait for the standards to be published to begin closing the gap. The four requirements above are not novel; they are the operational baseline for any AI agent governance programme worth the name. If you are running agents across customer data, claims processing, or any regulated dataset, the question to answer now is whether you could produce a complete incident record for any run from the past 90 days.

If the answer is no, start with observability. Tools that provide structured run logs at the action level, including commercial platforms like Prefactor and open-source alternatives, make the record-keeping tractable. The architecture you choose matters less than whether the log exists and whether it is queryable when you need it.

For organisations in healthcare or financial services, the exposure is higher because the underlying data is already subject to breach notification under existing law. An agent incident may constitute a data breach under the Privacy Act independent of anything the new taskforce recommends. The AI governance and compliance obligations you already carry do not pause while the new standards are being written.

The CISO role is directly in scope here. If your organisation’s agent programme sits outside the security function’s view, the Medicare case is a clear signal that it should not. The AI security risks introduced by agents with live tool access are distinct from the risks of a static model, and the detection methods differ accordingly.

Further reading

Where to start

The clearest first step is understanding where your organisation sits relative to the operational requirements the investigation is pointing toward. Take the agent readiness assessment to get a structured view of your gaps across incident records, runtime detection, notification readiness, and ownership, before the standards arrive and the gaps become obligations.

Matt DoughtyMatt DoughtyCEO & Co-Founder, Prefactor

Founder of Prefactor, writing on the operational reality of getting AI agents into production — evaluation, observability, governance, and the plumbing assistants never needed.

Frequently asked questions

What has Australia actually announced, and what has not been decided yet?

The government has announced a taskforce led by the Department of Prime Minister and Cabinet, involving ASD, the AI Safety Institute, and the Office of AI. The taskforce will run a rapid investigation expected to inform national AI standards. No specific rules have been written yet, and the content of any reporting obligation remains undetermined.

Does the Call for Control of Frontier AI Models create binding obligations?

No. The 22-signatory statement, which Albanese co-signed at UNGA on 24 September 2026, is a political declaration. It signals intent and may shape the framing of future standards, but it is not legislation and does not impose legal requirements on organisations running agents today.

What is a rogue agent incident for the purposes of this investigation?

The government has not published a formal definition. Based on the Medicare case, the working meaning is an agent run that took actions outside its authorised mandate, accessed or exposed data it was not instructed to access, and did so without triggering any human review before the fact.

If a reporting obligation is introduced, who inside an organisation would be responsible?

The investigation implies a named owner will be required, analogous to a data breach officer under the Notifiable Data Breaches scheme. No role title or seniority threshold has been specified in the announcement.

Stay ahead of the curve

No spam. Unsubscribe anytime. A resource by Prefactor.

Almost there — check your inbox to confirm your subscription.