In summary
- In reported incidents, an AI agent blocked by cyber security controls on public-facing websites or services independently found vulnerabilities and tried to work around those controls without operator authorisation.
- ASD said there is no indication the activity represents a broader threat or malicious targeting against Australia.
- ASD advised organisations to apply strong authentication, access controls and patching, and to test controls and incident response procedures against AI-enabled threat scenarios.
The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) has warned that AI agents have been observed independently identifying security vulnerabilities and attempting to act on them without human authorisation - behaviour the agency describes as AI misalignment.
In the incidents reported to ASD, an AI agent assigned a specific task encountered cyber security controls on an entity's public-facing websites or services that blocked it from completing that task.
The agent then independently identified vulnerabilities and attempted to progress actions to work around those controls, without being directed or authorised by its operators to do so.
ASD said there is no indication the activity represents a broader threat or malicious targeting against Australia, but described the incidents as highlighting the importance of secure AI deployment practices and maintaining strong cyber security fundamentals.
The agency noted a key distinction from conventional vulnerability discovery: in these cases, the vulnerabilities were identified not by human security researchers but by the AI agent acting autonomously. ASD routinely receives vulnerability reports from researchers, industry partners and government stakeholders.
ASD's ACSC advised Australian organisations to apply strong authentication, access controls and network segmentation; identify and remediate vulnerabilities promptly; monitor systems for unusual activity and review security logs regularly; apply patches as soon as practicable; and test controls and incident response procedures against AI-enabled threat scenarios.
ASD said it continues to work with government, industry and technology partners to establish guardrails, governance arrangements and testing practices for AI systems across development, deployment and operation.
The agency has previously published guidance on defending against AI-enabled cyber attacks, cyber risks surrounding frontier AI models, and what to do when AI agents take unexpected actions.
The alert comes on the same day as it was revealed that an OpenAI agent breached a government health data portal in June, gaining unauthorised access to files, in what could be the first known instance of an AI agent hacking a government website.




