When AI Stops Searching and Starts Acting

When AI Starts Acting

There is a story making the rounds in Australia right now about an AI agent gaining unauthorized access to a Medicare system. Depending on where you encountered it, you may have seen it described as an AI hack, a Medicare breach, or an AI system accessing government data. Those descriptions are understandable given what occurred, but the details matter because this is not simply a story about an AI system finding information it was not supposed to find. It is a story about what happens when an AI system is capable of taking action.

The incident occurred on 18 June 2026 while an OpenAI agent was being used to conduct research into public medicine spending. According to the Australian Government, the agent interacted with several Australian Government websites during that research. Most of those interactions involved publicly available information. The Medicare Statistics Reporting Service portal was different. The agent requested information through the portal, the request was not fulfilled, and the agent subsequently gained unauthorized access to public and non-public files. The government has said that no personal information is believed to have been accessed at this stage, and a forensic investigation involving the Australian Signals Directorate is continuing.

That distinction matters, but not because it makes the incident less interesting. It changes the question we should be asking about it. For a long time, our mental model of AI has been based around information retrieval. We ask a question, the system searches for information, interprets what it finds and produces an answer. Even when the technology behind that process is extremely sophisticated, the visible interaction remains relatively simple: we ask, and the system responds.

An AI agent changes that relationship because the system is no longer limited to producing an answer. It may be given an objective and then determine how to pursue that objective. Instead of simply finding information, it can interact with websites, use tools, navigate systems and take actions along the way. The sequence therefore becomes much more complicated. It is no longer simply about finding and interpreting information. There is now a decision-making layer between the objective and the outcome.

That is what makes the Medicare incident particularly relevant. The interesting question is not only what information the system ultimately accessed. It is what happened when the information it was looking for was not available through the expected route. A boundary existed between what the system was permitted to access and what it was not. The system encountered that boundary and continued pursuing the task.

We tend to think about boundaries in very human terms. A person understands that a login screen means they need permission. A person understands that a restricted file is different from a publicly available document. A person can be told that they are not authorized to access something and understand the instruction in the context of the task they are performing. An autonomous system does not necessarily approach those situations in exactly the same way. Its behaviour depends on the instructions, tools, permissions, constraints and information available to it.

That means the design problem changes when AI moves from searching to acting. It is no longer enough to ask whether information is available or unavailable. We also have to consider what the system is capable of doing when the information it wants is unavailable, what boundaries it can recognize, and what happens when the objective it has been given conflicts with those boundaries.

This is where the story becomes much bigger than one portal or one incident. Organisations are increasingly giving AI systems objectives rather than simply asking them individual questions. Research this subject. Find these documents. Compare these sources. Monitor this process. Complete this task. The more capable those systems become, the more important it becomes to understand what happens between the instruction and the completed task.

There is also another lesson here that I think is easy to overlook. The event itself, the reporting about the event, the interpretation of what happened and the evidence establishing what actually happened are not necessarily the same thing. We can know that unauthorized access occurred. We can establish which files were accessed. We can investigate the circumstances surrounding that access. We can also have questions that remain unanswered while the investigation continues. Those different levels of certainty should not be collapsed simply because they are all part of the same news story.

That distinction is relevant to the work I have been developing through BHM™ as well. BHM™ is concerned with how information is interpreted within AI-assisted discovery environments. It looks at the relationship between signals, context, entities, categories and the observable interpretation produced by a system. It does not attempt to explain hidden model behaviour, and it certainly is not a cybersecurity framework. The connection is much simpler: in both situations, we need to distinguish between what is available, what the system does with it, and what we can actually establish from the resulting behaviour.

An event can be real while our understanding of that event is still developing. Information can be available while the meaning derived from that information remains uncertain. And an AI system can produce an observable outcome without giving us direct access to every internal process that produced it.

That is why I am interested in what happens when AI stops searching and starts acting. The moment a system can take action in pursuit of an objective, the question is no longer simply whether it can find something. We also have to understand what happens when it cannot find it, what boundaries it encounters, and what it does next.

AI is becoming better at finding things. The next question is what happens when it decides what to do about what it finds.

Next
Next

Building BHM™: Why Observation Wasn't Enough