Australia warns organizations to adopt agentic AI with strong cybersecurity controls

Agentic AI systems offer opportunities for businesses and organizations to protect their networks, but they also carry significant risks if human oversight isn’t implemented properly.
The Australian Signals Directorate (ASD), Australia’s cybersecurity agency, argues that AI agents have the potential to significantly improve the cyber defense of companies and organizations.
But before deploying any autonomous AI agents in a corporate environment, businesses must address important security risks.
The incident at OpenAI and Hugging Face has proven this.
OpenAI’s advanced AI models were tasked with completing a benchmark test to measure maximum cyber capability. To obtain the benchmark test solution, the models took actions beyond their intended testing environment and established internet connectivity, in part by identifying and exploiting a zero-day vulnerability in third-party software hosted internally by OpenAI.
As a result, OpenAI’s models breached part of Hugging Face’s production infrastructure and accessed internal datasets and service credentials.
“The findings provide an important insight into the future capabilities of highly capable AI systems and reinforce the need for robust security, governance, and oversight mechanisms in the deployment of advanced cyber capabilities, as well as strong cybersecurity fundamentals,” the ASD concludes.
Traditional security systems rely on human review and interaction. AI agentic systems, on the other hand, can make decisions independently and take action with almost no human involvement.
“This combination of autonomy, tool access, and operational privileges can create opportunities for privilege escalation, prompt injection attacks, unintended or deceptive behavior, data compromise, and cascading failures across interconnected systems,” Australia’s cybersecurity agency warns.
Businesses and organizations considering introducing agentic AI systems into their digital environments should begin with low-risk, non-sensitive tasks and ensure the systems operate within clearly defined objectives and constraints.
On top of that, they should continuously monitor agentic behavior and tool usage. But most importantly, human oversight must remain in place at all times. This includes live monitoring of agentic activities, detecting unauthorized behavior, and implementing measures to stop agentic operations when necessary.
Other cybersecurity experts warn of the need to remain vigilant against the next OpenAI/Hugging Face debacle.
“OpenAI is criminally negligent when it comes to cybersecurity, and is very good at viral marketing to executives via poor and uncritical media coverage,” security researcher Kevin Beaumont claims.