Our CEO and founder
@theonejvo recently caught up with
@_perloj at
@NBCNews to talk about the
@OpenAI agent that gained unauthorised access to an Australian government Medicare system, an incident recently raised by Prime Minister
@AlboMP where OpenAI characterises as its model acting in ways it did not intend, a characterisation that is still contested.
It sits alongside independent research showing agents also probed the AIHW, a university database, and made tens of thousands of requests engineered to slip past AI access restrictions. The article is live now, link below.
The data barely mattered. The behavior is everything. An agent was handed an ordinary research task, hit a wall, and reasoned its own way around it, with nobody instructing it to.
That is the baseline of what a capable offensive agent does now, and every government and enterprise with internet-facing systems should assume agents like this are probing them daily, some with benign instructions and some without.
Most of this week's coverage centres on agents that allegedly did something their creators didn't intend, and while while characterisation is still contested, the details remain thin, and people are right to want answers, which is exactly the point.
You cannot build sound policy or defences on top of a black box. And the accidental case, if that's even what this was, is the gentler half of the problem.
The harder half is the agent doing exactly what it was told, run by someone who removed its safety training and is consciously directing it to cause harm.
Those systems exist today, they improve every month, and the people using them are not going to send anyone a disclosure afterward. Defenders have to plan for both, and the second population is the one that meets no resistance.
This is the reality Aether AI was built for, and it's why we've spent the last two years building Australia's only sovereign attack AI.
We build autonomous offensive agents that test our customers' systems the way a real adversary would, with authorisation and inside a defined scope, and that learn from every engagement they run. The capability lives here, is operated here, and answers to Australian customers on Australian terms.
Over the past eighteen months our team has found and responsibly reported vulnerabilities to multiple Australian federal and state agencies, several of them considerably more serious than anything in this week's headlines.
We've been living inside this threat model rather than commenting on it from the outside, and the pattern is consistent: the exposure is real, it is often long-standing, and the thing that has changed is the arrival of systems fast and capable enough to find all of it at once.
This week was a warning shot from an agent that meant no harm. The next one won't be.