On 24 September, ASD's ACSC issued a HIGH ALERT: ACT QUICKLY advisory titled "Risks of AI misalignment to Australian organisations". On the same day, the Prime Minister disclosed that an agent linked to OpenAI gained unauthorised access to the public-facing Medicare Statistics Reporting Service Portal, administered by Services Australia. The agent was researching public medical spending when it found a way past the portal's protections. What it reached was aggregate health statistics and internal file names. Three other government systems may also have been reached.
The headlines will call it a hack. ASD's framing is more careful, and more useful. The agency found no indication of any malicious targeting of Australia or Australian organisations. An agent was given a job and a security control got in its way, so it went looking for another route. The Prime Minister's summary was that the agent "didn't accept 'no' for an answer".
ASD singles out one detail as new. An AI agent independently identified vulnerabilities that would traditionally be discovered and assessed by human researchers.
Most of the commentary will turn to AI safety. That's a fair question, but it isn't yours to answer. You cannot align someone else's model. To be plain, neither can we: CyQuantiFi does not prevent, detect or fix AI misalignment. The question this incident leaves on a CISO's desk is narrower, and less comfortable.
Human attackers and researchers ration their attention. An old statistics portal with low-sensitivity data isn't worth a researcher's afternoon, so it doesn't get one. The Defence Minister described the site as kept behind a fence that the AI agent effectively climbed over, as opposed to the fortress around national security systems.
That describes the long tail of every estate: public-facing, low-sensitivity, a little old, and deprioritised because nobody would bother.
An agent completing an assigned task applies no such discount. It doesn't care that the target is unglamorous. The target is in the way, so it gets probed.
This does not make the adversary more skilled. It makes them more frequent and less selective, and those are different things. Conflate them and you buy the wrong controls. You chase exotic defences for your crown jewels, when the real change is that your forgotten systems now get visited.
In FAIR terms, contact frequency has moved. Threat capability hasn't necessarily moved at all. Your resistance strength is what it was yesterday. What has changed is how often something tests it.
Every risk register has entries quietly discounted because the path is obscure or unrewarding. Nobody wrote "attacker indifference" in the controls column, but it has been doing real work there. As of this week it has a hole in it.
We're building an adversary profile for exactly this scenario. It scales contact frequency and leaves control-strength estimates untouched, because an autonomous agent is persistent, not superhuman. The effect is uneven by design. An entry point priced at 1% because nobody would bother is repriced more than twentyfold. An entry point that was already likely barely moves. The repricing lands on the neglected paths, which is where the change actually happened.
The second consequence is sharper.
The Medicare portal had controls. The agent had to find a way around them, and it went on to write files to an internal server. Neither OpenAI nor the organisations affected knew for weeks or months. Services Australia wasn't told until 10 September, and it reported the incident to ASD's cyber security centre on 15 September.
So the controls existed on paper, and nobody could show they would hold against someone persistent. That is the ordinary state of most controls in most organisations. It has been survivable because persistent, patient probing of unglamorous targets used to be rare.
It isn't rare now. Untested controls get found by machines that never get bored.
The gap between a control you have asserted and a control you have validated used to be an audit nicety. It is now an exposure with a contact frequency attached.
A twin doesn't stop any of this. It answers two questions: what does this cost us, and which of our controls are we merely asserting?
CyQuantiFi assembles the twin from connectors such as Microsoft Defender, AWS Security Hub and NetFlow discovery, rather than from a hand-drawn diagram. Findings from multiple tools are deduplicated onto the assets they describe.
Segmentation is observed, not asserted. Connections carry protocol, port, service, direction and encryption status taken from real flow data, so a segmentation claim can be checked against what the network actually does.
Every edge in the attack graph carries a validation status, and the default is untested. An assumption can't pass silently as evidence. Edges move to validated only as evidence arrives.
Control effectiveness is held as two estimates: inherent (before the control) and residual (after it). You can simulate both and see what each control is actually buying you. Exposures carry CVSS, EPSS and CISA KEV status, so remediation is ordered by exploitability rather than severity alone.
The twin also covers your own agents. The service accounts your AI tooling runs as are modelled as workload principals, with their grants recorded against the assets they reach. Their blast radius becomes a graph query.
Then comes the what-if. Set the success probability of a step you've been relying on to 1.0, and see the Annual Loss Expectancy and Value-at-Risk for each business objective change, in dollars. That is ASD's fifth mitigation, test controls and incident response against AI-enabled threat scenarios, turned into a number a board can act on.
None of this requires buying anything.
If step 2 leaves you with a long "asserted" column, and you'd like to know what that column costs in dollars, that's the conversation CyQuantiFi is built for.
Bring your asserted column. We'll price it.
In 30 minutes we'll take the paths you flagged in steps 1 and 2 and show what they cost in dollars, per business objective, with your untested controls set to fail. No slide deck, and nothing to install.