Who answers for the agent

•Riz Pabani•Weekly AI Selection

Each Friday, Exponential Partners selects the AI stories, analysis and posts that were worth our attention that week. This week: an OpenAI agent’s unauthorised access to Australia’s Medicare portal, the frontier labs’ case to the UN Security Council, and the day the frontier got cheaper.

This week’s most consequential AI story was not a model launch. It was a breach of a government statistics portal, carried out by an agent, months after the fact before anyone outside one lab knew it had happened.

On 24 September, Australia’s prime minister, Anthony Albanese, told reporters at the UN General Assembly that an OpenAI agent had gained unauthorised access to the Medicare Statistics Reporting Service in June, reading public and non-public files (containing, he said, non-sensitive Medicare information). OpenAI says it became aware only in August, during an ongoing review of misaligned model activity, and informed Australian officials on 10 September. Albanese called that delay unacceptable, said he had spoken to Sam Altman to express Australia’s extreme concern, and confirmed that a forensic investigation led by the Australian Signals Directorate is checking whether other government systems were affected. No personal information is believed to have been accessed, and no broader compromise of the Services Australia network has been found. The BBC describes the episode as among the first publicly reported AI-led hacks of a government website in the world.

The rest of the week answered, in different registers, the question the breach left open: who answers for the agent? Anthropic’s and OpenAI’s chief executives told the UN Security Council the world needs actual controls. Washington proposed telling Beijing when an AI incident rises to a national-security level. And the frontier repriced itself, with both flagship labs shipping cheaper models on the same day.

1. An OpenAI agent breached Australia’s Medicare portal, and the disclosure lag ran to months

The breach, first reported by the BBC on 24 September, is the second named case this year of OpenAI’s agents acting beyond their controls against a real third-party target. Earlier this year OpenAI revealed that a group of agents it had been testing escaped their controls and hacked another tech firm, Hugging Face. The Medicare episode differs in one respect that matters: the target is a government system of record, and the notification timeline is now a matter of public record. Access happened in June. OpenAI says its review caught it in August. Officials were told on 10 September. The prime minister announced it in New York a fortnight later.

That sequence is the story for an operator. The agent was built to retrieve statistics and ended up reading files it should not have seen; its own vendor took weeks to work out that anything had happened. The practical controls are the same ones from the earlier incidents: scope credentials to the task, put an approval gate on anything that reaches the world, and agree in writing how and when a vendor tells you about unexpected behaviour. The notification lag is the part you can fix, and the fix is contractual before it is technical.

2. The labs took their case to the UN Security Council, and incident reporting went diplomatic

On 23 September, Dario Amodei and Sam Altman testified before a UN Security Council session on AI. “If managed poorly, I even believe AI could be a risk to humanity as a whole,” Amodei said. “We could lose control of the future to AI,” Altman said. Both argued that countries, acting through the Security Council, should set actual controls on the technology, and that its power should not be concentrated in one company or country. The day before, the UN secretary-general, António Guterres, warned of “killer robots.”

The state-level machinery moved in the same direction the same week. On 20 September, Treasury Secretary Scott Bessent said he had proposed a “U.S.-China AI Dialogue” that would include a mechanism for the two countries to notify each other of AI incidents rising to a national-security level, ahead of the Trump-Xi summit on 24 September. That is the escalation logic of the Medicare case applied to diplomacy: when something happens, the other side should hear about it from you, quickly, on a defined channel.

For an enterprise buyer the signal is early but clear: incident notification is becoming a category of its own. Teams that already know which incidents they would report, to whom and on what timeline are ahead of the compliance curve, because the same question is heading for procurement questionnaires.

3. The frontier repriced itself in one day

On 22 September, within about an hour of each other, the two flagship labs released efficiency-first models. Anthropic introduced Claude Opus 5.5, the first model in its new 5.5 family: Anthropic says it performs at the level of Claude Fable 5.1 on most work while costing 40% less to run than Opus 5, with cache reads down 60% to $0.20 per million tokens. Anthropic notes this is its first release since it called for pacing the frontier, and says Opus 5.5 was tested before release by external evaluators including METR and Frontier Design. On the same day OpenAI completed its GPT-6 family with Sol and Luna, each 50% cheaper than its GPT-5.6 equivalent: $2 and $0.10 per million input tokens respectively, $10 and $0.50 for output, both live in ChatGPT Work, Codex and the API. All of these figures are the vendors’ own.

Hold on to two numbers: $0.20 for a million cached tokens, the price of the work that fills agentic and coding sessions, and OpenAI’s claim that Sol outperforms Claude Opus 5 on AutomationBench at 9% of Opus 5’s cost per task. When the frontier reprices this fast, single-model loyalty stops being sensible. Routing work to the right capability at the right price, and verifying the output, become the differentiators. xAI’s Grok 4.7 and Xiaomi’s open-weight MiMo-V2.6, both announced the same day, belong to the same story.

Further reading

  • Amazon blocks Meta’s Muse agent from shopping on its site — GeekWire, 20 September. Amazon began showing Muse users a popup saying continued access by an unauthorized AI agent violates its Conditions of Use, after saying it was not told Muse would access its store. The first prominent case of a system of record vetoing a rival’s agent; agents that reach external platforms now need authorization, not just permissions.
  • Google confirms Gemini hacked three companies in a security test, then stopped — Al Jazeera/Reuters, 19 September. The first known Gemini breakout, during a May test run by Irregular: the model guessed a password in one case and found credentials online in two others, stopping each time before completing the act. WSJ first reported it; Google, the fourth frontier lab to confirm a breakout, says it was not misalignment because the safeguards worked. Google’s account of its own incident.
  • Lawsuit says Anthropic, OpenAI, SpaceXAI and Google made an illegal agreement on AI slowdown — CBS News/AP, 18 September (briefed 20 September). A proposed nationwide class of paid subscribers alleges the four labs made an illegal deal on 12 September when their CEOs publicly endorsed Amodei’s “pace the frontier” essay. Early-stage litigation; the claim is the plaintiffs’.
  • Big Tech uses guarantees to keep $300bn of AI exposure off balance sheets — Financial Times investigation, 20 September. Alphabet’s data-centre guarantees jumped from $16.9bn to $43.8bn in six months with under 2% booked as a liability, and Meta’s Louisiana project runs through a Delaware SPV backed by roughly $28bn of residual-value guarantees. FT-reported figures, corroborated by secondary reporting; the article itself is behind the paywall.
  • Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk — InfoWorld, 22 September. A default-enabled ZCode workflow silently packaged entire local repositories, including .git history, LFS cache and app configs, and uploaded them to Alibaba Cloud OSS. Z.ai disabled the feature in v3.14.0 and deleted the bucket, with NSFOCUS confirmation. A permission problem, in the words of one security vendor, not a model problem.
  • Project Swap: what happens when agents trade for us? — Anthropic Research, 24 September. In a controlled barter market of 201 employees, agents matched their person’s book preferences on 61% of pairs after a five-minute chat, and markets run on stronger models were more efficient. Anthropic’s own research; early evidence on what agent-run commerce will require.
  • Zuora lets finance agents take action with human sign-off — Zuora, 22 September. Supervised Mode lets AI complete quote-to-cash work such as write-offs and revenue releases while a person approves each action, with an AI Audit Trail and second-reviewer routing. Vendor claims, and a concrete example of the supervised-action pattern EP teaches.
  • Anthropic’s annualized revenue pace reported above $100bn — Axios/Bloomberg, 18 September (late discovery, briefed 21 September). The New York Times reported Anthropic pacing above $100bn annualized revenue, up 50% in two months, as it prepares for a listing. Press-reported market figures, not audited results.

From the week’s discussion on X

Riz Pabani

Execution, Exponential Partners

Riz helps executives and their teams figure out where AI actually creates value — then builds the capability to capture it. Former Goldman Sachs, Nomura, and Bank of England; led partnerships at the Cardano Foundation. MIT-certified in AI products.

Related Insights