All articles

Insights · 25.09.2026 · Valarian Team

What an OpenAI Agent Hacking Australia’s Medicare means for Governments

Sensitive data must be moved to a true zero-trust digital infrastructure now.

What an OpenAI Agent Hacking Australia’s Medicare means for Governments

On 18 June, an OpenAI agent hacked Australia’s national health service. It took over two months for the Australian government to find out.

The hack might not have been intentional – it does not matter. All public services that deal with highly sensitive information must take decisive steps to prevent this from happening to them.

There are three key takeaways:

  1. It cannot be dismissed as a “one-off” – it is another incident in a fast growing list of hacks by AI agents.
  2. We are reliant on model providers to disclose the hack; they may do so via email (as was the case here). If governments start taking action against them, providers might be disincentivised to inform the government, or worse, withhold their models.
  3. Current public sector infrastructure, on which so much of our data is stored, is not ready for these kinds of breaches.

We have an urgent problem. A trust and overreliance problem. And a digital security and infrastructure problem. All of these point to the need for a zero-trust and high internal visibility approach when dealing with sensitive data.

There are some steps which can be taken immediately to address these problems.

Sensitive data must be moved to a true zero-trust digital infrastructure. Infrastructure that keeps customers in control of their data, agents, and inference. This means your data does not leak to model providers – access will be never given or revoked – and any agents that are deployed to make services more efficient only get access to what the task requires and nothing more.

ACRA was built to solve this:

1. Data boundaries. AI cannot read cipher text – you have to de-encrypt your data (the query and the data it contains) for the LLM to respond to the prompt. That is the point of danger, where you reveal your data and, more importantly, the interpretation of that data, to the model provider. With ACRA, you can API into a frontier lab – revealing the prompt but not the underlying source documentation – or, for maximum privacy, deploy open weight models inside an enclave. Here, the model, prompts, documents, search tools, outputs, and supporting data stay inside the controlled environment. The data never leaves your organisation, without diminishing your AI capabilities.

2. Agent containment.ACRA creates a secure boundary to deploy agents in isolated enclaves – agents only access the data you provide, are subject to universal permissions by default, and are confined by architecture within the enclave perimeter. ACRA provides the layer around the AI model: the user interface, the tools the AI is allowed to use, the information it is allowed to retrieve, the network connections it is allowed to make, and the audit trail of what happened. This zero-trust approach to models, agents and users protects the data you control and limits the blast radius when things go wrong.

All of this comes with a further right: the encryption keys are yours. Not held by the platform on your behalf, not in the custody of the vendor, but yours, so that not even the infrastructure provider can read your content.

For too long, organisations have been offered a false choice. On one side are slow, disconnected systems that keep data tightly held but make it hard to act. On the other are large external platforms that promise capability, but do not offer the necessary isolation at an infrastructure level, risk the creation of single-supplier dependency, and have unclear ownership and difficult exit routes.

AI should improve capability, but it should not weaken sovereignty. Organisations should be able to modernise without surrendering control of the systems and information they use and own. With ACRA they can.

Deploy infrastructure
you control.

Company

About Careers

Resources

Blog Contact

Compliance

Privacy
Established 2020 · London

Control infrastructure for high-consequence systems.
© 2026 Valarian · London

Made in the UK