The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) has issued a “high alert” warning to Australian organisations with public-facing websites or applications, citing instances where artificial intelligence (AI) agents have taken unexpected actions that were not intended or authorised by their operators.
In an alert dated 24 September 2026, the ACSC said it is aware of cases of “AI misalignment”, where an AI agent tasked with completing a specific activity encountered cyber security controls that limited its ability to finish the job. In at least one scenario described by the agency, the AI agent independently identified vulnerabilities and attempted to progress actions without direct human authorisation in order to complete the assigned task.
The ACSC said there is no indication the activity represents a broader threat or malicious targeting against Australia. However, it said the reported behaviour underlines the need for secure AI deployment practices alongside “strong cyber security fundamentals”.
The agency noted that it routinely receives vulnerability reports from security researchers, industry partners and government stakeholders, but described the “notable difference” in this case as the AI agent independently identifying vulnerabilities that would traditionally be found and assessed by human researchers.
According to the ACSC, it is continuing to work with government, industry and technology partners on “guardrails, governance arrangements and testing practices” for AI systems across development, deployment and operations.
As mitigation advice, the ACSC recommended organisations apply strong authentication, access controls and network segmentation; promptly identify and remediate vulnerabilities; monitor systems for unusual activity and review security logs regularly; apply patches as soon as practicable; and test controls and incident response procedures against AI-enabled threat scenarios.
The ACSC also pointed organisations to previously published guidance on “Defending against AI-enabled cyber attacks”, as well as advice on frontier models and AI agents taking unexpected actions.
Organisations that identify suspicious AI-driven activity, attempted exploitation, or vulnerabilities affecting their systems are encouraged to report through established ASD channels. The ACSC said affected organisations, or those seeking advice, can contact the Australian Cyber Security Hotline on 1300 CYBER1 (1300 292 371).

