The Essential Eight is not enough for AI-enabled cyber attacks
The Essential Eight is a vital protective baseline, but it is not enough to protect against AI-enabled cyber threats. Why organisations need stronger controls, assurance, resilience and recovery in the age of AI agents.
The Essential Eight* is a valuable, practical and overdue cyber security baseline in far too many organisations. But I worry that we have started treating it as the finish line, rather than what it actually is: a baseline.
The Australian Signals Directorate is clear that the Essential Eight makes it harder for adversaries to compromise systems. But it does not guarantee protection against every threat. That matters now more than ever, because if we do not have even the cyber basics in place, we are even more vulnerable to AI agent-based attacks.
AI does not need to invent a new class of vulnerability when too many organisations still have unpatched systems, weak identity controls, excessive permissions, fragile integrations and inadequate monitoring. It can simply find and exploit the weaknesses already sitting in plain sight.
Cyber resilience requires more than implementation of eight controls. It requires an active control environment that understands critical assets, manages third-party exposure, detects threats, rehearses response, verifies recovery and gives boards evidence that controls actually work.
The warning has arrived
This is no longer an abstract discussion about what capable AI agents might do in the future. It is happening now.
Prime Minister Anthony Albanese has revealed that an AI agent developed by OpenAI gained unauthorised access to the public-facing Medicare Statistics Reporting Service portal, administered by Services Australia, in June 2026. The agent accessed public material as well as files not intended for public release. OpenAI agent breached Medicare, Albanese reveals.
The government says the evidence available indicates there was no broader compromise of the Services Australia network. That is reassuring, but it is not the whole story. An AI agent crossed an access boundary into a government service and accessed material that was not meant to be public.
The Prime Minister called the incident unacceptable and said he had raised Australia’s concern directly with OpenAI chief executive Sam Altman, including concern about the delay and manner of the company’s notification.
That should be a wake-up call. The Essential Eight remains a sensible foundation, but basic cyber hygiene alone cannot manage the risks created by highly automated, persistent and capable attackers.
A baseline, not a destination
The Essential Eight addresses important attack paths: application control, patching applications and operating systems, restricting administrative privileges and Office macros, user application hardening, multi-factor authentication and regular backups. Check out this handy Essential Eight explained.
Every organisation should implement these controls properly. If they are absent, incomplete or inconsistently applied, they give AI-enabled attackers the same advantages they have long given human attackers, only at greater speed and scale.
Implementation against a maturity model is not the same thing as being resilient when an attacker gains an initial foothold, a supplier is compromised, an identity platform fails or a critical service is disrupted. A maturity rating is not a comfort blanket, a procurement badge or a board slide declaring the job done. It is evidence of progress against a defined subset of controls.
AI changes the control problem
The Medicare incident should be understood as a control challenge in a world of capable AI agents. It does not mean the Essential Eight has failed. It means the security model needs to account for attackers that can automate reconnaissance, test exposed systems, identify weak configurations and pursue connected pathways at machine speed.
I have written previously about how AI has changed the cyber threat landscape. The core point remains the same: AI and cyber security are no longer separate conversations.
Modern compromise is rarely one dramatic failure. It is usually a chain: a vulnerable component, an identity weakness, overly broad permissions, a trusted integration and insufficient monitoring. An attacker does not need an extraordinary breakthrough if the environment already provides a pathway.
As I discussed in When AI escapes containment: rethinking data protection in the agentic era, we need to consider AI agents as potential privileged insiders. They may be able to combine code analysis, network scanning, open-source intelligence and access to internal tools far faster than a human operator.
The practical shift is straightforward. Organisations must assume that attackers can use automation and AI to find weaknesses faster than traditional security teams can manually identify and remediate them.
Controls need governance
Cyber security is not simply a technology implementation task. It is a governance discipline requiring clear accountability, risk appetite, investment decisions and meaningful assurance.
NIST’s Cybersecurity Framework 2.0 includes Govern alongside Identify, Protect, Detect, Respond and Recover. NIST’s Cybersecurity Framework 2.0 recognises that cyber security cannot be delegated entirely to the CIO, CISO or an outsourced provider.
This is also where cyber governance and AI governance converge. As I argued in What we need to think about for effective AI governance, good governance is not a standalone AI project. It is built on the existing disciplines of data governance, cyber security, risk management and sensible leadership.
Boards and executives should expect credible answers to these questions:
- Which business services are genuinely critical, and what level of downtime is acceptable?
- Where are the organisation’s most important data, systems, identities and dependencies?
- Which risks have been accepted, by whom, for how long and with what compensating controls?
- Which suppliers, cloud platforms and managed providers could create a material disruption?
- Can the organisation detect an intrusion before sensitive information or critical services are affected?
- When was the incident response plan last tested in a realistic exercise?
- Can backups be restored within the recovery time the business actually requires?
If those answers are unavailable, inconsistent or dependent on a spreadsheet nobody trusts, the organisation does not have effective cyber governance.
What must sit around it
The Essential Eight should remain the floor, but a serious cyber control environment needs more.
| Control area | What good looks like |
|---|---|
| Asset and service visibility | A reliable view of critical services, systems, data, identities, owners and dependencies |
| Identity security | Strong MFA, least privilege, privileged-access management, lifecycle controls and continual review of access |
| Detection and monitoring | Centralised logging, security monitoring, alert triage and tested detection coverage for priority threats |
| Incident response | Defined decision rights, playbooks, communications plans, external support arrangements and regular exercises |
| Recovery and resilience | Tested restoration, isolated backups, recovery objectives and business continuity integration |
| Third-party risk | Security requirements in contracts, visibility of critical suppliers, assurance reviews and contingency arrangements |
| Secure delivery | Security built into software, infrastructure and configuration change, rather than checked at the end |
| Data protection | Classification, minimisation, encryption, retention, access controls and a clear understanding of sensitive-data flows |
| People and culture | Role-based education, phishing resilience, insider-risk controls and a culture where reporting is safe and expected |
This is especially important where public-facing services connect to sensitive data, identity systems, cloud platforms and third parties. The critical issue is not simply whether a system has been patched. It is whether its architecture, access controls, monitoring and response arrangements prevent an initial intrusion becoming a serious incident.
Evidence matters more than policy
A policy is not a control. A dashboard is not assurance. A vendor attestation is not proof that an organisation can recover from a real attack.
The test is whether controls operate effectively in the real environment, including the awkward parts: legacy systems, exceptions, shadow IT, privileged accounts, acquisitions, contractors and cloud services configured by multiple teams.
ASD’s Essential Eight guidance recognises that organisations must assess implementation and maturity, not simply declare compliance. That assessment needs to extend to attack simulation, access reviews, configuration evidence, incident exercises, restoration tests and independent validation of the controls protecting critical services.
Exceptions should not become permanent. They need named owners, expiry dates, documented compensating controls and active review by the people who own the risk.
A better question
The Essential Eight remains one of Australia’s most useful cyber security interventions. It provides an achievable foundation and removes excuses for avoiding basic cyber hygiene.
But the Medicare incident is a warning that the foundation is not enough. An AI agent gained unauthorised access to a government portal and accessed files that were not intended to be public.
If an organisation does not have even the cyber basics in place, it is vulnerable to AI agent-based attacks. If it does have the basics in place, it has only established the minimum platform from which to build real resilience.
The real question is not: “Have we achieved Essential Eight maturity?”
It is: “What evidence do we have that our critical services can withstand, detect, respond to and recover from an AI-enabled attack?”
*ASD to retire Essential Eight within two years, consults on replacement