FutureScot
Cyber

Former NHS Scotland tech boss questions whether ‘our institutions are ready’ for autonomous AI after Australian healthcare breach

Deryck Mitchelson says the Australian healthcare breach 'hits close to home'. Photograph: Paul Watt

A former NHS Scotland technology boss has questioned whether ‘our institutions are ready’ for autonomous AI after an Australian government website was breached by rogue OpenAI agents.

Deryck Mitchelson, who helped build critical NHS systems during the Covid pandemic, said the cyber incident affecting the national Medicare system in Australia should serve as a warning to all healthcare organisations.

Mitchelson, who is now the chief information security officer (CISO) at Glasgow-headquartered cybersecurity firm Systal, said the breach especially resonated given his time as National CIO for NHS Scotland, from 2018 to 2022.

He said: “As someone who has led healthcare technology at a national level, this story hits close to home. Healthcare systems hold some of the most sensitive data in existence, and they are increasingly dependent on AI to process and analyse it. 

“The Australian breach involved an agent researching healthcare spending – but the implications go far beyond one government system. If autonomous AI agents can bypass permissions in one healthcare environment, every organisation that has given AI access to patient data, clinical systems or health records needs to ask: what are the boundaries we’ve set, and are they actually enforced?”

Mitchelson spearheaded the delivery of several high-profile projects during his time at NHS National Services Scotland, including the Protect Scotland contact tracing app, the QR-code based ‘check in’ app, and the Covid passport app.

He took up his current role with Systal – the delivery partner for NHS Scotland’s security operations centre (SOC), which provides an incident response capability to ensure 24/7 protection across NHS Scotland’s assets, infrastructure, and patient data – in May this year.

He added: “The OpenAI breach is a warning, but not for the reason the headline suggests. Our security systems were designed around human behaviour and clearly defined permissions. Autonomous AI agents don’t operate that way – if given a goal, they find another route to achieve it. We’re now giving AI access to websites, data, code and consequential systems. The question isn’t whether AI can act independently. We now know it can. The question is whether our institutions are ready for it.”

However, Mitchelson suggested the breach, which was revealed yesterday at the United Nations by Australian prime minister Anthony Albanese, is not about an AI suddenly becoming “rogue” or deciding to attack a government.

He added: “It is about something much more important: AI systems are increasingly capable of taking actions, not just answering questions.”

According to the Australian government, an OpenAI agent had been tasked with researching healthcare spending – but took that one step further by bypassing restrictions, accessed public and non-public files and wrote files into a government system.

OpenAI says the activity happened during an internal evaluation and that its models took actions the company did not intend. It says there is no evidence individual patient records were accessed, a position backed up by the Australian government’s own checks.

Critics, though, have pointed to the length of time it took to discover the breach, internally at OpenAI, and then to inform the Australian government.

It is thought the breach occurred on 18 June 2026, when an autonomous OpenAI agent bypassed security blocks to infiltrate a public Medicare statistics portal.

OpenAI reportedly didn’t discover the breach, though, until last month during an internal review of “misaligned model activity”.

They subsequently informed the Australian government nearly three months after the initial incident by sending an email to a general, public-facing Services Australia inbox on the 10th of September. The email was escalated to Australia’s cybersecurity centre before a government minister was notified and the prime minister alerted.

The delay and the casual method of notification drew sharp criticism from Australian Prime Minister Anthony Albanese, who described the timeline as “obviously unacceptable”.

Mitchelson added: “This isn’t an argument to stop AI development. It is an argument for much stronger oversight, permissions, monitoring and accountability as AI becomes more autonomous.

“An autonomous AI agent doesn’t necessarily understand a permission boundary in the same way a human does. If it is given a goal, it may simply look for another way to achieve it. That changes the cybersecurity equation.”

Related posts

New public-facing cyber hub receives ‘substantial’ donation from Arnold Clark

Kevin O'Sullivan
September 17, 2024

Leading Scottish cloud services company Brightsolid hires two senior executives

Kevin O'Sullivan
March 10, 2023

Scotland’s leading cyber fraud organisation issues Fringe festival ticket scam warning

Kevin O'Sullivan
August 5, 2024
Exit mobile version