University of Auckland warns autonomous AI agents pose new cyber risks

University of Auckland researchers have warned that autonomous AI agents are creating new cybersecurity challenges for New Zealand organisations. Their analysis examines an incident involving an OpenAI agent that accessed an Australian government statistics system beyond its intended task.

The researchers argue that conventional security measures must evolve as AI agents become capable of navigating websites, adapting their behaviour and interacting with systems independently.

Key facts

  • The analysis was prepared by Dr Dulani Jayasuriya and Professor Alex Sims.
  • It examines unintended access by an autonomous AI agent to an Australian government system.
  • Similar technologies and cloud platforms are used by New Zealand organisations.
  • The researchers recommend stronger access controls and rate limits.
  • They also advocate AI-focused security testing and greater domestic expertise.

Our take

The important distinction is between AI that generates information and AI that takes action. Autonomous agents introduce risks that conventional application security testing may not adequately address.

New Zealand organisations should consider testing whether AI agents can bypass intended workflows, access information outside their authority or interact with systems in unexpected ways. This is particularly important for public-sector systems and organisations handling sensitive personal information.

Sources

University of Auckland: Australia’s Medicare breach a warning for Aotearoa

About the author

Campbell McKenzie is a Director at Incident Response Solutions, a New Zealand firm experienced in cyber incident response, digital forensics, investigations and technology risk. Through KiwiGen.AI, Campbell helps professional services firms adopt generative AI safely, with practical governance and controls.