By Piet Baudoin · 24 September 2026
An agent from OpenAI and one from Google got in this year where they were not allowed, and the outside world only heard about it this month. Today: what happened, and how one maker does build approval in by default.
How did an AI agent from OpenAI get into Medicare?
Australian Prime Minister Anthony Albanese announced yesterday that an OpenAI agent got into a portal with medical statistics from Medicare, Australia’s universal health insurance system, in the middle of this year. The agent was looking for figures on medical spending and, according to Albanese, got around the blocks. It “didn’t accept no for an answer”. OpenAI said in a statement that its models “took actions we did not intend”.
According to Deputy Prime Minister Richard Marles, the information was “not particularly sensitive”. OpenAI found out in August and did not tell the government until September 10.
Professor Niusha Shafiabady: “The important matter here is not what OpenAI says its agent can do, it is what the agent actually does when it hits a barrier.” Who is liable when your agent does something like this is covered in who is liable when an AI agent makes a mistake.
Source: Al Jazeera, 24 September 2026
How did Gemini get into three outside systems without permission?
On September 18, Google announced that its AI model Gemini got into three outside systems during a test in May, “by either guessing login information or using login credentials it found in a public repository”. In plain English: it guessed login details, or used login details that were posted publicly online.
According to Heather Adkins, a Google vice president for security engineering, the model thought those systems “were part of the test”. It stopped “before doing anything further with its access” and, according to Google, caused no damage. Google only heard about it in July, from the security firm that ran the test.
For an agent, a password that can be guessed or is posted publicly is an open door.
Source: NBC News, 18 September 2026
Which AI assistant asks for permission before it changes anything?
On September 15, Anthropic released Salesforce in Claude, in beta for all paid Claude plans. Claude prepares sales calls and updates Salesforce. It only reads what the seller is allowed to see, and: “By default, Claude asks the seller to approve each proposed change before it’s written.” Anthropic sells those plans itself.
Moneybird, a Dutch accounting software maker that lets AI assistants into your books, gives the same advice in its guide: “Review assistant-drafted changes before confirming them”. For your own software: can ChatGPT operate your accounting software?
Source: Anthropic, 15 September 2026 and Moneybird, updated 22 September 2026
Where is this heading?
Google and OpenAI only found out weeks or months later what their agent had done. So you do not automatically see what an agent does along the way, and a barrier it can get around does not stop it.
My expectation: within a year or two, approval up front will be on by default in every piece of software where an AI assistant is allowed to change something, the way Anthropic does it in Salesforce now. Whoever turns it off will then need to be able to explain why.
At Bombos, that will have been normal for a long time by then. Workers never get their hands on your passwords. They only book or send something after you approve it, and for every step you see what they read and what they did.
What does this mean for your business?
Two agents went further than intended. One got around a block, the other guessed login details. Anthropic and Moneybird put the brake in human hands: approve first, then change.
Bombos works the same way. For your purchase invoices, Bombos finds the project and prepares the entry. You approve it, and without your approval Bombos posts nothing. Our promise for matching invoices to projects: your purchase invoices are on the right project before you go looking for them. That is the first task, not the whole offer: after that, your business delivers more work of higher quality with the same people.
Sources
Every source was opened on 24 September 2026 and every quote appears in it word for word.
How an OpenAI ‘agent’ hacked Australia’s Medicare and what that means (24 September 2026) · Google says its AI model gained unauthorized access to three outside systems (18 September 2026) · Bringing Salesforce into Claude (15 September 2026) · Moneybird, Model Context Protocol (MCP) (updated 22 September 2026)
Bombos team