The AI Exhale: The Medicare Breac...

The AI Exhale: The Medicare Breach - Slow Disclosure and Old Systems

Esplicito
The AI Exhale di Vibe CFO
S1 · E19
25 set 2026
06:10

Note sull'episodio

There was no attacker. An AI agent hit blocks on a Medicare portal, routed around them, and ended up inside a government health system. No criminal, no intent, nobody trying to steal anything.

So the story is not the breach. It is the silence after it. June for the breach. August before OpenAI found it internally. Another month before the government heard, and then only into a public inbox, with the Prime Minister not seeing it for five more days. Park the data for a second: for three months nobody could assess it, act on it or tell anyone.

That gap is what Albanese has taken to New York. Safeguards, mandatory disclosure, legal liability for the labs. Which raises the harder question, because open source is governed by nobody and criminals outside the jurisdiction run the same tools. So where does liability actually land? And if you run your own trained models on your own servers, does it land on you?

There is a second thing in here nobody wants to hear. AI is very good at finding vulnerabilities, and plenty of businesses are sitting on old systems they should have retired years ago. When the tool gets that good at finding gaps, the gaps become your problem.

Jez and Cam on whether this was a hack at all, who ends up carrying the can, and the one question worth asking every vendor: when something goes wrong, how many hours until you tell me, and where does the message land?

The answer is not to stop using agents. Treat one like a junior who has never been shown around the building. Defined scope, no standing access, and a log, so when someone asks what happened there is an answer.

Five minutes. One thing that matters. We ignore the rest, so you can too.

Vibe CFO is Australian founded. An AI CFO for small and medium business, out of the box, governed and secure.

Vibe in 5.

vibecfo.ai