Australia faces security challenges as agentic AI expands into everyday life

The rise of autonomous AI agents, capable of performing complex tasks, is prompting urgent security and privacy concerns in Australia, as systems become more powerful and more connected, blurring the lines of control and trust.

AI agents are moving the discussion about artificial intelligence beyond chat. For many Australians, generative AI has meant a tool that answers questions or produces text on demand. The newer wave is different: it is designed to act, not just respond. Stephen Kho, director of offensive security at Gen, describes agentic AI as “AI with hands and feet”. In practical terms, that can mean an assistant that reads email, sorts messages, drafts replies, updates calendars and carries out routine tasks across connected services.

That shift matters because the central issue is no longer only what an AI system can say, but what it is allowed to do. The more useful an agent becomes, the more access it usually needs to email, files, calendars and sometimes financial or business systems. Kho says that can be powerful, but it also means users may be granting broad permissions without fully understanding the consequences. In enterprise settings, access is typically restricted and monitored. For everyday users, the controls are often looser and the risks less visible.

The security concern is growing as AI skills and extensions become part of the ecosystem. Research cited by TechRadar Pro says Zenity Labs found a credential-stealing campaign on a public skills registry, where malicious actors cloned legitimate tools, used lookalike names and later inserted code that could pull SSH keys, cloud credentials, Git tokens, Docker files and database data. One family of those skills was reported to have more than 1.7 million installs. That pattern mirrors traditional software supply-chain attacks, but it is now aimed at AI environments where an agent may be authorised to act across multiple systems.

Cybersecurity specialists are warning that older security models are not built for this level of autonomy. TechRadar Pro reports that organisations increasingly need continuous monitoring, auditable logs, verified AI identities and fail-safe controls for higher-risk actions. Some vendors are responding with guardrails of their own; Gen has introduced Sage, a protection layer meant to inspect agent activity and flag risky behaviour before it is carried out. The aim is not to block AI adoption, but to keep it within boundaries that users and businesses can understand and govern.

The consumer side of the shift is arriving too. Amazon has launched Alexa+ in Australia, with early access beginning on August 6, 2026, according to Tom’s Guide. The upgraded assistant can handle more natural conversation and more complex tasks, including smart-home control, email handling and appointment scheduling. Amazon says users can review and delete interaction histories through a privacy dashboard, but the rollout also underlines the wider tension around agentic AI: convenience is increasing at the same pace as the amount of trust these systems require. For users and businesses alike, the practical question is becoming less about whether AI can help and more about where to draw the line on access.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.