← Newsroom Media release · For immediate release

Who gave the agents the keys? CiBRAI publishes a framework for putting AI agents to work under human authority

As the Federal Government investigates an AI agent’s access to a Medicare statistics portal, Australian cyber security company CiBRAI has released a practical operating model for building teams of people and AI agents with clear jobs, owners, limits and a way to stop.

AUSTRALIA, 25 September 2026. Australian cyber security company CiBRAI today released “Who gave the agents the keys?”, a 17-page whitepaper setting out the CiBRAI Agentic Business Framework. Written by CiBRAI founder and Chief Information Security Officer Andrew Curtis, the paper argues that deploying AI agents is a business design decision, not only a technology one, and gives executives a team charter to complete before the first agent starts work.

The release follows the Prime Minister’s confirmation this week that an OpenAI agent accessed public and non-public files on a Medicare statistics portal in June. The Government has said no personal information was accessed, and a multi-agency taskforce working with the Australian Signals Directorate (ASD) and the AI Safety Institute is investigating. Separately, ASD guidance published this month states that prompt injection cannot be fixed inside the model itself, and that controls must sit in the software surrounding it.

“Every agent needs a job, a boss, a boundary and a brake,” said Andrew Curtis, CISO and founder of CiBRAI. “Software can now plan, use tools and coordinate work. The business therefore needs to decide how people and agents will work together, what each contributes and where their authority ends.”

The framework organises human-agent teams around six connected disciplines: Purpose, Accountability, Knowledge, Authority, Collaboration and Assurance. Each one produces something a manager can inspect, from named owners and deputies to information boundaries, independent approvals and rehearsed recovery. People keep the judgement, relationships and responsibility; agents gather approved information, prepare options, challenge assumptions and coordinate permitted work.

Practical recommendations in the paper include:

  • A charter before a pilot. Ten fields, from shared outcome and permitted knowledge to decision rights, operating limits and a documented stop and fallback, completed with named people before any agent is deployed.
  • An independent second key. For consequential actions, proposing, approving and executing are separated, and an enforcement gate checks that the required people approved this exact action, scope and expiry. Two agents agreeing is not independent authority.
  • Controlled answers, not universal visibility. Agents receive only the permitted answer they need. As the paper puts it, “Information is not authority. A useful answer grants no new powers.”
  • Rehearse the bad day. Test poisoned sources, unavailable approvers, exhausted limits and failed services, and measure the time it takes to stop every worker and pending action.
  • A 90-day path. Design one low-risk team, rehearse the work, then prove a limited service, with a decision to continue, narrow, redesign or retire made on evidence.

“A valid login cannot rescue a badly designed job,” Mr Curtis said. “Identity tells us who is acting. The operating model determines why they are acting, what they need to know and which decisions belong to someone else.”

The framework draws on current guidance from ASD’s Australian Cyber Security Centre and international partner agencies, which recommends agentic AI only for low-risk, non-sensitive tasks, as well as NIST, Singapore’s Infocomm Media Development Authority and the OWASP Top 10 for Agentic Applications. Its worked example, a public threat-research support team for a security operations centre, is designed to stay within that scope: agents prepare the brief, and people decide the response.

The paper also applies the model beyond cyber, showing how a sales, operations and finance team can use agent support without handing a single coordinator the combined powers of every department.

“The next great organisation chart will include software,” Mr Curtis said. “The responsibility at the top will still be human.”

The CiBRAI Agentic Business Framework is available free at cibrai.com/cibrai-agentic-business-framework, with the full whitepaper available as a PDF download.

ENDS

About CiBRAI

CiBRAI is an Australian cyber security company specialising in agentic AI. It applies the CiBRAI Agentic Business Framework as a core part of its cybersecurity operating platform and the way it designs human-agent security operations. CiBRAI works alongside its sister consultancy GadgetAccess. cibrai.com | gadgetaccess.com

About Andrew Curtis

Andrew Curtis is a CISO and the founder of CiBRAI, with more than 20 years of experience across enterprise and government cyber security, architecture, governance and uplift programs.

Interview availability

Andrew Curtis is available for interview and comment on agentic AI governance, human oversight of AI agents, and how Australian organisations can apply current ASD guidance in practice.

Media contact

Andrew Curtis | Founder and CEO, CiBRAI
acurtis@cibrai.com | +61 416 143 454 | www.cibrai.com

Notes to editors

The whitepaper cover and security-team artwork can be downloaded from the CiBRAI media kit. Both are illustrative conceptual images created with AI image generation and are not product screenshots. Quotations may be attributed to Andrew Curtis, CISO, CiBRAI.