Government alert
A routine task can cross an unintended boundary
An AI agent is software that can take steps towards a goal, such as using a browser or calling another application. The ASD AI agent alert, published on 24 September 2026, describes cases where agents took unexpected actions that their operators had not intended or authorised. In one scenario, an agent independently identified vulnerabilities and attempted to progress its task after security controls blocked the intended route. Read the original ASD advisory.
ASD says there is no indication that this activity represents a broader threat or malicious targeting against Australia. The alert does not identify Sydney businesses as a special target. It does, however, apply to Australian organisations with public-facing websites or applications, including those that do not use AI themselves.
For a small business, that creates two jobs. Keep the systems you expose to the internet secure, and put enforceable limits around any AI tools you authorise to act. A task that sounds harmless to a person can still lead to an unexpected action when software pursues the outcome.
At a glance
Protect your website and control your own AI
Protect what is public
Even if you do not use AI
Control what AI can do
When you use AI tools
Business responsibilities
Put a name beside each security task
Consider a hypothetical accounting practice in Parramatta. Its website developer updates pages, a hosting company runs the server, and an IT provider supports staff computers. A security advisory arrives while the practice manager is handling client deadlines. Each supplier can be doing its agreed job while nobody has accepted responsibility for the website plugin update.
Ask for the responsibility split in writing. Hosting, website maintenance and office IT support are different scopes. A hosting invoice alone does not tell you who checks application advisories or tests the site after a change. The same question applies to a Penrith trades business whose quote form feeds enquiries into a separate booking platform.
Business owner
Nominate a decision maker for urgent changes. Identify the website functions that cannot remain broken, and agree who can approve a short interruption when a security update needs attention.
Website maintainer
Confirm responsibility for the content management system, themes and plugins. Ask who receives advisories, installs fixes and checks enquiry forms after updates.
Hosting provider
Confirm the server and platform responsibilities, available security logs and recovery arrangements. Ask where the hosting team hands an issue over to your website developer.
IT support provider
Confirm the devices, identities and services covered by the support agreement. Record how the team coordinates with the website maintainer when an incident crosses those boundaries.
Separate current example
What the WordPress security update illustrates
WordPress 7.1.2 addresses a critical vulnerability, CVE-2026-87902. The official vulnerability advisory, published on 22 September 2026, describes an unauthenticated page-template path traversal issue. Under particular theme and server conditions, it can lead to remote code execution. In plain language, a successful attack could cause the server to run code it should not run.
Those conditions matter. This is not a statement that every WordPress website allows remote code execution. WordPress recommends updating immediately and has also provided patched releases for older branches. The release announcement credits researcher Robert Ressl for responsible disclosure.
This is a separate example, not a vulnerability identified in ASD's reported incidents. Neither advisory establishes that connection. The practical link is ASD's recommendation to identify and remediate vulnerabilities promptly. Public-facing software needs attention regardless of whether the activity reaching it comes from a person, a conventional script or an AI agent.
Ask your maintainer to confirm the installed patched version, rather than sending a screenshot showing only that an update is available. Core software, plugins and themes have separate release cycles. Updating one does not prove the others are current. If a licence or download error blocks a security update, give it an owner and an escalation deadline.
Change control
Patch promptly without losing the enquiry form
A critical security release needs an urgent decision. Waiting for the next monthly maintenance visit can leave a known weakness exposed. An uncontrolled update can also interrupt the part of the website that brings work into the business. Agree a proportionate process with the people responsible before the next alert.
Before the update
Confirm the affected component and vendor advice. Check that a recent backup exists and that someone can restore it. Identify the forms, bookings or payments that need testing.
After the update
Read back the installed version. Test the important customer journey on desktop and mobile, including delivery of a test enquiry. Review errors and record who checked the result.
Use staging where available, but do not let a lengthy test schedule become an indefinite delay for an urgent fix. Your maintainer should assess exposure and discuss temporary protection or restricted access if the patch cannot be applied promptly. Rolling back to a vulnerable version is not a complete security resolution.
When comparing business web hosting, ask how recovery and platform support fit with the maintenance agreement. For broader coordination, Sydney IT support should have a documented escalation path to the supplier that owns the affected component.
Automation permissions
Set limits before connecting an AI agent
An agent that can read a document has a different risk profile from one that can send emails or change a live website. Start with a defined task and the minimum access it needs. Our AI readiness guide explains how to begin with one real use case. For agents, document which actions require a person to approve them.
Use separate, restricted accounts where the platform supports them. Keep production administration outside the default access scope. Require human approval before publishing, changing permissions or exporting sensitive records. Test what happens when a requested action is blocked. A safe workflow should stop and escalate rather than receive broader access simply to finish the job.
Written instructions alone are insufficient. Enforce restrictions through application permissions and the tools the agent can actually invoke. Keep activity logs, nominate someone to review exceptions and make sure an authorised person can stop the workflow and revoke access. ASD also recommends testing controls and incident response against AI-enabled scenarios.
ThreatLocker application control is a separately scoped option for controlling software execution and constraining approved applications on supported endpoints. Duo MFA is a separately scoped option for strengthening supported account access. Neither replaces website patching or an AI agent's own permission controls. Scope the protection to the system and action you need to control.
Ask for evidence
Four checks a business owner can request
Named owner
A current record showing who maintains each internet-facing service and who makes an urgent decision if the usual contact is unavailable.
Installed fix
The component name and patched version, with the completion time and the customer functions tested afterwards.
Access boundaries
A list of the AI agent's accounts and permissions, actions requiring approval, and the person authorised to stop it.
Response record
An alert destination, a log-review owner and a tested escalation path. Suspicious activity needs investigation even when the website still appears to work.
FAQ
Common questions from business owners
Does the ASD AI agent alert apply if we do not use AI?
Yes. ASD says the alert is relevant to Australian organisations with public-facing websites or applications. Your own use of AI is a separate question. Keep exposed software patched and monitor for unusual activity.
Was the WordPress flaw involved in the ASD incidents?
The official ASD alert and WordPress advisory do not establish that link. WordPress 7.1.2 is a separate example of prompt vulnerability remediation. Remote code execution depends on the theme and server conditions documented in the WordPress advisory.
Should we give an AI agent administrator access?
Our recommendation is to start with the minimum permissions needed for a defined task. Keep consequential actions behind human approval and enforce those limits through system permissions. Broad access should not be the default response when an agent cannot complete a task.
What should we do if we notice suspicious activity?
Contact the provider responsible for the affected system, preserve relevant logs and follow your incident response process. ASD asks organisations to report suspicious AI-driven activity, attempted exploitation or vulnerabilities through its reporting channels.
Explore more
Related guidance and services
Application control
Explore ThreatLocker for scoped application allowlisting and restrictions on supported endpoints.
Business web hosting
Review hosting options and clarify the split between platform support and website maintenance.
AI readiness
Start with one use case and decide what the business needs before connecting more tools.
Incident response
Review incident response support before an urgent event leaves your team searching for contacts.
Source notes
Read the original advisories
Sources checked on 24 September 2026. The local business scenarios above are hypothetical. The operational checklist and diagram are Milnsbridge recommendations, not a claim that ASD has endorsed a particular product.
Sydney and Penrith
Clarify who owns your next security update
Bring the names of your website maintainer and hosting provider, plus the systems your staff rely on. We can discuss where IT support fits and what needs separate scope. Milnsbridge reports a 20-second average answer time and 87% first-call resolution.
About the Author
Adrian Weir
Adrian Weir is the Managing Director and founder of Milnsbridge Managed IT Services, with over 30 years of global IT experience spanning Telstra, Citibank, Unilever, and hundreds of Sydney SMBs. A Microsoft Partner since 2002, Adrian leads a team of IT specialists delivering responsive, business-focused managed IT support across Greater Sydney.
Meet the Milnsbridge Team
