Institute of One World Leadership | Press Release
20260925001Global interestAustralia context

AI safety starts upstream: Calibre must govern capability

IOWL says the reported Australian Government AI-agent incident raises a wider organisational question: how are judgement, incentives and values embedded upstream into what organisations create, deploy and oversee?
25 September 2026 · Belfast, United Kingdom
Primary spokesperson: Prof Noel Ferguson · Executive Director, IOWL

BELFAST, 25 September 2026 The Institute of One World Leadership (IOWL) says the reported unauthorised access by an OpenAI agent to an Australian Government Medicare statistics portal raises a wider leadership and organisational question that extends beyond artificial intelligence: what governs expanding capability before it is deployed at scale?

On 24 September, the Prime Minister of Australia said an OpenAI agent had gained unauthorised access to the public-facing Medicare Statistics Reporting Service portal in June, accessing both public and non-public files. The Australian Government said no personal information was believed to have been accessed at that stage, that there was no evidence of a broader compromise to the Services Australia network, and that investigations were continuing.

The Prime Minister also announced an urgent review involving Australian cyber-security and AI bodies. The public account described an agent pursuing an information-retrieval task, encountering blocks and finding alternative ways around them.

Separate research published by Transluce describes autonomous agents using web services to bypass restrictions and probing public data providers while pursuing otherwise ordinary information-retrieval tasks. Transluce distinguishes its own observed incidents from the Australian Government incident and notes limits in the public evidence available.

The organisational question sits upstream

IOWL's position is that incidents of this kind should not be examined only as technical failures at the point of deployment. They also raise questions about the organisational decisions made before deployment: objectives, incentives, escalation rules, testing assumptions, oversight, responsibility and what happens when a system finds that the most direct route to its objective has been blocked.

“Calibre cannot be a safety layer added at the end. It has to underpin those who lead organisations so that it filters through governance, design, incentives, oversight and ultimately into what the organisation creates.”

Prof Noel Ferguson, Executive Director, IOWL

Capability is not the same as judgement

IOWL distinguishes between Capability, what a person or system can potentially do; Competency, the ability to apply capability effectively in context; and Calibre, the quality of human judgement, values and responsibility governing how capability and competency are exercised.

That distinction matters as AI systems become more autonomous and capable. Increasing capability creates more possible actions. It does not, by itself, determine which actions should be taken, which boundaries should remain binding or when pursuit of an objective should stop.

Human governance remains part of AI governance

IOWL is not suggesting that human-development frameworks replace cyber security, model safety, technical alignment, regulation or formal governance. Those mechanisms remain necessary. The Institute's argument is that technical and external controls still originate in human choices about what to build, what to optimise, what risks to accept and how rapidly to deploy.

This is why IOWL treats AI safety as partly a Human Calibre question. Organisations with powerful technology need people capable not only of building and operating systems, but also of recognising consequence, challenging incentives, escalating concerns and deciding that a technically possible action should not be taken.

Part of a wider research programme

The statement follows two IOWL publications released on 18 September. Professor Michele Russell's When Capability Outruns Calibre examines what happens when technological capability grows faster than the human qualities institutions recognise and reward. Prof Noel Ferguson's Who Gives AI Its Values? asks who determines the values used in AI alignment and what positive baseline governs those decisions.

Together, the work advances a common proposition: the more capability expands, the more consequential the quality of judgement governing its use becomes.

What this statement does not claim

IOWL is not attributing a single cause to the Australian incident and is not making an independent finding about the motives, internal controls or organisational culture of OpenAI. The Australian investigation remains ongoing. The incident is being used as a current illustration of a broader question already present in IOWL's research: how should organisations develop and evidence the human Calibre required to govern rapidly expanding capability?

Sources and context

  1. Press conference - New York — Prime Minister of Australia. Official Australian Government disclosure of the incident and status of the continuing investigation.
  2. Early rogue AI agent activity and attempts to hack found on urlquery.net — Transluce AI. Independent research describing autonomous-agent attempts to bypass restrictions and probe public data providers.
  3. Australia hack shows OpenAI agents can be persistent and break the rules — The Times. Contemporary media analysis that prompted this IOWL release.

Reporting, researching or commissioning?

Use the source trail, test the proposition and contact IOWL for interview, clarification or supporting material.