Get in Touch with Us!

GovernIT Consulting Inc.

We turn stalled projects into delivered value through governance discipline, independent oversight, and hands-on execution.

Edit Template

The Gap Between Detection and Action

On June 18, an OpenAI agent looking up public medical spending figures for an internal evaluation bypassed blocks on Australia’s Medicare statistics portal and accessed non-public files. OpenAI says it became aware on August 11, 54 days later.

Australia heard on September 10, another 30 days on, and according to the Prime Minister the notice arrived as an email to a public mailbox.

For operators, that timeline is at least as interesting as the breach. There are two different delays in it: the time between something going wrong and someone noticing, and the time between noticing and the information reaching a person who is accountable for deciding what to do.

Most of the incident metrics I see concentrate on the first one. We monitor systems, write alerts, keep logs and report on time to detect and time to respond. But detection on its own doesn’t mean the organization knows in a way that lets it act.

Here, the first delay happened inside the company that built and ran the agent, during its own evaluation work, and it still took almost eight weeks.

The second delay gets more complicated once the chain crosses an organizational boundary. One side has to investigate the issue and decide who needs to know. The other side has to assess what it received and get it in front of someone with the authority to contain it or escalate it. A public mailbox adds another stop at the beginning.

Every step can be reasonable on its own while the total still isn’t.

I think there’s a useful operating measure in this: time to accountable awareness. How long does it take between something materially unexpected happening and a person with the authority to act understanding that it happened?

That’s different from time to detect. A system can be technically observable while the problem remains invisible to anyone who can do something about it. Alerts can fire and contractual notification requirements can be met while the information still moves slower than the risk does.

AI agents make that gap harder to ignore because they can act at machine speed while the organizations responsible for them still detect, assess, escalate and decide at human speed.

If I were giving agents more room to act this year, I’d test that chain as hard as the model itself. A simple tabletop would do it: plant an anomaly in an agent’s logs and time how long it takes to reach a named person with the authority to contain it or escalate it. Then run the same exercise with a vendor in the middle.

For a material incident, that number should be measured in hours. I’d much rather discover a slow escalation path in a tabletop than through a regulator’s email.

A control environment is only as fast as the path from the log to the person who can act.

If you ran that tabletop tomorrow, would the answer come back in hours or in weeks?

admin

Writer

Leave a Reply

Your email address will not be published. Required fields are marked *

Categories

Latest Posts

  • All Posts
  • AI & Digital Transformation
  • Business Strategy
  • Governance & Risk
  • Leadership & Change
  • Markets & Policy
  • Project Delivery & Recovery

Tags

GovernIT Consulting

We turn stalled projects into delivered value through governance discipline, independent oversight, and hands-on execution.

We want to hear from you

© 2026 GovernIT Consulting Inc. All rights reserved. See Accessibility for more information.

Join our Insight newsletter

You have been successfully Subscribed! Ops! Something went wrong, please try again.