Back To All LAB3 Stories
Opinion

Published: 6 Oct 2026

The Medicare Incident Hasn't Shaken Confidence in AI. It Has Sharpened Questions About AI Agents.

Author

Jason Leonard, Practice Lead - AI, LAB3

Jason Leonard

Practice Lead - AI, LAB3

The Medicare incident has not changed organisations' appetite for AI. It has changed the questions they are asking about accountability, visibility and control.

Jason Leonard — Practice Lead - AI, LAB3

The Conversation Has Shifted

The Medicare incident showed what can happen when AI agents operate at scale without sufficient control over how they pursue an objective. Understandably, it captured attention and prompted serious questions about safety, access and accountability. Those questions should lead to better decisions, rather than stalled AI programs.

In recent conversations, our clients have focused on the parts of agentic AI that sit within their control. They want to know how agents can remain productive, cost effective and safe inside their enterprise. The answers depend heavily on the organisation's level of AI maturity.

Mature Organisations Are Finding New Gaps

One large multinational client is already advanced in its AI journey. It has established platforms, governance processes and AI solutions operating across the business.

Following the Medicare incident, its leaders began reprioritising several questions.

  • Should agents act using a person's identity or have controlled identities of their own?
  • Which systems and data should each agent be able to access?
  • If an agent updates a system, how will the owner know what changed, why it changed and who authorised the action?

Visibility Is Becoming a Critical Capability

Tracking and logging are central to this conversation. When controls are weak, investigating an incident can become a long, manual and backward-looking exercise. Strong visibility gives teams the chance to identify early warning signs before a problem grows.

The Emerging Challenge of Agent Sprawl

The client also raised a practical challenge that will become more common as adoption increases.

One business team builds an agent that retrieves data from an enterprise system such as Salesforce or ServiceNow. Another team creates a separate agent that retrieves similar data. A third team follows. Each solution may work, but the organisation now has several agents repeatedly making similar calls into the same system of record.

That creates duplicated effort, additional cost and potential pressure on core systems. It also introduces questions about data loss prevention when those calls are made using agent identities. Most organisations need a skilled advisor to recognise when an agent is the wrong approach. If several teams need the same enterprise data, a shared data platform may provide a more efficient answer than sending multiple agents back to the source system. The right solution may combine agents, data platforms and improved operating processes.

Solving this requires considered enterprise design across the platform, governance, production, maintenance, support and cost control. This organisation already has many of those elements in place. LAB3's work is helping the client identify and close the remaining gaps as the technology and available implementation patterns continue to evolve.

Early-Stage Organisations Need a Clear Path to Production

Another client, a mid-sized insurance company, is at an earlier stage. Its challenge is speed.

Business leaders are developing their own AI capabilities, often moving faster than the internal digital team. Once an experiment proves useful, the expectation is that digital will take responsibility for running, maintaining and scaling it.

Without a consistent approach, that handover becomes difficult. Solutions may use different technologies, duplicate existing work or require major changes before they are ready for production. Digital teams can quickly inherit a collection of promising experiments that were never designed for enterprise use.

This organisation needs full governance, but it can establish that governance through practical steps that support its current maturity.

Three Practical Foundations

  1. The first step is to decide which platforms the organisation endorses, publish that guidance and give people access to those platforms. When employees know where they should build, they are less likely to select technologies that create unnecessary security, scalability or support challenges later.
  2. The second is to create a register of existing AI solutions. That gives teams visibility of what has already been built and helps prevent several parts of the business from solving the same problem independently.
  3. The third is to establish an advisory service for people who have an idea but have not started building. Early guidance can direct them towards approved technology, existing capabilities and sensible development patterns. It also creates a cleaner pathway from experimentation into production.

This approach allows the digital team to guide innovation while the business continues moving quickly. Governance becomes part of how ideas progress, rather than a process introduced after the difficult decisions have already been made.

Platforms Provide a Strong Starting Point

Platform choice can reduce many of these risks from the beginning.

Microsoft Copilot Studio and Microsoft Foundry provide established guardrails and approaches for developing agents within an organisation's environment. Agents can operate with defined identities, and those identities can be scoped to approved data and systems. Access is granted deliberately and configured around the agent's purpose.

The platform provides a foundation. Organisations still need to make good decisions about identity, architecture, monitoring, ownership and operating processes.

Confidence Comes from Control

That is where LAB3 adds the greatest value. Clients bring us business problems, and we find the right answer. Sometimes that answer involves an AI agent. Sometimes it involves a data platform, an operating model change or a combination of solutions.

The Medicare incident has given organisations a reason to examine their approach more closely. That scrutiny is healthy. It can improve governance, clarify ownership and create stronger foundations for growth.

Confidence in AI should come from knowing what your agents can access, what they are doing, what they cost and who remains accountable. With those foundations in place, organisations can keep innovating with greater control to fear less and achieve more.

Back To All LAB3 Stories

CONNECT WITH OUR AI EXPERT

Jason Leonard

AI Practice Lead, LAB3

Jason starts with the business outcome, not the AI.