Why your safeguards can fail together

A long sealed driveway on acreage winding uphill between palms and bamboo

We live on acreage, with a long, steep driveway and a gate at the top. Our dogs have always slept in the house, behind a screen door with a latch.

One morning when our kids were still at school, my husband left the gate open when he went to work, because he knew I’d be heading out with the kids not long after.

Ollie was a Great Dane cross and too friendly for his own good. He had also worked out how to flick the screen door latch up with his snout, which none of us knew at the time. When someone walked past the top of the driveway with two greyhounds, he was through the door, up the hill and out the open gate to say hello.

We all ran after him. My son and daughter reached him first, and none of us saw him touch either dog, so we walked back down the driveway with him, thinking no harm had been done.

Later that day there was a note in the letterbox. One of the greyhounds had a small puncture wound in its chest and needed minor surgery.

We were certain the injury wasn’t caused by Ollie. The kids had been right there, and he never got close enough to either dog. We paid for the surgery anyway, and for the follow-up treatment when there were complications, because it was our gate that was open.

Nobody made a careless decision that morning. Each of us was relying on a safeguard someone else was looking after. The same thing happens inside organisations, where safeguards that look separate are often more connected than they appear.

An open screen door with a small latch, looking out onto a red timber verandah and garden

Why safeguards fail together

Many organisations protect the risks they worry about with more than one safeguard, such as a policy and a sign-off, or a system control and a person who checks the output.

That is sound practice, but the existence of one safeguard can change how carefully the other is operated. A system setting is left a little looser because a human will review the output, and the reviewer only skims because the system would have flagged anything odd.

Each of those decisions, made by different people at different times, can seem reasonable on its own. Yet safeguards tend to fail together, because people ease off one when they know another strong one exists, and nobody sees the combined gap until something gets through both.

In health, many people know this as James Reason’s Swiss cheese model, where harm gets through when the holes in several safeguards line up.

A version of this played out in June 2026 on a Medicare statistics portal run by Services Australia. An OpenAI agent, given a research task on public spending on medicines, kept hitting blocks on the portal. Prime Minister Anthony Albanese described what happened next:

“The AI agent found a way around those blocks. Didn’t accept no for an answer, if you like.”

It reached files that were not public, though the government says no personal information appears to have been accessed.

The protections on that portal appear to have been built on the assumption that whatever reached them would stop when told no. Until recently, that was a fair assumption. As more work is handed to AI tools and agents, it is going to be tested more often, and in many organisations.

Gartner expects AI agents to become a significant source of breaches, predicting that by 2028, 25 per cent of enterprise breaches will be traced back to AI agent abuse. At the time, its Chief of Research, Daryl Plummer, said:

“The implementation of guardrails, security filters, human oversight, or even security observability are not sufficient to ensure consistently appropriate agent use.”

Test the safeguard everyone relies on

You can find the gap before something else does. Take one risk to your next executive meeting and work through it in this order.

Test the safeguard everyone relies on: 1. Pick one risk your executive team would describe as covered. 2. List every safeguard on it, including the people who check. 3. Ask the person who holds each safeguard what they have eased off because another one is there. 4. Take the safeguard everyone relies on most out of the picture, and test whether anything else would be enough to stop the problem.

If nothing else would stop it, that risk depends on one safeguard, and that is where to start.

Where AI tools are involved, add two moves that don’t rely on the tool stopping when it is told no. Limit what it can reach: ask what it can open, change or send without a person approving it, remove anything it doesn’t need, and if the tool comes from a provider, get their answer in writing. Then agree who would know if something got through, how quickly, and by what route. OpenAI found its agent’s activity about eight weeks after it happened.

The gaps often sit between people’s areas of responsibility, so this review works best when everyone who holds a safeguard is part of the same conversation. I facilitate these reviews with boards and executive teams, so the people responsible for different safeguards can see how they depend on each other, find the gaps between them and agree what to tighten first.

If there is a risk your team would call covered and this has made you less sure, reply and tell me which one. That is usually enough to work out whether a review like this would be useful.

Written with AI assistance. The thinking and the final wording are mine.

Share This