Most healthcare organisations deploying agentic AI have inherited a critical identity gap: permissions no human deliberately approved, because the identity architecture was built for people, not machines.
Full guide delivered to your inbox
Agentic AI is already scheduling appointments, summarising clinical notes, triaging referrals, and querying patient records across Australian healthcare. Each of those actions touches sensitive data, and in most deployments, the clinical system receiving the request has no reliable way to know who authorised it, which agent made it, or whether the access sat within the scope of the original privacy impact assessment. This article explains why that identity gap exists, why neither national policy nor the vendor market has closed it yet, and what a correctly architected agent-identity gateway looks like in practice, before the Privacy Act's automated decision-making disclosure rules land in December 2026.
Includes the full architecture breakdown of where identity is lost in agentic healthcare workflows, an explanation of the Privacy Act's incoming automated decision-making disclosure rules, and a six-step checklist for closing the identity gap before your next AI deployment goes live.
No noise. Unsubscribe anytime. Your details are used only to deliver this guide and occasional Lumaris insights on the same topic.
Read enough? The guide is one form away.
Get the guideIt is written for CISOs, CIOs, and heads of AI at Australian healthcare organisations that are deploying or evaluating agentic AI systems. It assumes the reader understands what AI agents are but has not yet addressed the identity governance gap they create.
The Privacy Act's automated decision-making disclosure rules (APP 1.7-1.9) commence on 10 December 2026. Organisations that cannot trace which AI agent accessed which record, under whose authorisation, will not be able to meet the disclosure obligation credibly.
Yes. The identity gap is the same regardless of whether the AI agent was built in-house or supplied by a vendor, because the clinical system still cannot answer who authorised the access without a correctly architected identity gateway in place.
Map every AI agent's access to identifiable patient data and name an accountable owner for each one. Without that inventory, none of the other remediation steps, including scoped credentials and policy-as-code enforcement, can be sequenced or prioritised.
Most conversations begin simply. Someone wants to know whether we are the right fit for what they are navigating. That is a perfectly good starting point.