Elastic launches AI agents for security & ops in Australia
Fri, 9th Oct 2026 (Today)
Elastic has launched AlertZero and Elastic NightShift in Australia, adding AI agents to security and observability work.
The launch comes as organisations face growing scrutiny over how quickly they can detect AI agents operating inside their systems and understand what those agents are doing.
A recent government disclosure sharpened that focus. The Prime Minister said an OpenAI agent accessed non-public files on a Services Australia Medicare statistics portal in June, and the government was not informed until September.
OpenAI told a parliamentary inquiry the incident was "not super sophisticated" and that AI had changed the cyber equation. It said governments and companies needed to increase cybersecurity spending and use AI to identify vulnerabilities more quickly.
Against that backdrop, businesses are under more pressure to improve visibility over AI systems already running across their networks. Elastic said its research found only 31% of Australian businesses have a central view of the AI agents they run.
The same research suggested detection remains slow outside normal working hours. Only 9% of Australian organisations surveyed said they would detect a compromise within five minutes after hours.
Security focus
AlertZero is designed for security operations tasks including triage, hunting, detection tuning and forensics. Elastic said it is intended to provide an evidence-backed answer for every alert, with analysts required to approve consequential actions.
Elastic is positioning the product around broad visibility across an organisation's data rather than narrower samples or fragmented sources. That approach reflects a wider shift in cybersecurity, where the challenge is not only spotting threats but understanding activity across sprawling digital environments.
Operations role
Elastic NightShift is aimed at Site Reliability Engineering and operational troubleshooting. Elastic described it as an AI SRE that works continuously to identify issues standard alerts may miss across the technology stack, while showing its reasoning at each step.
The product extends AI agents beyond security teams into observability and systems operations. In practice, that means using the same underlying data environment to investigate service issues, infrastructure faults and abnormal behaviour that may not trigger conventional alarms.
Both products rely on Elastic's platform as the data foundation, allowing the agentic layer to search across the full dataset rather than a limited subset. Elastic argues this is necessary if AI-based defence tools are to provide reliable answers in environments where information is often split across multiple systems.
The announcement also reflects a broader trend in enterprise software, with suppliers placing AI agents into operational workflows while keeping a human approval step for higher-risk decisions. In security, that balance has become more important as companies look for ways to handle a larger volume of alerts without handing full control to automated systems.
Australian organisations have become a key test case for that shift because the policy discussion has moved quickly from experimentation to oversight. The Medicare portal incident underscored concerns that many institutions still lack basic visibility into where AI agents are active, what they can access and how quickly unusual behaviour can be detected.
Elastic's research suggests that visibility gap remains significant. A centralised view of AI agents is still uncommon, leaving many businesses in a weak position when incidents occur after hours or across disconnected systems.
By tying security and observability to a common data layer, Elastic is seeking to address that problem through broader monitoring and investigation. Its message is that AI tools used in defence are only useful if they can examine the full environment rather than isolated fragments.