What must Australian agencies change after the new AI-enabled cyber direction?
A binding direction requires non-corporate Commonwealth entities to inventory and plan down legacy-technology risks. It sets deadlines and a reporting route, but leaves agencies to define the depth of their own stocktakes.
Editorial responsibility: The Impact of AI Editorial Desk · Report a factual concern
At a glance
- 1The direction applies to non-corporate Commonwealth entities under Australia's Protective Security Policy Framework.
- 2By 31 March 2027, entities must complete a legacy-technology stocktake, maintain a risk plan and report completion to Home Affairs.
- 3Operators of Systems of Government Significance face an earlier 31 December 2026 deadline for additional risk-reduction measures.
Living evidence record
Impact record IAI-0HI0I0M
Evidence stage
Announced
Confidence
Supported
Reporting basis
Source analysis
Independent support
Not yet
Record status
Monitoring
Last checked
30 September 2026
Source trail
2 direct sources across 1 source type.
People impact
Documented in this record.
Uncertainty
Limits and next checks are explicit.
Stages describe the evidence available—not whether a technology is good or bad. See the public method.
Related-source reporting disclosure
This record analyses 2 linked source records around the same underlying development. The extra records add method, date or context, but they do not by themselves constitute independent replication of every performance claim or predicted outcome.
What is mandatory—and for whom
Australia's Department of Home Affairs published PSPF Direction 002-2026 on 29 September. Under the Protective Security Policy Framework, accountable authorities of non-corporate Commonwealth entities must comply with a direction issued by the department's secretary. The instrument says frontier-AI capabilities have targeted the Commonwealth technology estate and that unsupported systems plus accumulated vulnerabilities now pose an unacceptable risk.
The scope is specific: non-corporate Commonwealth entities covered by the PSPF, not every Australian business, state government or public body. The document defines legacy technology through existing PSPF criteria covering end-of-life or out-of-support products combined with factors such as impractical maintenance, unacceptable risk, poor value or obstruction of technology strategy. It does not publish the number of affected systems or agencies and should not be read as a measured prevalence study.[1]
The deadlines turn advice into accountable work
By 31 March 2027, every covered entity must conduct a stocktake of legacy systems it manages or has managed on its behalf. It must develop and maintain a risk-management plan inside its cyber strategy and uplift plan, including a reduction target, priorities, mitigations for systems that remain and procedures to rationalise the technology estate. Completion and a copy of the plan must be reported to Home Affairs' Commonwealth Security Policy Branch.
Entities operating Systems of Government Significance face an additional 31 December 2026 deadline to incorporate risk-reduction measures that will be detailed in an explanatory note due by 13 October. The direction tells agencies to prioritise public-facing services and critical government systems, while recognising the shorter interval between vulnerability discovery and exploitation. National-security functions may seek a reporting exemption for a legitimate business reason, but the document does not create a general opt-out.[1][2]
Why AI changes the timing, not the basics
The required actions are familiar security fundamentals: know the estate, remove unsupported technology, patch rapidly, reduce exposure and plan for continued operation. The AI element is the threat tempo. More capable systems can help attackers discover, combine and exploit weaknesses faster, shrinking the time available for defenders. That does not mean an autonomous model can compromise every legacy system, and the direction supplies no incident count or comparative exploitation rate.
For agency leaders, a useful stocktake should record ownership, support status, public exposure, data sensitivity, dependencies, patchability, compensating controls and the consequence of failure. A list without service relationships can miss a supported front end that depends on an unsupported back end. Suppliers should be included where they operate systems on an agency's behalf, but accountability remains with the entity. Risk reduction may mean replacement, isolation, tighter access, virtual patching or a tested continuity plan rather than immediate removal in every case.[1][2]
Effects on people and the evidence still missing
People rely on government systems for payments, health, identity, taxation and other essential services. Faster patching can reduce exposure, but rushed changes can also interrupt access, especially where an old system supports a public-facing service with few alternatives. The direction explicitly tells entities to balance availability with security. Agencies should test accessible fallbacks, publish service notices and include continuity for people who cannot switch channels easily.
The assessment would become stronger if the October explanatory note defines measurable risk-reduction standards and later reporting shows how many systems were found, retired, isolated or remediated, with incident and outage trends. It would weaken if agencies choose shallow stocktakes, set non-comparable targets or treat plan submission as the outcome. The present document is important because it creates mandatory governance and dates; it is not evidence that Australia's legacy-system risk has already fallen.[1]
What this means for people
- Residents depend on secure, continuously available public services and may be harmed by either exploitation or poorly managed replacement work.
- Government technology teams gain a formal mandate for inventory and remediation but still need resources and comparable targets.
Global context
The direction applies to a defined part of Australia's federal government. Other governments face similar legacy-system and AI-enabled threat pressures, but the legal obligations and deadlines do not transfer outside Australia.
What the evidence does not yet show
- The direction is a policy instrument and provides no denominator for systems, agencies, vulnerabilities or AI-enabled incidents.
- Agencies determine the depth and scope of their own stocktakes, which may reduce comparability.
- Additional measures for critical government systems depend on an explanatory note due after publication.
What to watch next
- The Policy Explanatory Note due by 13 October 2026 and its measurable standards for critical systems.
- Completion data for stocktakes and risk plans at the December 2026 and March 2027 deadlines.
- Evidence that vulnerability reduction improves without avoidable disruption to public services.
Evidence trail
Sources used for this report
Links checked 30 September 2026
This report is labelled source analysis. We summarise and analyse source material in our own words; company statements remain attributed claims until independently supported. Translated summaries preserve the meaning of the original source and link back to it. Read our editorial standards.
Continue the story
Related reporting
Security & Defence
Is AI changing cyberattacks—or speeding up familiar tactics?
Microsoft's 2026 Digital Defense Report says threat actors are using AI across parts of existing attack workflows while people, credentials and exposed systems remain central. Its vast telemetry offers useful scale, but the public summary does not disclose a common denominator for every headline percentage.
9 min · 2 sources
Security & Defence
Did AI agents hack government websites—or only attempt to?
California has served OpenAI with an investigative subpoena over agent-related cybersecurity incidents. The update separates a compulsory information request from any finding of liability, while preserving the evidence limits around the reported government-site activity.
8 min · 4 sources
Security & Defence
Can companies control what AI agents can access? Gartner finds a governance gap
In a survey of 297 cybersecurity leaders, 54% said their organisation had no defined approach to limiting AI-agent access or reused human permissions. The finding supports tighter privilege controls, but the public release omits geography, sampling and question wording.
5 min · 2 sources
Reader discussion
Add evidence, experience or a question
No account is required. Reader notes are published after a brief civility, relevance and safety check; disagreement is welcome.
Published reader notes
0No published reader notes yet. You can start the evidence-led discussion above.
Prefer a private correction or response? Contact the newsroom.