top of page

Australian Signals Directorate AI Warning Exposes the Cost of Always-On Legacy Systems

1 day ago
13 min read

The Australian Signals Directorate AI warning puts a direct conflict at the center of Australia’s cyber defense: old systems must be replaced, despite expectations of constant availability. Abigail Bradshaw, the agency’s director-general, says governments and businesses face “enormous” modernization costs as AI makes vulnerable technology easier to attack.

Her warning, delivered at the Sydney Dialogue in Canberra on September 14, 2026, was not a prediction about an entirely new class of software flaw. It was about artificial intelligence accelerating the discovery and exploitation of weaknesses that organizations have postponed fixing.

That distinction matters. Australia’s immediate contest is not simply defenders against smarter hackers. It is security modernization against the operational demand to keep essential services online without interruption.

The country already faces persistent criminal and state-backed cyber activity. The Australian Signals Directorate, or ASD, responded to more than 1,200 cybersecurity incidents during the 2024–25 financial year. That was an 11 percent increase from the previous year.

AI now threatens to compress the time between discovering a weakness and using it. The practical question is whether governments, infrastructure operators, and businesses can replace exposed systems before automated attackers exploit them at machine speed.

What the Australian Signals Directorate AI Warning Actually Changed

Australia’s cyber authority has moved AI-enabled attacks from a future scenario into current operational planning.

Bradshaw said ASD could not determine how many AI agents were already active online. An AI agent is software that can pursue a goal through multiple actions with limited human direction.

Asked about their number, Bradshaw gave a deliberately simple estimate: “a lot.” Her uncertainty was itself significant. Defenders cannot rely on counting identifiable human attackers when software agents can scan, test, and revisit targets continuously.

The reported warning tied that expanding automated activity to Australia’s legacy systems. Bradshaw said replacing those systems would require enormous spending and periods of downtime.

Legacy information technology includes hardware, software, protocols, and services that are unsupported, impractical to update, or no longer compatible with an organization’s accepted risk level. Such systems often remain in service because replacing them would interrupt important operations.

The warning therefore identified a difficult operational tradeoff. The systems most resistant to planned downtime can become the systems most likely to suffer unplanned disruption.

Hospitals, utilities, government departments, financial institutions, and transport networks cannot casually switch off a critical application. Yet continued availability can conceal accumulated security debt. An old server may still perform its intended function while lacking modern authentication, monitoring, encryption, or patch support.

AI hacking attacks increase the importance of those neglected gaps. ASD and the Australian Institute of Company Directors say newer models can identify vulnerabilities, combine minor weaknesses, and support malicious activity with less human oversight.

The agencies also warn that frontier models lower the expertise needed to perform some offensive tasks. Frontier AI refers to highly capable models with advanced reasoning, coding, language, or multimodal abilities.

That does not mean an autonomous system can effortlessly compromise every old computer. Successful intrusions still depend on access, configuration, defenses, credentials, and the attacker’s goals.

However, automation changes the economics of reconnaissance. A malicious actor can examine more systems, generate more tailored probes, and repeat failed attempts at lower marginal cost.

Australia’s existing exposure makes that change consequential. ASD’s 2024–25 threat report says state-sponsored actors continue targeting government and industry networks for espionage and potential disruption. Cybercriminals also target organizations for data theft, fraud, and extortion.

The same report recorded compromised assets, networks, or infrastructure in 55 percent of reported critical-infrastructure incidents. Compromised accounts or credentials represented another 19 percent.

These figures predate Bradshaw’s latest warning, but they show why AI acceleration matters. Automated attacks will enter an environment where defenders already handle recurring compromises, not a clean environment awaiting its first AI incident.

The policy signal has also changed. Australia’s cybersecurity leadership is no longer treating modernization as routine technology maintenance. It is presenting legacy replacement as a national resilience requirement.

That framing shifts responsibility upward. A board cannot treat an unsupported system as a narrow issue for its technology department when that system affects service continuity, public safety, or sensitive data.

Bradshaw’s intervention also connected infrastructure defense to wider debates over advanced AI oversight. She supported a role for national security agencies in independent evaluations of leading models.

That position places cyber intelligence organizations closer to model governance. These agencies understand the networks attackers target, but they also operate with secrecy and broad national-security mandates.

The resulting challenge is larger than software replacement. Australia must determine how to test frontier models, share threat information, and modernize infrastructure without allowing either vendors or security agencies to define every rule alone.

AI Hacking Attacks Make Old Weaknesses Easier to Scale

AI does not need to invent a new vulnerability when it can find and combine weaknesses that defenders already know exist.

Traditional automated scanning has existed for decades. Attackers already use scripts to discover exposed services, test common passwords, and identify known vulnerabilities.

The emerging difference lies in adaptation. A capable model can interpret unfamiliar code, generate variations of an exploit, explain error messages, or help connect information gathered from several systems.

ASD’s frontier AI guidance identifies three particularly important abilities. Models can find and weaponize vulnerabilities, chain lower-severity weaknesses into larger compromises, and support attacks with little human oversight.

The guidance says vulnerability discovery and exploitation timelines can fall from days to hours. This compression places pressure on organizations whose security processes still depend on monthly review cycles or slow approval chains.

Imagine an outdated web application that reveals its software version in an error message. The application also uses an old encryption protocol and connects to a poorly segmented internal network.

None of those weaknesses necessarily guarantees a major breach by itself. Together, they give an adaptive attacker several routes to test.

An AI system can analyze the exposed details, search its learned patterns for related attack methods, and generate code variants. It can then interpret the results and recommend another approach.

The model still requires infrastructure, access, and direction. Its output can also be wrong. Yet an attacker does not need perfect code on the first attempt when automated testing makes repeated attempts inexpensive.

Legacy systems make this process easier because their weaknesses are often well documented. Unsupported software may have years of public vulnerability research but no vendor patches.

Old equipment can also depend on default credentials, weak protocols, or applications that cannot support multifactor authentication. Specialized industrial devices may remain connected because replacement requires a shutdown, certification, or coordination with several suppliers.

AI hacking attacks also widen the pool of potential offenders. People with limited technical knowledge can use models to draft phishing messages, analyze stolen information, or modify existing malicious code.

ASD’s cyber threat report says criminals already use generative AI to inspect stolen datasets for credentials and extortion material. They also use it to create fake voices, videos, websites, identity documents, and spearphishing emails.

These uses do not require a fully autonomous superintelligence. They improve familiar criminal workflows by reducing labor and increasing volume.

That reality complicates public discussion about AI safety. Dramatic scenarios about systems escaping human control can distract from attackers using ordinary commercial models as productivity tools.

Australia must prepare for both possibilities without treating them as equivalent. A phishing operation assisted by generated text creates different technical and regulatory questions from an agent independently exploiting infrastructure.

Bradshaw’s inability to count active agents highlights that measurement problem. Internet traffic does not reliably disclose whether a human, a script, or a model selected each action.

Definitions also vary. Some vendors call any multi-step automation an agent, while researchers may reserve the term for systems that plan, use tools, and revise their behavior.

That uncertainty should limit sweeping claims about autonomous cyberwarfare. It should not delay basic defensive work.

If an organization closes unnecessary ports, separates old systems, rotates credentials, and centralizes logs, those controls help against both human-led and AI-assisted intrusions. Good security fundamentals remain useful even when the attacker’s exact level of automation is unclear.

This is why the Australian Signals Directorate AI warning is more practical than speculative. It does not depend on proving that autonomous attackers can defeat every defense.

It asks organizations to assume that discovery and exploitation will become faster. Under that assumption, long-standing weaknesses carry a higher expected cost.

The Real Contest Is Modernization Versus Constant Availability

Australia’s central problem is that the systems most important to daily life can also be the hardest to replace safely.

Organizations often keep old technology because it still works. A legacy application may process payments, store health records, coordinate industrial equipment, or support a government service used every day.

Replacing it can require data migration, retraining, integration testing, regulatory approval, and contracts with multiple vendors. Some organizations no longer employ the people who designed the original system.

Scheduled downtime then becomes a political and commercial risk. Customers expect banking, communications, identity, transport, and public services to remain continuously available.

Bradshaw’s warning makes that expectation part of the security problem. Taking a system offline for modernization creates a visible interruption. Leaving it online creates a less visible period of accumulated exposure.

Managers often postpone the visible cost. That choice can appear rational until an incident forces a longer and less controlled shutdown.

ASD’s legacy technology guidance states that replacement is the most effective long-term response. Temporary controls reduce risk but do not eliminate the underlying problem.

The guidance recommends network segmentation, stronger account controls, centralized monitoring, restricted availability, and removal of unnecessary services. Network segmentation isolates systems so that a compromise cannot easily spread across the wider environment.

These measures matter because complete replacement cannot happen immediately. An inventory may reveal hundreds of dependencies, including undocumented connections to suppliers or internally developed applications.

Organizations therefore need a sequence, not a single migration date. They must identify which systems face the internet, which hold sensitive data, and which support services whose failure would cause the most harm.

AI changes how leaders should rank that sequence. An exposed system with several small weaknesses deserves more attention when models can help attackers combine those weaknesses quickly.

Availability must also be measured more honestly. A system that operates every day but cannot resist or recover from an intrusion is not reliably available.

True availability includes the ability to contain an attack, restore trusted data, and continue essential services through alternative processes. That requires tested backups, incident exercises, and documented dependencies.

Australia’s national cyber strategy already recognizes this tension. Home affairs minister Tony Burke placed replacement of legacy IT among five continuing security priorities during the June 2026 launch of Horizon 2.

Burke’s Horizon 2 speech estimated cyberattacks cost Australia’s economy $25 billion each year. It attributed $12 billion to small businesses and $2.4 billion to government.

He also said a catastrophic attack lasting four weeks would cost the economy an estimated $35 billion. These are government estimates, not a forecast that such an event is imminent.

The figures clarify the tradeoff. Planned modernization is expensive, but persistent exposure also carries economic costs. An emergency replacement after a breach can combine both expenses.

Burke said the average cost of cybercrime during the preceding 12 months had risen by 50 percent to $80,000. He also identified human error as the cause of 60 percent of data breaches.

That human factor does not weaken the case for replacing old technology. It shows why technical modernization cannot stand alone.

A new system can remain vulnerable if employees receive excessive privileges, suppliers retain unnecessary access, or alerts go unread. Conversely, disciplined teams cannot indefinitely compensate for software that no longer receives security updates.

The primary opponent is therefore not AI itself. It is an operating model that treats uninterrupted service today as more important than reducing the chance of a larger interruption tomorrow.

Boards and public officials must make that tradeoff explicit. They should identify which services can tolerate scheduled downtime, which require parallel replacements, and which need temporary isolation.

They must also communicate the reason for disruptions. Citizens will reasonably object when important services become unavailable without clear notice or alternatives.

Modernization plans need service-level protections for vulnerable users. A digital identity migration, for example, should not deny access to people who lack a newer device or cannot complete a new authentication process.

Security and accessibility can conflict if replacement programs move too quickly. That is another reason to plan before an emergency removes the option of a controlled transition.

AI Regulation Cannot Substitute for Basic Cyber Defense

Model testing can reveal dangerous capabilities, but it cannot patch an unsupported server or redesign a fragile network.

Australia is developing rules for advanced AI while industry leaders call for faster international coordination. The government expects to introduce AI legislation in early 2027, according to comments reported from the Sydney Dialogue.

Anthropic chief executive Dario Amodei has called for independent assessors to examine leading models. Bradshaw argued that national-security agencies should participate in those evaluations.

The proposal addresses a real need. Evaluators should test whether models can discover vulnerabilities, develop malicious code, evade safeguards, or conduct extended operations with limited supervision.

Security agencies can contribute threat intelligence and realistic attack scenarios. They also understand which capabilities would give state-backed or criminal groups a meaningful advantage.

However, participation creates governance questions. Independent evaluation loses credibility if the process depends entirely on model companies or agencies whose methods cannot be scrutinized.

Testing criteria, escalation procedures, and public reporting obligations need clear boundaries. Governments must protect sensitive intelligence without turning every significant finding into a secret.

Australia also faces pressure from competing interests. Anthropic wants rapid rules and legal certainty. OpenAI has pursued broader engagement with the Australian government, including discussions about copyright and local model training.

The Australian Greens sought mandatory safety testing and transparency duties for advanced systems, but Labor senators rejected their motion for debate on September 14. That rejection did not settle the final design of the government’s forthcoming rules.

Assistant technology minister Andrew Charlton said individual executives should not determine the guardrails. His position sets up an important check on vendor influence.

AI companies possess technical knowledge that regulators need. They also have commercial incentives to shape definitions, testing thresholds, and disclosure requirements in favorable ways.

The government must use their expertise without outsourcing public policy. National security agencies require similar limits because cyber risk is not the only value involved.

Copyright, competition, privacy, civil liberties, and access to technology also shape the regulatory decision. A model that passes a cyber capability test can still create other harms.

More importantly, regulation will not erase existing legacy technology risk. Even strict safety controls cannot prevent every model from being copied, modified, stolen, or operated in another jurisdiction.

Attackers can also combine AI with conventional tools that remain widely available. The defensive plan cannot assume that domestic rules will remove offensive capability from the internet.

That is the skeptical angle missing from some AI policy debates. Model governance can reduce risk at the frontier, but infrastructure owners remain responsible for their own exposed systems.

The inverse is also true. Modernization alone will not address every AI-enabled threat. New systems can contain configuration errors, insecure dependencies, or excessive agent permissions.

ASD advises organizations to apply least privilege to people, services, and AI agents. Least privilege means granting only the access needed for a defined task.

That principle becomes critical when businesses deploy agents internally. An agent connected to email, cloud storage, source code, and financial systems creates a new concentration of authority.

If attackers manipulate the agent or steal its credentials, modern software can become the path to compromise. The answer is not to avoid AI entirely, but to limit permissions and monitor actions.

Defenders can also use AI to analyze alerts, identify unusual behavior, and prioritize vulnerabilities. Bradshaw has encouraged Australian organizations to adopt AI for defensive purposes rather than leaving the capability to adversaries.

This creates a second tradeoff. Faster automated defense can help teams respond at attack speed, but poorly governed automation can block legitimate activity or act on misleading data.

Human supervision remains necessary for high-impact decisions. Organizations should know which automated actions can interrupt services and how staff can reverse them.

The strongest security program therefore combines model evaluation, modern infrastructure, restricted access, and rehearsed recovery. None of those elements can replace the others.

Three Signals Will Show Whether Australia Is Closing the Gap

The next test is whether Australia converts a clear warning into measurable reductions in exposed systems and response time.

The first signal is the content of the government’s expected AI legislation in early 2027. The key issue is whether rules require independent capability testing, incident disclosure, and meaningful access for qualified evaluators.

A credible framework should distinguish between ordinary applications and models capable of materially assisting sophisticated cyber operations. Broad obligations applied to every developer would consume enforcement capacity without focusing on the highest risks.

The law should also define how national-security agencies participate. Their involvement would strengthen the Australian Signals Directorate AI warning if it produces repeatable tests and actionable guidance.

It would weaken the warning if evaluation becomes a closed process with no public accountability. Businesses need enough information to adjust procurement, access controls, and incident planning.

The second signal is a measurable legacy replacement program. Government departments and critical-infrastructure operators should report inventories, retirement schedules, and temporary protections for systems awaiting replacement.

A count of modernization projects is not enough. The useful measures include reductions in unsupported internet-facing software, stronger network separation, and shorter remediation times.

ASD’s recent data provides a baseline for the broader threat environment. The agency responded to more than 1,200 incidents in 2024–25 and notified critical-infrastructure entities of potential malicious activity more than 190 times.

Those totals can rise even as security improves because detection and reporting may become better. Australia should therefore track impact and recovery measures alongside incident volume.

How quickly did an organization detect unauthorized access? How far did the attacker move? Did essential services continue operating? How long did restoration take?

The third signal is evidence from real AI-enabled incidents and defensive exercises. Australia needs detailed case studies showing what models actually contributed to attacks.

Was AI used to generate phishing messages, inspect stolen data, discover a vulnerability, or control a multi-step intrusion? These are different capabilities with different defenses.

Public reporting should separate verified activity from speculation. Calling every automated intrusion an AI attack would distort investment and make trends harder to measure.

Exercises can help before large incidents occur. ASD led 17 cybersecurity exercises involving more than 120 organizations during 2024–25. Future exercises should test shorter decision windows and attacks that adapt after defenses change.

They should also include third-party suppliers. A modernized organization can still lose service when a smaller provider relies on unsupported equipment or weak credentials.

These three signals will reinforce the warning if Australia establishes credible model testing, retires exposed systems, and demonstrates faster containment. They will weaken it if policy remains general while modernization deadlines continue to move.

For business leaders, the immediate response does not require waiting for legislation. They can ask for an accurate technology inventory, identify unsupported products, and map critical dependencies.

They can also require evidence that backups restore correctly, not merely confirmation that backups exist. Incident teams should practice operating essential services without their normal systems.

Developers and AI product teams have a parallel responsibility. Agents should receive narrow permissions, authenticated tool access, complete logging, and clear limits on irreversible actions.

Knowledge workers should expect more convincing impersonation attempts as generated voices, documents, and messages improve. Verification through a separate channel becomes more important when a request involves money, credentials, or sensitive information.

No single action resolves the problem. Replacing old systems takes years, and AI capability will continue changing during that work.

The useful goal is reducing attacker advantage at every layer. That means fewer exposed legacy devices, faster patching, limited privileges, better monitoring, and recovery plans built around essential services.

Australia now has a clear diagnosis from its cyber intelligence chief. AI is accelerating exploitation while organizations remain tied to technology they cannot easily switch off.

The decision for leaders is concrete: which critical system will they isolate, replace, or test before automated attackers examine it again? The Australian Signals Directorate AI warning will matter only if that question produces funded deadlines, accountable owners, and safer transitions rather than another postponed upgrade.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page