AI breach prompts leaders to hit refresh on old tech

Government departments have been ordered to fast-track throwing away old cyber systems to mobilise against malicious artificial intelligence.
Sep 30, 2026, updated Sep 30, 2026

Every government department has been ordered to fast-track throwing away old cyber systems to mobilise against malicious artificial intelligence.

The directive to start a rapid stocktake and refresh comes days after a Medicare portal became the first known Australian government system to fall victim to an AI hack.

The break-in occurred on June 18, but made global headlines when Prime Minister Anthony Albanese informed the public last Thursday.

The Home Affairs Department-driven push to mothball old systems announced on Wednesday tracks with a sweeping government cybersecurity overhaul slated for completion by 2030.

Acting Home Affairs Minister Richard Marles said government systems “need to keep up”.

“We can’t wait for an old system to fail before replacing it,” he said.

“We need to identify vulnerabilities and deal with them before they can be exploited.”

More important systems will go under the knife first.

In May’s federal budget, Labor earmarked $160 million to upgrade Services Australia’s cybersecurity, and since the Medicare breach has pledged to accelerate decommissioning ageing platforms.

The government was wrestling with an array of systems needing protection against a new, far-reaching threat, former Australian Federal Police high-tech crime centre head Nigel Phair said.

For the sake of feasibility and transparency, it was useless to try and put everything in a locked box, he said.

“The reality is you can’t secure all data. You don’t have the time, the money or the effort,” Phair said.

Stay informed, daily

“The last thing you want to do is say, ‘let’s lock everything up’.”

He said government systems were “probably more antiquated than you think”, and stressed strengthening them was not a box-checking exercise.

“[Improving defences] is easy to say, harder to implement … cybersecurity is not a binary yes or no,” he said.

The Australian Signals Directorate, the nation’s cybersecurity agency, uses a four-tiered “maturity rating” to describe how sophisticated a cyber-attack government entities can handle.

By its November 2025 count, just 22 per cent met or exceeded its third-best rating, with only 35 per cent reporting at least half their cybersecurity incidents to the ASD the previous year.

It took five days for the agency to receive word of the Medicare breach after OpenAI’s notification landed in a public social services department inbox on September 10.

Marles said Wednesday’s announcement was intended to combat targeted AI threats as well as inadvertent ones like the one OpenAI posed in June.

The tech giant on Tuesday issued a candid apology for its lacklustre response to the breach after discovering it in August and leaving Canberra in the dark for weeks.

It will assemble its own Australian-based task force packed with domestic expertise to try and ward off dangerous autonomous AI.

The company’s chief strategy office Jason Kwon, along with a representative from Anthropic, will face a parliamentary grilling in October.

-with AAP

Want to see more stories from InDaily SA in your Google search results?

  1. Click here to set InDaily SA as a preferred source.
  2. Tick the box next to "InDaily SA". That's it.
News