Australia’s legacy systems were already a cyber risk. AI agents are raising the stakes
Most Australian government entities are running outdated technology – and AI systems may reveal their weaknesses, intentionally or not.
Australian government agencies face a cybersecurity risk stemming from the widespread use of outdated legacy technology, according to the Australian Signals Directorate. In 2025, 59% of government entities reported that legacy systems hindered their ability to implement critical cybersecurity measures. Legacy systems, defined as older hardware or software no longer supported by manufacturers or unable to meet current security requirements, pose a challenge not only technically but also due to issues with governance, responsibility, funding, and the availability of viable replacements.
Australia's vulnerability to AI-boosted cyber threats is enhanced by its widespread adoption of digital systems, perceived wealth, and patchy cyber defenses. Personal, financial, health, research, and proprietary data held by Australian governments and organizations make the country an attractive target for cybercriminals. AI agents contribute to this heightened risk, enabling cybercriminals and state-sponsored attackers to find vulnerabilities, analyze code, and exploit systems more rapidly.
AI agents have the capability to independently identify vulnerabilities, plan actions, use tools, interact with external systems, and adapt when encountering obstacles, as demonstrated in a recent Medicare incident in Australia. While AI does not create vulnerabilities in aging systems, it can change how quickly, persistently, and autonomously those vulnerabilities can be discovered and acted upon.
Governments and organizations hosting critical data must take steps to reduce AI agents' vulnerabilities. This includes identifying and isolating legacy systems, monitoring them closely, and potentially accepting residual risk for critical systems. Organizations using AI agents must also control what the agents can see, access, and do, implementing minimal access privileges, restricted permissions, strong authentication, monitoring, and human oversight for riskier actions. Audit trails should be maintained to track agent behavior and ensure accountability.
Written by urgent.news from The Conversation AU's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- When AI agents go rogue: Australia breach offers warning for countries like India thehindu.com
- When AI agents go rogue: Australia breach offers warning for countries like India economictimes.indiatimes.com
- Australia is run on legacy systems that AI agents can easily exploit, former UN cyber negotiator warns theguardian.com
- Australia news LIVE: Chalmers to reveal $6 billion budget boost ahead of interest rate decision; Cybersecurity experts say government blew OpenAI breach out of proportion theage.com.au
- Australia news LIVE: Chalmers to reveal $6 billion budget boost ahead of interest rate decision; Cybersecurity experts say government blew OpenAI breach out of proportion smh.com.au