The Albanese government is strengthening its defences against rogue AI activity in the wake of the OpenAI breach of a government website and ahead of the report from a taskforce it established to investigate the incident.
Author
- Michelle Grattan
Professorial Fellow, University of Canberra
A direction has been given to departments to "harden" cyber security defences on their "legacy" technology systems .
The Australian Signals Directorate reported last year that 59% of Australian government entities reported legacy technologies were impacting their ability to implement key cyber security controls.
The OpenAI agent was able to breach a legacy Services Australia portal containing Medicare statistics. The breach occurred in June but the government was only notified in September. The old site has since been closed.
Under the new direction issued by the secretary for the Department of Home Affairs, departments and agencies must:
conduct an immediate stocktake of their legacy systems
set a target to reduce this technology, backed by a risk management plan, and
report what they've done to the Department of Home Affairs.
The action comes as OpenAI, in a long statement, apologised for what happened in Australia and promised to "do better". It will send a senior member of its team to appear next week before the Australian parliamentary committee examining AI.
The taskforce the government set up to make recommendations following last week's announcement of the breach will report within weeks.
The government said in a statement today that its "most critical systems" will be prioritised in the review process. The move "is designed to fortify against all forms of AI-enabled threats: inadvertent, or deliberate and targeted".
The direction also requires agencies to "balance system availability with security, particularly where systems are public facing".
This will ensure agencies consider requirements for rapid patching and security when managing critical government systems.
Acting Home Affairs Minister Richard Marles said:
AI is changing the environment in which we operate at extraordinary speed. Government systems need to keep up.
We can't wait for an old system to fail before replacing it. We need to identify vulnerabilities and deal with them before they can be exploited.
![]()
Michelle Grattan does not work for, consult, own shares in or receive funding from any company or organisation that would benefit from this article, and has disclosed no relevant affiliations beyond their academic appointment.