Australia's Outdated Tech Open to AI Attacks, Spy Chief Warns

Australian Signals Directorate Director-General Abigail Bradshaw says AI-enabled attacks can exploit Australia's outdated technology.
She gave the warning at the Sydney Dialogue summit in Canberra on Monday, 14 September 2026. The Guardian reported her address under the title "Australia's outdated technology is vulnerable to AI hacking attacks, signals chief says".
Bradshaw said governments and businesses would have to spend "enormous" amounts to fix vulnerable old systems, known as legacy technology. She said the bill falls on both public and private owners. No dollar figure was given. The point was scale.
That fix would also mean switching off systems Australians expect to run all the time. Bradshaw described a blunt trade-off between keeping services running and fixing them. Some old platforms cannot be patched while they stay online.
Bradshaw said the Australian Signals Directorate did not know how many AI agents are active on the internet. AI agents are software tools that can act online without a human directing every step. That leaves a visibility gap, with automated activity happening at machine speed and scale outside checked inventories.
She called for national security agencies to be involved in independent testing of AI companies' models. The idea is direct access for assurance, not just taking vendors at their word. It would put agencies inside the testing loop for the most advanced, or frontier, systems.
Bradshaw led the ASD's Australian Cyber Security Centre as of September 2022. At that time she said cyber-attacks were increasingly common, sophisticated and agile. She was appointed Director-General of the Australian Signals Directorate in September 2024.
Looking at what this means for Canberra, the message is aimed at boards and budget committees as much as ministers. Fixing old systems is rarely electorally attractive. It is expensive, disruptive and invisible when it works. Bradshaw is telling owners they can no longer put it off.
In my view, the downtime point is the sharper political problem. Governments promise 24-hour services. Businesses promise 24-hour services. Properly fixing unpatched or unsupported systems often means isolating or shutting them down. Someone has to approve the outage and cop the complaints. That call sits above the security operations centre.
The broader context here is assurance and access. Bradshaw is linking two gaps. Operators cannot count the agents in their environment. Governments cannot independently check the models that produce those agents. For practitioners, that points to procurement controls, logging of agentic tool use, and negotiated rights to evaluate models with providers. None of that is cheap. All of it is now being framed as core national security business.


