Australia's Ageing Government Systems Are a Target for AI-Powered Attacks, Intelligence Chief Warns

The head of a leading Australian signals agency says crumbling legacy infrastructure, technology so old it can't easily be updated, is giving AI-assisted attackers a growing opening.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
Photoreal news-editorial 16:9 image of a darkened server room bathed in cool blue light, rows of blinking rack-mounted servers receding into the distance, subtl
Share

Key points

  • Australia's signals intelligence chief Abigail Bradshaw has warned that AI-powered attacks could exploit the country's outdated government technology.
  • Bradshaw described the cost of replacing legacy systems, meaning old technology that is difficult or impossible to update safely, as "enormous".
  • Anthropic's chief executive warned AI bots could swarm the internet within a year, calling for a slower pace of AI development.
  • OpenAI's chief and Elon Musk have publicly backed calls to slow AI's rapid rollout.

What exactly is the warning?

Abigail Bradshaw, who leads one of Australia's top signals intelligence agencies (organisations that monitor electronic communications for national security), has said publicly that artificial intelligence could be used to attack systems that were never built to handle it. The core problem is legacy technology: software and hardware so old, and so deeply embedded in critical services, that replacing it requires "enormous" sums of money that governments have historically refused to spend.

Australians now expect digital government services to run around the clock, which makes it very hard to take systems offline long enough to update or replace them. Old code stays. Old code carries old flaws.

AI changes the calculation. Tools that criminals or hostile states deploy can now scan large numbers of systems automatically, find weaknesses faster than any human team could, and craft attacks tailored to those specific weaknesses. Against infrastructure that hasn't been patched in years, that capability is far more dangerous than it would be against a freshly maintained system.

What are the AI developers saying?

The alarm isn't coming from security agencies alone. Dario Amodei, chief executive of Anthropic, the company behind the Claude AI assistant, has warned that autonomous AI bots, meaning software programs that act independently without a human directing each step, could be loose across the internet within a year. We reported on that warning on 13 September in Anthropic's CEO Says AI Could Take Over the Internet Within a Year. Safety Isn't Ready.

The heads of OpenAI and Elon Musk have reportedly backed that position, as first covered by Guardian Australia. That the people building the most capable AI tools are saying, in public, that things are moving too fast is worth taking seriously.

The Australian government is currently working out what rules should govern AI. Bradshaw's warning lands squarely in that debate.

The legacy-technology problem isn't new, and neither is the funding argument. What's changed is that AI lowers the skill and cost required to find and exploit old vulnerabilities at scale. Governments that have been deferring infrastructure spend for a decade are running out of runway.

Should you worry?

Government agencies and private companies running old infrastructure should treat this as a prompt to audit what they're actually running, not a theoretical future concern. Citizens whose data sits inside ageing public-sector systems have every reason to ask their representatives what the upgrade plan looks like.

If you receive unexpected contact claiming to be from a government service and asking you to confirm personal details, treat it with suspicion. Criminals use moments of public anxiety about security to run phishing campaigns, where fake messages trick people into handing over passwords or personal information.

© 2026 Threat Vectr