Google AI
The Times Australia

Times Media

Australia needs an AI early-warning system — but Canberra is still writing the rules

  • Written by: The Times

The Australian government is troubled by A.I. but is unable to come up with a cogent policy

Artificial intelligence is already strengthening Australia’s cyber defences. It is also giving criminals and hostile states faster, more capable tools. The challenge for Canberra is no longer whether AI should be used, but whether Australia can build safeguards as quickly as the technology is advancing.

Australia’s cyber-intelligence chief has called for an early-warning system capable of identifying emerging artificial intelligence threats before separate incidents become a national crisis.

Abigail Bradshaw, Director-General of the Australian Signals Directorate, says Australia needs a more formal mechanism through which intelligence agencies, technology companies and other organisations can report unusual AI behaviour, combine their observations and recognise wider patterns.

Cybersecurity agencies already exchange information about malicious software, vulnerabilities and attacks. The concern is that Australia does not yet have an equally mature system for risks created or accelerated by increasingly autonomous artificial intelligence.

It is a significant warning from the agency responsible for defending Australia against serious cyber threats—and for conducting offensive cyber operations when authorised by the government.

The message is not that Australia should reject AI. On the contrary, Bradshaw says it is becoming one of the most useful defensive tools available.

Tasks that once required Australian cybersecurity specialists to work for weeks can now reportedly be completed in hours with the assistance of advanced AI models.

But attackers can use the same advantage.

That is the problem Canberra must confront: artificial intelligence does not belong exclusively to governments, respectable businesses or benevolent researchers. Its capabilities can also be used by criminal organisations, fraud networks, hostile intelligence services and individuals with little technical expertise of their own.

From automated assistance to autonomous action

The immediate concern is not simply that AI can produce convincing emails or answer technical questions.

The more consequential development is the emergence of “agentic AI”—systems that can be connected to data, software and tools and then instructed to undertake a sequence of actions on a user’s behalf.

A conventional chatbot might explain how to complete a task. An AI agent may be able to perform parts of that task itself.

Properly controlled, this could allow organisations to find software vulnerabilities, monitor networks, analyse suspicious activity and respond to threats much faster.

Poorly controlled, an AI agent may be given excessive access to confidential information, financial systems, communications or critical infrastructure. It may misunderstand an instruction, act on unreliable information or be manipulated by an external attacker.

The danger does not necessarily lie in the language model alone. It can arise from the software “harness” connecting the model to an organisation’s data and operational systems.

The Australian Signals Directorate has consequently urged organisations adopting agentic AI to apply familiar but essential protections: restricted access, secure system design, monitoring, audit records, human supervision and clear accountability for high-impact decisions.

These precautions may sound elementary. Their importance grows considerably when software can operate at machine speed.

Australia’s ageing systems create an opening

Australia is not beginning this transition with a clean technological slate.

Governments, companies, hospitals, universities and essential-service providers often rely on complicated networks assembled over many years. New software may sit alongside ageing databases, unsupported applications and equipment that was never designed to interact with autonomous AI.

A capable attacker does not have to defeat every part of such a network. The attacker needs to find only one poorly maintained system, exposed account or excessively powerful connection.

AI can make that search faster.

It can help identify weaknesses, adapt malicious code, produce convincing impersonations and conduct many attempted intrusions simultaneously. It can also reduce the level of specialist knowledge previously required to attempt sophisticated fraud or cybercrime.

Australia’s vulnerability therefore comes from the combination of a powerful new technology and a large collection of old systems.

AI did not create every weakness. It may, however, make those weaknesses easier to discover and exploit.

What would an early-warning system do?

An AI early-warning system would not be an alarm announcing that artificial intelligence had suddenly become dangerous.

Its purpose would be to gather fragments of information that might otherwise remain isolated.

One business may discover an AI agent attempting an action outside its assigned role. A government agency may observe a new method of automated intrusion. A technology company may detect repeated misuse of a model. Researchers may identify a capability that was not apparent during earlier testing.

Individually, each event may appear manageable. Collectively, they could reveal a new class of threat.

The value of an early-warning system would lie in allowing authorised participants to share those observations quickly, analyse them together and warn other potential targets.

Australia already understands this principle in other areas of national security. Bushfire authorities combine observations to identify a spreading emergency. Health agencies monitor unusual cases to detect outbreaks. Cybersecurity organisations exchange indicators of malicious activity.

AI requires a comparable capacity because its risks can move across industries and borders before traditional regulation catches up.

Canberra cannot outsource the rules

The federal government is preparing mandatory Australian standards for high-risk uses of AI. It has also established an Australian AI Safety Institute and is participating in international discussions about testing, transparency and control.

Those steps are necessary, but Australia faces a difficult strategic reality.

Most of the world’s most advanced AI systems are developed overseas. Their capabilities, restrictions and commercial priorities are largely determined by foreign companies operating within the strategic competition between the United States and China.

Australian organisations can benefit from those systems without controlling their development.

Assistant Science and Technology Minister Andrew Charlton has argued that decisions about AI should not be left solely to technology companies or global superpowers. That is an important principle. Australia must be able to establish rules reflecting its own national security, laws, institutions and public expectations.

Yet regulation that arrives years after a technology has been deployed will have limited protective value.

Canberra must regulate a rapidly moving industry without freezing beneficial innovation, driving investment elsewhere or creating rules that are obsolete before they commence.

There will never be a perfect moment at which government understands everything about AI and can legislate with certainty. The practical answer must therefore include adaptable standards, continuing technical assessment and a warning network able to respond between legislative changes.

What businesses should do now

Australian businesses do not need to wait for the final federal framework before acting.

Any organisation allowing AI to interact with its systems should know what information the technology can access, what actions it can perform and who remains responsible for its decisions.

AI services should receive only the permissions required for their task. Important actions should be recorded. Sensitive decisions should retain meaningful human review. Employees should know which systems are approved and what information must not be entered into them.

Organisations must also continue the ordinary work of cybersecurity: installing updates, replacing unsupported software, using multi-factor authentication, maintaining recoverable backups and controlling privileged accounts.

AI does not make those disciplines obsolete. It makes neglecting them more dangerous.

The instructive irony

There is an obvious irony in using artificial intelligence to help explain why artificial intelligence requires supervision.

But the irony also demonstrates the point.

AI can gather information, identify connections, test an argument and help a human publisher communicate a complicated subject. It does not have to be given final authority over what is true, what should be published or what consequences society should accept.

The useful relationship is not human or machine. It is capable technology operating within human purpose, judgment and accountability.

That principle should apply whether AI is helping to prepare a newspaper article, creating advertising copy, reviewing a company’s computer network or supporting an Australian government agency.

The Times View

Australia does not need to choose between using artificial intelligence and protecting itself from artificial intelligence. It must learn to do both at the same speed.

An early-warning system would not eliminate the risks, but it would give government, industry and researchers a better chance of seeing a threat before it spreads unseen through the country’s connected systems.

Canberra’s task is larger than writing another set of technology rules. It must build the institutions, technical expertise and trusted relationships required to govern a capability that will continue changing after any law is passed.

Artificial intelligence can give Australia stronger defences. It can also give its adversaries stronger weapons.

The decisive question is not whether the machines will become more capable. They will.

It is whether Australia’s systems of human oversight will become more capable with them.

Times Magazine

Australia Needs Permission Budgets for AI Agents

The Times recently argued that Australia should keep building the data centres the AI economy requ...

Nikon Is Developing Nine New Cinema Lenses and a Major ZR Firmware Update

Nikon is developing a new series of nine NIKKOR Z CINEMA T1.9 VV cinema lenses, designed for cinem...

The Hormuz conflict enters a more dangerous phase — and Australia will pay for every voyage

The conflict around Iran and the Strait of Hormuz has entered a more dangerous phase, with the Uni...

Technology

Australia Needs Permission Budgets …

The Times recently argued that Australia should keep building the data centres the AI economy requ...

Local News

Fitstop Global Games to Bring 1,000…

The Australian-born fitness brand is bringing its global competition home, with athletes from across...

Culture

Australia Needs Permission Budgets for AI Age…

The Times recently argued that Australia should keep building the data centres the AI economy requ...

Travel

Cairns Esplanade Lagoon — the stage where Cai…

“All the world's a stage.” Shakespeare wasn't writing about Cairns when he penned that famous lin...

The Times Features

Epson launches LifeStudio Series of smart mini projecto…

A major new chapter in smart home projection “designed for every moment” Epson has announced on...

Fitstop Global Games to Bring 1,000 Athletes to Brisban…

The Australian-born fitness brand is bringing its global competition home, with athletes from across...

AI Health Coaching Pilot Shows Potential to Extend Prim…

Early results from a New Zealand primary care rollout suggest AI could help health teams reach sig...