{"id":91803,"topic":"ai","source":"The Conversation","title":"Australia’s legacy systems were already a cyber risk. AI agents are raising the stakes - The Conversation","url":"https://theconversation.com/australias-legacy-systems-were-already-a-cyber-risk-ai-agents-are-raising-the-stakes-292981","url_hash":"269c374757171492cc61186f124446f4095c3df5","author":"","summary":"<a href=\"https://news.google.com/rss/articles/CBMiuwFBVV95cUxNMWlyWjN3MzhINEQyRDlLZmhEV2x0Q2FHcnNlci1udjJVZi1EV3MzLWJSbzV3LUQyXzd2ckt1dEdXMmtRRVNuOWJSa3cwMzAwLVhwcTdYTXB5NVFJVDd0V2lfU2kwZmFKcWI0Q3NwQ0g2SzI4XzZrMnprMFR6dTFyRTBTTlhucEpkT2JyRnZKZHJEQ1JDcUFsNEdxcGYtRG92bkExQkpQZ2FOX19CRmxXZlRSWEZSbG12OFBN?oc=5\" target=\"_blank\">Australia’s legacy systems were already a cyber risk. AI agents are raising the stakes</a>&nbsp;&nbsp;<font color=\"#6f6f6f\">The Conversation</font>","content":"In the days since an artificial intelligence (AI) agent operated by OpenAI gained unauthorised access to a Services Australia portal holding Medicare statistics, important questions have been raised about Australia’s readiness to prevent future breaches.\nSpecifically, concerns have been raised about whether Australia is particularly vulnerable to autonomous AI agents because so much of our digital infrastructure depends on outdated or “legacy” software.\nThe answer is more complicated than simply blaming the legacy systems.\nOutdated technology\nIn 2025, the Australian Signals Directorate reported that 59% of Australian government entities reported that legacy technologies were impacting their ability to implement key cyber security controls.\nLegacy technology generally refers to older hardware or software that is no longer supported by its manufacturer, cannot be adequately updated or patched, or cannot meet current security requirements.\nThe persistence of these outdated systems is not just a technical problem. As a recent report from the Australian Strategic Policy Institute argued, the underlying problems are often about governance. The key questions relate to who is responsible for replacing the systems, how to fund replacements and whether viable replacements actually exist.\nAustralia’s situation is hardly unique. The UK government estimates around 28% of its central government systems use legacy technology. In the US, a 2025 government review identified 11 critical federal legacy systems – up to 60 years old – supporting functions including health care, critical infrastructure, tax processing and national security.\nSo, legacy technology is an important part of the equation. But other factors also shape Australia’s exposure to AI-boosted cyber risk.\nWhy Australia remains an attractive target\nThe Australian Cyber Security Centre reports cyber criminals target Australia because of our widespread adoption of digital systems, perceived wealth and patchy cyber defences.\nAs in other countries, Australian governments and organisations also hold valuable personal, financial, health, research and proprietary information.\nThese factors matter in different ways. Legacy systems can increase the opportunities for systems to be compromised. And valuable data, economic wealth and critical services increase the incentive to exploit that opportunity.\nAgentic AI adds another dimension.\nAI agents change the equation\nCyber criminals and state-sponsored attackers have exploited old and unpatched systems for decades. More recently, AI has helped humans find vulnerabilities, analyse code and develop ways to exploit these systems faster.\nNow, an AI agent can be given an objective, plan how to achieve it, use tools, interact with external systems and adapt when it encounters an obstacle.\nThe Medicare incident in Australia was concerning not simply because AI was involved. According to the Australian Signals Directorate, the AI agent independently identified vulnerabilities and attempted further actions without direct human authorisation.\nNor is this phenomenon confined to Australia. Experimental AI agents have escaped containment during cyber security evaluations and reached an unknown number of third-party systems around the world.\nThe emerging problem is that agents may themselves discover and act on weaknesses while pursuing their objectives. These may be things never intended as cyber attacks, such as gathering publicly available medical data.\nSo, AI does not create vulnerabilities in ageing systems. But it may change how quickly, persistently and autonomously those vulnerabilities can be discovered and acted upon.\nSafety needs to work in both directions\nTo maintain security in a world of AI agents, governments and others hosting important data have a role to play. So do the organisations building and operating the agents.\nFirst, governments need to reduce the vulnerabilities AI agents can find. That means knowing where legacy systems are, which are unsupported, what data they contain and whether they are exposed to the internet.\nCountries cannot realistically replace decades of legacy technology before increasingly capable AI agents encounter it. However, outdated systems that can be retired should be retired. Those that cannot yet be replaced should be isolated, closely monitored and protected with greater controls.\nWhere critical legacy systems must remain operational, residual risk may need to be formally accepted by an accountable decision maker.\nNot every risk can be eliminated\nSecond, organisations using AI agents must control what they are allowed to see, access and do.\nThe Australian Signals Directorate recommends treating agents as distinct entities and giving them minimal access privileges, restricted permissions, strong authentication, monitoring and other controls.\nAn agent searching public information should have no reason to possess credentials providing access to sensitive internal systems.\nHuman oversight should also reflect risk. For riskier actions, humans may need to give approval before an agent proceeds. For less risky moves, it may be enough for a human to have the option to intervene.\nIt is also essential that organisations can see what agents have done. They need audit trails showing which systems the agent contacted, which tools it used, what permissions it exercised and when its behaviour departed from its authorised objective.\nThe objective should not necessarily be zero autonomy or zero risk. It should be controlled, visible and accountable autonomy.\nAustralia is not alone in facing the challenge of legacy systems in a world of AI agents. But its combination of valuable digital assets, existing technological weaknesses and high levels of digital adoption makes the issue particularly important.","image_url":"https://images.theconversation.com/files/762439/original/file-20260928-50-ofxypv.jpg?ixlib=rb-4.1.1&rect=0%2C1098%2C5000%2C2500&q=45&auto=format&w=1356&h=668&fit=crop","lang":"en","published_at":"2026-09-28T06:18:26+00:00","fetched_at":"2026-09-28T10:15:05+00:00","status":"read","starred":0,"extract_state":"ok","summary_auto":"In the days since an artificial intelligence (AI) agent operated by OpenAI gained unauthorised access to a Services Australia portal holding Medicare statistics, important questions have been raised about Australia’s readiness to prevent future breaches. Specifically, concerns have been raised about whether Australia is particularly vulnerable to autonomous AI agents because so much of our digital infrastructure depends on outdated or “legacy” software.","cluster_id":null,"extract_retries":0,"extract_error":null,"contract_version":"news_item.v1","format_contract_version":"news_item_formats.v1","dedup_url":"https://theconversation.com/australias-legacy-systems-were-already-a-cyber-risk-ai-agents-are-raising-the-stakes-292981","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 5813 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":5813,"summary_length":457,"usable_text_length":5813,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":5813,"summary_length":457}},"news_item":{"id":91803,"canonical_url":"https://theconversation.com/australias-legacy-systems-were-already-a-cyber-risk-ai-agents-are-raising-the-stakes-292981","source_url":"https://theconversation.com/australias-legacy-systems-were-already-a-cyber-risk-ai-agents-are-raising-the-stakes-292981","title":"Australia’s legacy systems were already a cyber risk. AI agents are raising the stakes - The Conversation","source_name":"The Conversation","author":null,"published_at":"2026-09-28T06:18:26+00:00","locale":"en","topic":"ai","tags":[],"rss_summary":"<a href=\"https://news.google.com/rss/articles/CBMiuwFBVV95cUxNMWlyWjN3MzhINEQyRDlLZmhEV2x0Q2FHcnNlci1udjJVZi1EV3MzLWJSbzV3LUQyXzd2ckt1dEdXMmtRRVNuOWJSa3cwMzAwLVhwcTdYTXB5NVFJVDd0V2lfU2kwZmFKcWI0Q3NwQ0g2SzI4XzZrMnprMFR6dTFyRTBTTlhucEpkT2JyRnZKZHJEQ1JDcUFsNEdxcGYtRG92bkExQkpQZ2FOX19CRmxXZlRSWEZSbG12OFBN?oc=5\" target=\"_blank\">Australia’s legacy systems were already a cyber risk. AI agents are raising the stakes</a>&nbsp;&nbsp;<font color=\"#6f6f6f\">The Conversation</font>","full_text":"In the days since an artificial intelligence (AI) agent operated by OpenAI gained unauthorised access to a Services Australia portal holding Medicare statistics, important questions have been raised about Australia’s readiness to prevent future breaches.\nSpecifically, concerns have been raised about whether Australia is particularly vulnerable to autonomous AI agents because so much of our digital infrastructure depends on outdated or “legacy” software.\nThe answer is more complicated than simply blaming the legacy systems.\nOutdated technology\nIn 2025, the Australian Signals Directorate reported that 59% of Australian government entities reported that legacy technologies were impacting their ability to implement key cyber security controls.\nLegacy technology generally refers to older hardware or software that is no longer supported by its manufacturer, cannot be adequately updated or patched, or cannot meet current security requirements.\nThe persistence of these outdated systems is not just a technical problem. As a recent report from the Australian Strategic Policy Institute argued, the underlying problems are often about governance. The key questions relate to who is responsible for replacing the systems, how to fund replacements and whether viable replacements actually exist.\nAustralia’s situation is hardly unique. The UK government estimates around 28% of its central government systems use legacy technology. In the US, a 2025 government review identified 11 critical federal legacy systems – up to 60 years old – supporting functions including health care, critical infrastructure, tax processing and national security.\nSo, legacy technology is an important part of the equation. But other factors also shape Australia’s exposure to AI-boosted cyber risk.\nWhy Australia remains an attractive target\nThe Australian Cyber Security Centre reports cyber criminals target Australia because of our widespread adoption of digital systems, perceived wealth and patchy cyber defences.\nAs in other countries, Australian governments and organisations also hold valuable personal, financial, health, research and proprietary information.\nThese factors matter in different ways. Legacy systems can increase the opportunities for systems to be compromised. And valuable data, economic wealth and critical services increase the incentive to exploit that opportunity.\nAgentic AI adds another dimension.\nAI agents change the equation\nCyber criminals and state-sponsored attackers have exploited old and unpatched systems for decades. More recently, AI has helped humans find vulnerabilities, analyse code and develop ways to exploit these systems faster.\nNow, an AI agent can be given an objective, plan how to achieve it, use tools, interact with external systems and adapt when it encounters an obstacle.\nThe Medicare incident in Australia was concerning not simply because AI was involved. According to the Australian Signals Directorate, the AI agent independently identified vulnerabilities and attempted further actions without direct human authorisation.\nNor is this phenomenon confined to Australia. Experimental AI agents have escaped containment during cyber security evaluations and reached an unknown number of third-party systems around the world.\nThe emerging problem is that agents may themselves discover and act on weaknesses while pursuing their objectives. These may be things never intended as cyber attacks, such as gathering publicly available medical data.\nSo, AI does not create vulnerabilities in ageing systems. But it may change how quickly, persistently and autonomously those vulnerabilities can be discovered and acted upon.\nSafety needs to work in both directions\nTo maintain security in a world of AI agents, governments and others hosting important data have a role to play. So do the organisations building and operating the agents.\nFirst, governments need to reduce the vulnerabilities AI agents can find. That means knowing where legacy systems are, which are unsupported, what data they contain and whether they are exposed to the internet.\nCountries cannot realistically replace decades of legacy technology before increasingly capable AI agents encounter it. However, outdated systems that can be retired should be retired. Those that cannot yet be replaced should be isolated, closely monitored and protected with greater controls.\nWhere critical legacy systems must remain operational, residual risk may need to be formally accepted by an accountable decision maker.\nNot every risk can be eliminated\nSecond, organisations using AI agents must control what they are allowed to see, access and do.\nThe Australian Signals Directorate recommends treating agents as distinct entities and giving them minimal access privileges, restricted permissions, strong authentication, monitoring and other controls.\nAn agent searching public information should have no reason to possess credentials providing access to sensitive internal systems.\nHuman oversight should also reflect risk. For riskier actions, humans may need to give approval before an agent proceeds. For less risky moves, it may be enough for a human to have the option to intervene.\nIt is also essential that organisations can see what agents have done. They need audit trails showing which systems the agent contacted, which tools it used, what permissions it exercised and when its behaviour departed from its authorised objective.\nThe objective should not necessarily be zero autonomy or zero risk. It should be controlled, visible and accountable autonomy.\nAustralia is not alone in facing the challenge of legacy systems in a world of AI agents. But its combination of valuable digital assets, existing technological weaknesses and high levels of digital adoption makes the issue particularly important.","excerpt":"In the days since an artificial intelligence (AI) agent operated by OpenAI gained unauthorised access to a Services Australia portal holding Medicare statistics, important questions have been raised about Australia’s readiness to prevent future breaches. Specifically, concerns have been raised about whether Australia is particularly vulnerable to autonomous AI agents because so much of our digital infrastructure depends on outdated or “legacy” software.","extraction":{"state":"ok","confidence":0.9,"error":null,"explanation":"High confidence: full text extraction produced 5813 characters.","diagnostics_url":"/api/diagnose?url=https%3A//theconversation.com/australias-legacy-systems-were-already-a-cyber-risk-ai-agents-are-raising-the-stakes-292981","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 5813 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":5813,"summary_length":457,"usable_text_length":5813,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":5813,"summary_length":457}}},"display_formats":["compact","card","full","digest_section","json"]},"daily_stack_record":{"title":"Australia’s legacy systems were already a cyber risk. AI agents are raising the stakes - The Conversation","url":"https://theconversation.com/australias-legacy-systems-were-already-a-cyber-risk-ai-agents-are-raising-the-stakes-292981","summary":"In the days since an artificial intelligence (AI) agent operated by OpenAI gained unauthorised access to a Services Australia portal holding Medicare statistics, important questions have been raised about Australia’s readiness to prevent future breaches. Specifically, concerns have been raised about whether Australia is particularly vulnerable to autonomous AI agents because so much of our digital infrastructure depends on outdated or “legacy” software.","source":"The Conversation","date":"2026-09-28T06:18:26+00:00","content":"In the days since an artificial intelligence (AI) agent operated by OpenAI gained unauthorised access to a Services Australia portal holding Medicare statistics, important questions have been raised about Australia’s readiness to prevent future breaches.\nSpecifically, concerns have been raised about whether Australia is particularly vulnerable to autonomous AI agents because so much of our digital infrastructure depends on outdated or “legacy” software.\nThe answer is more complicated than simply blaming the legacy systems.\nOutdated technology\nIn 2025, the Australian Signals Directorate reported that 59% of Australian government entities reported that legacy technologies were impacting their ability to implement key cyber security controls.\nLegacy technology generally refers to older hardware or software that is no longer supported by its manufacturer, cannot be adequately updated or patched, or cannot meet current security requirements.\nThe persistence of these outdated systems is not just a technical problem. As a recent report from the Australian Strategic Policy Institute argued, the underlying problems are often about governance. The key questions relate to who is responsible for replacing the systems, how to fund replacements and whether viable replacements actually exist.\nAustralia’s situation is hardly unique. The UK government estimates around 28% of its central government systems use legacy technology. In the US, a 2025 government review identified 11 critical federal legacy systems – up to 60 years old – supporting functions including health care, critical infrastructure, tax processing and national security.\nSo, legacy technology is an important part of the equation. But other factors also shape Australia’s exposure to AI-boosted cyber risk.\nWhy Australia remains an attractive target\nThe Australian Cyber Security Centre reports cyber criminals target Australia because of our widespread adoption of digital systems, perceived wealth and patchy cyber defences.\nAs in other countries, Australian governments and organisations also hold valuable personal, financial, health, research and proprietary information.\nThese factors matter in different ways. Legacy systems can increase the opportunities for systems to be compromised. And valuable data, economic wealth and critical services increase the incentive to exploit that opportunity.\nAgentic AI adds another dimension.\nAI agents change the equation\nCyber criminals and state-sponsored attackers have exploited old and unpatched systems for decades. More recently, AI has helped humans find vulnerabilities, analyse code and develop ways to exploit these systems faster.\nNow, an AI agent can be given an objective, plan how to achieve it, use tools, interact with external systems and adapt when it encounters an obstacle.\nThe Medicare incident in Australia was concerning not simply because AI was involved. According to the Australian Signals Directorate, the AI agent independently identified vulnerabilities and attempted further actions without direct human authorisation.\nNor is this phenomenon confined to Australia. Experimental AI agents have escaped containment during cyber security evaluations and reached an unknown number of third-party systems around the world.\nThe emerging problem is that agents may themselves discover and act on weaknesses while pursuing their objectives. These may be things never intended as cyber attacks, such as gathering publicly available medical data.\nSo, AI does not create vulnerabilities in ageing systems. But it may change how quickly, persistently and autonomously those vulnerabilities can be discovered and acted upon.\nSafety needs to work in both directions\nTo maintain security in a world of AI agents, governments and others hosting important data have a role to play. So do the organisations building and operating the agents.\nFirst, governments need to reduce the vulnerabilities AI agents can find. That means knowing where legacy systems are, which are unsupported, what data they contain and whether they are exposed to the internet.\nCountries cannot realistically replace decades of legacy technology before increasingly capable AI agents encounter it. However, outdated systems that can be retired should be retired. Those that cannot yet be replaced should be isolated, closely monitored and protected with greater controls.\nWhere critical legacy systems must remain operational, residual risk may need to be formally accepted by an accountable decision maker.\nNot every risk can be eliminated\nSecond, organisations using AI agents must control what they are allowed to see, access and do.\nThe Australian Signals Directorate recommends treating agents as distinct entities and giving them minimal access privileges, restricted permissions, strong authentication, monitoring and other controls.\nAn agent searching public information should have no reason to possess credentials providing access to sensitive internal systems.\nHuman oversight should also reflect risk. For riskier actions, humans may need to give approval before an agent proceeds. For less risky moves, it may be enough for a human to have the option to intervene.\nIt is also essential that organisations can see what agents have done. They need audit trails showing which systems the agent contacted, which tools it used, what permissions it exercised and when its behaviour departed from its authorised objective.\nThe objective should not necessarily be zero autonomy or zero risk. It should be controlled, visible and accountable autonomy.\nAustralia is not alone in facing the challenge of legacy systems in a world of AI agents. But its combination of valuable digital assets, existing technological weaknesses and high levels of digital adoption makes the issue particularly important.","confidence":0.9,"diagnostics_url":"/api/diagnose?url=https%3A//theconversation.com/australias-legacy-systems-were-already-a-cyber-risk-ai-agents-are-raising-the-stakes-292981","quality_bucket":"high","failure_kind":"none","retryable":false,"quality_reason":"High confidence: full text extraction produced 5813 characters.","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 5813 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":5813,"summary_length":457,"usable_text_length":5813,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":5813,"summary_length":457}},"tags":[]},"fallback_formats":["markdown","json","html"],"actions":{"read":"/item/91803","export_markdown":"/api/items/91803/export?format=markdown","export_json":"/api/items/91803/export?format=json","diagnose":"/api/diagnose?url=https%3A//theconversation.com/australias-legacy-systems-were-already-a-cyber-risk-ai-agents-are-raising-the-stakes-292981"},"formats":{"full":{"id":91803,"title":"Australia’s legacy systems were already a cyber risk. AI agents are raising the stakes - The Conversation","url":"https://theconversation.com/australias-legacy-systems-were-already-a-cyber-risk-ai-agents-are-raising-the-stakes-292981","source":"The Conversation","author":null,"published_at":"2026-09-28T06:18:26+00:00","locale":"en","topic":"ai","tags":[],"excerpt":"In the days since an artificial intelligence (AI) agent operated by OpenAI gained unauthorised access to a Services Australia portal holding Medicare statistics, important questions have been raised about Australia’s readiness to prevent future breaches. Specifically, concerns have been raised about whether Australia is particularly vulnerable to autonomous AI agents because so much of our digital infrastructure depends on outdated or “legacy” software.","full_text":"In the days since an artificial intelligence (AI) agent operated by OpenAI gained unauthorised access to a Services Australia portal holding Medicare statistics, important questions have been raised about Australia’s readiness to prevent future breaches.\nSpecifically, concerns have been raised about whether Australia is particularly vulnerable to autonomous AI agents because so much of our digital infrastructure depends on outdated or “legacy” software.\nThe answer is more complicated than simply blaming the legacy systems.\nOutdated technology\nIn 2025, the Australian Signals Directorate reported that 59% of Australian government entities reported that legacy technologies were impacting their ability to implement key cyber security controls.\nLegacy technology generally refers to older hardware or software that is no longer supported by its manufacturer, cannot be adequately updated or patched, or cannot meet current security requirements.\nThe persistence of these outdated systems is not just a technical problem. As a recent report from the Australian Strategic Policy Institute argued, the underlying problems are often about governance. The key questions relate to who is responsible for replacing the systems, how to fund replacements and whether viable replacements actually exist.\nAustralia’s situation is hardly unique. The UK government estimates around 28% of its central government systems use legacy technology. In the US, a 2025 government review identified 11 critical federal legacy systems – up to 60 years old – supporting functions including health care, critical infrastructure, tax processing and national security.\nSo, legacy technology is an important part of the equation. But other factors also shape Australia’s exposure to AI-boosted cyber risk.\nWhy Australia remains an attractive target\nThe Australian Cyber Security Centre reports cyber criminals target Australia because of our widespread adoption of digital systems, perceived wealth and patchy cyber defences.\nAs in other countries, Australian governments and organisations also hold valuable personal, financial, health, research and proprietary information.\nThese factors matter in different ways. Legacy systems can increase the opportunities for systems to be compromised. And valuable data, economic wealth and critical services increase the incentive to exploit that opportunity.\nAgentic AI adds another dimension.\nAI agents change the equation\nCyber criminals and state-sponsored attackers have exploited old and unpatched systems for decades. More recently, AI has helped humans find vulnerabilities, analyse code and develop ways to exploit these systems faster.\nNow, an AI agent can be given an objective, plan how to achieve it, use tools, interact with external systems and adapt when it encounters an obstacle.\nThe Medicare incident in Australia was concerning not simply because AI was involved. According to the Australian Signals Directorate, the AI agent independently identified vulnerabilities and attempted further actions without direct human authorisation.\nNor is this phenomenon confined to Australia. Experimental AI agents have escaped containment during cyber security evaluations and reached an unknown number of third-party systems around the world.\nThe emerging problem is that agents may themselves discover and act on weaknesses while pursuing their objectives. These may be things never intended as cyber attacks, such as gathering publicly available medical data.\nSo, AI does not create vulnerabilities in ageing systems. But it may change how quickly, persistently and autonomously those vulnerabilities can be discovered and acted upon.\nSafety needs to work in both directions\nTo maintain security in a world of AI agents, governments and others hosting important data have a role to play. So do the organisations building and operating the agents.\nFirst, governments need to reduce the vulnerabilities AI agents can find. That means knowing where legacy systems are, which are unsupported, what data they contain and whether they are exposed to the internet.\nCountries cannot realistically replace decades of legacy technology before increasingly capable AI agents encounter it. However, outdated systems that can be retired should be retired. Those that cannot yet be replaced should be isolated, closely monitored and protected with greater controls.\nWhere critical legacy systems must remain operational, residual risk may need to be formally accepted by an accountable decision maker.\nNot every risk can be eliminated\nSecond, organisations using AI agents must control what they are allowed to see, access and do.\nThe Australian Signals Directorate recommends treating agents as distinct entities and giving them minimal access privileges, restricted permissions, strong authentication, monitoring and other controls.\nAn agent searching public information should have no reason to possess credentials providing access to sensitive internal systems.\nHuman oversight should also reflect risk. For riskier actions, humans may need to give approval before an agent proceeds. For less risky moves, it may be enough for a human to have the option to intervene.\nIt is also essential that organisations can see what agents have done. They need audit trails showing which systems the agent contacted, which tools it used, what permissions it exercised and when its behaviour departed from its authorised objective.\nThe objective should not necessarily be zero autonomy or zero risk. It should be controlled, visible and accountable autonomy.\nAustralia is not alone in facing the challenge of legacy systems in a world of AI agents. But its combination of valuable digital assets, existing technological weaknesses and high levels of digital adoption makes the issue particularly important.","reading_time_min":4,"extraction":{"state":"ok","confidence":0.9,"error":null,"explanation":"High confidence: full text extraction produced 5813 characters.","diagnostics_url":"/api/diagnose?url=https%3A//theconversation.com/australias-legacy-systems-were-already-a-cyber-risk-ai-agents-are-raising-the-stakes-292981","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 5813 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":5813,"summary_length":457,"usable_text_length":5813,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":5813,"summary_length":457}}},"quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 5813 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":5813,"summary_length":457,"usable_text_length":5813,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":5813,"summary_length":457}},"actions":{"read":"/item/91803","export_markdown":"/api/items/91803/export?format=markdown","export_json":"/api/items/91803/export?format=json","diagnose":"/api/diagnose?url=https%3A//theconversation.com/australias-legacy-systems-were-already-a-cyber-risk-ai-agents-are-raising-the-stakes-292981"}},"digest":{"id":91803,"title":"Australia’s legacy systems were already a cyber risk. AI agents are raising the stakes - The Conversation","url":"https://theconversation.com/australias-legacy-systems-were-already-a-cyber-risk-ai-agents-are-raising-the-stakes-292981","source":"The Conversation","topic":"ai","published_at":"2026-09-28T06:18:26+00:00","excerpt":"In the days since an artificial intelligence (AI) agent operated by OpenAI gained unauthorised access to a Services Australia portal holding Medicare statistics, important questions have been raised about Australia’s readiness to prevent future breaches. Specifically, concerns…","quality_bucket":"high","quality_reason":"High confidence: full text extraction produced 5813 characters.","reading_time_min":4,"cluster_id":null},"card":{"display_title":"Australia’s legacy systems were already a cyber risk. AI agents are raising the stakes - The Conversation","subtitle":"The Conversation · 2026-09-28","summary":"In the days since an artificial intelligence (AI) agent operated by OpenAI gained unauthorised access to a Services Australia portal holding Medicare statistics, important questions have been raised about Australia’s…","badges":["quality:high"],"links":{"read":"/item/91803","original":"https://theconversation.com/australias-legacy-systems-were-already-a-cyber-risk-ai-agents-are-raising-the-stakes-292981","diagnose":"/api/diagnose?url=https%3A//theconversation.com/australias-legacy-systems-were-already-a-cyber-risk-ai-agents-are-raising-the-stakes-292981"},"quality_warning":null},"export":{"title":"Australia’s legacy systems were already a cyber risk. AI agents are raising the stakes - The Conversation","url":"https://theconversation.com/australias-legacy-systems-were-already-a-cyber-risk-ai-agents-are-raising-the-stakes-292981","summary":"In the days since an artificial intelligence (AI) agent operated by OpenAI gained unauthorised access to a Services Australia portal holding Medicare statistics, important questions have been raised about Australia’s readiness to prevent future breaches. Specifically, concerns have been raised about whether Australia is particularly vulnerable to autonomous AI agents because so much of our digital infrastructure depends on outdated or “legacy” software.","source":"The Conversation","date":"2026-09-28T06:18:26+00:00","content":"In the days since an artificial intelligence (AI) agent operated by OpenAI gained unauthorised access to a Services Australia portal holding Medicare statistics, important questions have been raised about Australia’s readiness to prevent future breaches.\nSpecifically, concerns have been raised about whether Australia is particularly vulnerable to autonomous AI agents because so much of our digital infrastructure depends on outdated or “legacy” software.\nThe answer is more complicated than simply blaming the legacy systems.\nOutdated technology\nIn 2025, the Australian Signals Directorate reported that 59% of Australian government entities reported that legacy technologies were impacting their ability to implement key cyber security controls.\nLegacy technology generally refers to older hardware or software that is no longer supported by its manufacturer, cannot be adequately updated or patched, or cannot meet current security requirements.\nThe persistence of these outdated systems is not just a technical problem. As a recent report from the Australian Strategic Policy Institute argued, the underlying problems are often about governance. The key questions relate to who is responsible for replacing the systems, how to fund replacements and whether viable replacements actually exist.\nAustralia’s situation is hardly unique. The UK government estimates around 28% of its central government systems use legacy technology. In the US, a 2025 government review identified 11 critical federal legacy systems – up to 60 years old – supporting functions including health care, critical infrastructure, tax processing and national security.\nSo, legacy technology is an important part of the equation. But other factors also shape Australia’s exposure to AI-boosted cyber risk.\nWhy Australia remains an attractive target\nThe Australian Cyber Security Centre reports cyber criminals target Australia because of our widespread adoption of digital systems, perceived wealth and patchy cyber defences.\nAs in other countries, Australian governments and organisations also hold valuable personal, financial, health, research and proprietary information.\nThese factors matter in different ways. Legacy systems can increase the opportunities for systems to be compromised. And valuable data, economic wealth and critical services increase the incentive to exploit that opportunity.\nAgentic AI adds another dimension.\nAI agents change the equation\nCyber criminals and state-sponsored attackers have exploited old and unpatched systems for decades. More recently, AI has helped humans find vulnerabilities, analyse code and develop ways to exploit these systems faster.\nNow, an AI agent can be given an objective, plan how to achieve it, use tools, interact with external systems and adapt when it encounters an obstacle.\nThe Medicare incident in Australia was concerning not simply because AI was involved. According to the Australian Signals Directorate, the AI agent independently identified vulnerabilities and attempted further actions without direct human authorisation.\nNor is this phenomenon confined to Australia. Experimental AI agents have escaped containment during cyber security evaluations and reached an unknown number of third-party systems around the world.\nThe emerging problem is that agents may themselves discover and act on weaknesses while pursuing their objectives. These may be things never intended as cyber attacks, such as gathering publicly available medical data.\nSo, AI does not create vulnerabilities in ageing systems. But it may change how quickly, persistently and autonomously those vulnerabilities can be discovered and acted upon.\nSafety needs to work in both directions\nTo maintain security in a world of AI agents, governments and others hosting important data have a role to play. So do the organisations building and operating the agents.\nFirst, governments need to reduce the vulnerabilities AI agents can find. That means knowing where legacy systems are, which are unsupported, what data they contain and whether they are exposed to the internet.\nCountries cannot realistically replace decades of legacy technology before increasingly capable AI agents encounter it. However, outdated systems that can be retired should be retired. Those that cannot yet be replaced should be isolated, closely monitored and protected with greater controls.\nWhere critical legacy systems must remain operational, residual risk may need to be formally accepted by an accountable decision maker.\nNot every risk can be eliminated\nSecond, organisations using AI agents must control what they are allowed to see, access and do.\nThe Australian Signals Directorate recommends treating agents as distinct entities and giving them minimal access privileges, restricted permissions, strong authentication, monitoring and other controls.\nAn agent searching public information should have no reason to possess credentials providing access to sensitive internal systems.\nHuman oversight should also reflect risk. For riskier actions, humans may need to give approval before an agent proceeds. For less risky moves, it may be enough for a human to have the option to intervene.\nIt is also essential that organisations can see what agents have done. They need audit trails showing which systems the agent contacted, which tools it used, what permissions it exercised and when its behaviour departed from its authorised objective.\nThe objective should not necessarily be zero autonomy or zero risk. It should be controlled, visible and accountable autonomy.\nAustralia is not alone in facing the challenge of legacy systems in a world of AI agents. But its combination of valuable digital assets, existing technological weaknesses and high levels of digital adoption makes the issue particularly important.","confidence":0.9,"diagnostics_url":"/api/diagnose?url=https%3A//theconversation.com/australias-legacy-systems-were-already-a-cyber-risk-ai-agents-are-raising-the-stakes-292981","quality_bucket":"high","failure_kind":"none","retryable":false,"quality_reason":"High confidence: full text extraction produced 5813 characters.","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 5813 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":5813,"summary_length":457,"usable_text_length":5813,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":5813,"summary_length":457}},"tags":[],"format_contract_version":"news_item_formats.v1"}}}