Australia’s aging technology could be facing a very modern threat: AI agents that can find weaknesses at speeds that dramatically shorten defenders' response time.
Australian Signals Directorate Director-General Abigail Bradshaw warned this week that artificial intelligence is changing the country’s cyber threat landscape, potentially giving attackers new ways to find and exploit vulnerabilities across outdated systems. She called for Australia to develop an AI “early warning system” that could help organizations identify emerging risks before they spread.
The concern reaches beyond Australia. As autonomous AI systems become better at navigating networks, writing code, and completing multistep tasks, the same capabilities businesses hope will make workers more productive could also make cyberattacks faster and easier to scale.
Australia’s old technology meets a new kind of attacker
Speaking at the Australian Strategic Policy Institute’s Sydney Dialogue AI Masterclass, Bradshaw warned about the security implications of increasingly capable AI systems.
According to ABC News, she urged Australian organizations to embrace AI as a defensive tool while government, industry, and AI companies improve how they share information about emerging risks.
Bradshaw offered a striking example of AI’s potential speed advantage. Work that previously would have taken ASD cybersecurity experts “weeks and weeks” could now be completed in hours using advanced AI models, she said.
Part of the problem is the technology already in place within Australian organizations.
Bradshaw warned that outdated systems remain vulnerable as AI increases the speed at which weaknesses can be discovered. The Guardian reported that she expects legacy technology would likely be among the first systems compromised in a major AI-enabled attack if organizations fail to modernize quickly enough.
That concern builds on an existing technology problem in the country. eWeek previously examined how 58% of Australian enterprises surveyed by IDC and MongoDB described their technology architecture as too rigid, costly, and slow to support the AI systems they are trying to build.
That creates an uncomfortable mismatch. Organizations may be adopting increasingly sophisticated AI, while some of the underlying infrastructure was designed for a much slower threat environment.
Australia is also investing heavily in the infrastructure needed for an AI-driven economy. eWeek recently examined Australia’s AI data center boom, noting that billions of dollars are flowing into new computing capacity as the country tries to position itself as a regional AI hub.
More computing power, however, also means more infrastructure to protect.
Why AI agents change the cybersecurity equation
Generative AI has already made it easier to produce convincing phishing messages, analyze code, and automate pieces of an attack. AI agents potentially push that further because they are designed to take actions and complete sequences of tasks with less human intervention.
An agent tasked with finding a vulnerability, for example, could theoretically examine systems, test possible weaknesses, adjust its approach, and continue working toward a goal.
There are already signs of cyberattacks moving in this direction. eWeek reported in July on what researchers described as the first known “agentic ransomware” attack, in which an AI system was used to automate multiple stages of a ransomware operation.
That does not mean autonomous AI agents can simply break into any system. Their capabilities remain constrained by the models, tools, permissions, and environments available to them, and Bradshaw’s warning is about the direction of the threat rather than evidence that autonomous agents are already compromising Australian infrastructure at scale.
But the trajectory matters.
Bradshaw said AI’s ability to quickly identify vulnerabilities could force organizations to rethink even basic security practices. Instead of following predictable patching schedules, she suggested some vulnerabilities may need to be addressed within 48 hours as organizations increasingly prioritize security over uninterrupted system availability.
Australia wants AI fighting AI
Bradshaw’s proposed answer is not to keep artificial intelligence away from cybersecurity. It is to put more AI on defense.
She said Australia currently lacks a formalized AI equivalent of the early-warning mechanisms already used in cybersecurity. Bringing together reports about individual AI incidents could help intelligence agencies, businesses, and AI companies identify broader patterns and emerging risks.
Bradshaw also pointed to existing partnerships between government and industry, along with international arrangements for the rapid sharing of technical information, as models Australia could build on.
The concept reflects a broader shift in cybersecurity. If attackers can use AI to accelerate reconnaissance and vulnerability discovery, defenders will increasingly need capabilities that can operate at comparable speed.
That makes information sharing particularly important. A weakness discovered against one organization could potentially be relevant to many others, making early identification and rapid communication more valuable as AI compresses response times.
For Australia, the challenge is particularly sharp. The country is simultaneously trying to accelerate AI adoption, expand computing infrastructure, and modernize technology environments that were not designed for autonomous AI systems.
What eWeek found: Australia’s AI warning is really about speed
Bradshaw’s warning points to a larger problem than any single AI-powered hacking technique.
- The security gap could become a speed gap. Legacy systems have always created vulnerabilities, but AI could dramatically shorten the time required to discover weaknesses. Bradshaw’s weeks-to-hours example shows how large that shift could become.
- AI defense may become less optional. Bradshaw explicitly urged Australian organizations to embrace AI defensively, arguing that defenders need capabilities comparable to those available to cybercriminals and state-backed attackers.
- Modernizing old systems becomes an AI issue. Australia’s push to build new AI infrastructure cannot be separated from the technology already running inside businesses and government agencies. New computing capacity does not erase vulnerabilities in older systems.
- Availability could become a security trade-off. Bradshaw warned that faster vulnerability discovery could require organizations to patch systems much more quickly, potentially taking services offline that Australians have grown accustomed to having continuously available.
- Australia could become an important test case. The country is simultaneously expanding its AI capabilities and confronting the security consequences of that expansion. How successfully it connects government intelligence, private-sector defenses, AI companies, and rapid information sharing could offer lessons well beyond Australia.
The AI race is becoming more than a competition to build smarter models and larger data centers. It is also becoming a race between attackers and defenders over who can put those capabilities to work faster.
Related reading: For another look at how AI is reshaping cyber threats, read the Federal Reserve's warning that frontier AI could find vulnerabilities and chain exploits at machine speed.


