A purge of legacy systems across Australia’s federal government would likely cost billions and remains unlikely. Still, the OpenAI Medicare breach has prompted an immediate stocktake of the outdated technology agencies run.
PSPF Direction 002-2026 was signed by Home Affairs Secretary Stephanie Foster on September 29. It gives non-corporate Commonwealth entities until 31 March 2027 to identify their legacy systems and plan to reduce them.
The direction does not mince words. "In the contemporary cyber threat environment, where Frontier AI capabilities have targeted the Commonwealth's technology estate, the continued operation of vulnerable legacy technology systems... poses an unacceptable risk to the Australian Government," it states.
"We can't wait for an old system to fail before replacing it. We need to identify vulnerabilities and deal with them before they can be exploited," Acting Home Affairs Minister Richard Marles said, as reported by The Conversation.
The scale of the problem is well documented. In 2025, the Australian Signals Directorate reported that 59% of government entities said legacy technology was impacting their ability to implement key cyber security controls.
A 2024 Mandala and Microsoft report found 71% of departments still relied on outdated IT. It consumed around 40% of their technology budgets, The Canberra Times reported.
What agencies must do
Each entity must identify all legacy systems run by it or on its behalf, prioritising public-facing services. It then needs a Legacy Technology Risk Management Plan with a reduction target matched to its risk appetite.
The plan must also cover prioritisation, mitigations for systems that stay in service and procedures to rationalise the technology estate. Results go to Home Affairs' Commonwealth Security Policy Branch.
Agencies running Systems of Government Significance face a 31 December 2026 deadline for additional risk reduction measures. Detail will follow in a Policy Explanatory Note due by 13 October.
Agencies must also patch faster, recognising "the shortened time between vulnerability discovery and exploitation". Reporting exemptions are limited to national security functions.
A governance problem, not just a technical one
Abu Barkat ullah, Associate Professor of Cyber Security at the University of Canberra, argues the answer is "more complicated than simply blaming the legacy systems". Writing in The Conversation, he points to an Australian Strategic Policy Institute finding that the underlying problems are often about governance.
"The key questions relate to who is responsible for replacing the systems, how to fund replacements and whether viable replacements actually exist," he wrote.
He is frank about the limits. "Countries cannot realistically replace decades of legacy technology before increasingly capable AI agents encounter it."
Systems that can be retired should be, he argues. Those that cannot "should be isolated, closely monitored and protected with greater controls."
Where critical systems must stay, residual risk may need to be formally accepted by an accountable decision maker.
"AI does not create vulnerabilities in ageing systems. But it may change how quickly, persistently and autonomously those vulnerabilities can be discovered and acted upon," he wrote.
He also puts onus on agent operators. "An agent searching public information should have no reason to possess credentials providing access to sensitive internal systems."
Australian Cyber Security Centre head Stephanie Crowe said AI was changing "the rate, scale and speed" of malicious activity. She stressed that software updates, network segmentation and zero trust remain the most effective defences.
What OpenAI says happened
In a post titled How we will do better for Australia, OpenAI apologised for its models accessing four Australian government services without authorisation in June.
An experimental internal model, asked to research spending on medicines for skin conditions in Victoria, found non-public access to Services Australia's Medicare Statistics Reporting Service. OpenAI says it ran commands and retrieved internal files, credentials and aggregate statistics, but no individual records.
Its agents also reached three other bodies: the NSW Bureau of Crime Statistics and Research, the Victorian Agency for Health Information and the AIHW.
OpenAI found the activity in mid-August and told Services Australia on 10 September. "We should have shared preliminary findings sooner," it said.
It has promised an Australian taskforce to report by year's end. Chief Strategy Officer Jason Kwon is due before the Joint Select Committee on Artificial Intelligence in Sydney on 6 October.