Policy Research Program

Security at the Margins: AI, Public Sector Governance, and Australia's National Security Gap

By George Trigenis, Josianne Belyea, Tara Matheson, and Tian Tian Dorge

·

EXECUTIVE SUMMARY

The global artificial intelligence (AI) ecosystem is increasingly characterised by an unprecedented concentration of technological prowess, with secure AI infrastructure, data protection, and cybersecurity emerging as core pillars that are fundamentally reshaping national security priorities worldwide. In Australia, this shift underscores the importance of embedding national security considerations into public-sector AI deployment to safeguard government systems against emerging threats.

Our research examines how gaps in Australia's National AI Plan may increase public-sector exposure to national security risks relative to peer jurisdictions, the lessons to be drawn from international approaches, and the policy levers available to mitigate these challenges.

This paper addresses: (1) the evolving nature of technology and security in a national security context; (2) comparative analysis of national AI plans in the United States, Canada, the People's Republic of China, and the Republic of Korea; (3) AI adoption in the Australian economic and social context, as well as public-sector specific AI threats; and (4) actionable mitigation levers and solutions against public sector AI threats.

The comparative jurisdictional analysis reveals distinct approaches to AI and national security:

1. The United States of America (US)

The US treats AI as strategic infrastructure and a national-power asset, linking AI leadership directly to economic competitiveness, military advantage, export control, cyber resilience, and global standard-setting. Its model is highly top-down and White House-led, using executive orders, OMB memoranda, federal procurement, infrastructure acceleration, National Institute of Standards and Technology (NIST) testing capacity, and an AI export strategy to advance adoption and security simultaneously.

2. Canada

Canada has positioned itself as a leading power in the creation of AI policy. Implemented in 2017, the Pan-Canadian AI Strategy was the first national AI strategy to be adopted globally. This, alongside the AI Strategy for the Federal Public Service (2025-2027), its Directive on Automated Decision Making, and Guide on the Use of Generative AI, demonstrates a commitment to human-centred and responsible AI implementation. Canada's approach thus prioritises tools that mitigate against internal risks of AI use, such as bias and transparency.

3. The People's Republic of China

China has established AI as a cornerstone of national strategy through two primary directives: the 2017 New Generation AI Development Plan and the 2025 AI+ Action Plan, framing AI as essential to economic resilience, social governance, and global influence. China targets 70% AI penetration across key sectors by 2027, 90% by 2030, and a fully AI-powered economy by 2035, prioritising practical, large-scale deployment across industry, healthcare, defence, and governance over AGI investment. Public sentiment remains broadly optimistic, with 95% expressing confidence in AI's future.

4. The Republic of Korea

South Korea has established a centralised, innovation-driven AI national strategy through its Framework Act on the Development of Artificial Intelligence and the Establishment of Trust (AI Basic Act) enacted in 2025 and the National AI Action Plan (2026 to 2028). South Korea aims for a top-three global AI status by 2030, with ambitious public-sector adoption objectives, a dual "full-stake" strategy for sovereign AI development, alignment with the US, and significant public-private investment partnerships. Although formal AI legislation excludes defence and national security systems from its scope, South Korea embeds cybersecurity and AI risk oversight via dedicated inter-agency bodies.

5. Australia

Australia's National AI Plan is primarily a civilian, productivity, and inclusion strategy: it aims to capture the economic gains from AI, spread benefits across workers and communities, and keep Australians safe through existing legal, regulatory and ethical frameworks. National security is present through digital sovereignty, foreign investment screening, data-centre expectations, critical infrastructure references, and GovAI. However, Australia's AI Plan does not publicly integrate defence, intelligence, dual-use AI, AUKUS Pillar II, or a ranked map of high-risk public-sector systems. Implementation is practical but soft: it relies on GovAI, Chief AI Officers, training, grants, R&D incentives and voluntary standards, leaving Australia with a weaker enforceability and assurance framework than leading peers. Australia can learn from peer jurisdictions without replicating them directly: from the US, it can take central coordination, procurement discipline, and strategic infrastructure framing; from Canada, mandatory algorithmic impact assessment and public transparency; from China, the importance of technical standards being operational controls rather than abstract ethics language; and from South Korea, dedicated AI legislation and institutional coordination through a national AI committee.

Based on these findings, the paper proposes the following targeted recommendations to enhance Australia's public sector AI security to align its National AI Plan with national security priorities:

1. Integrate National Security as a Core Pillar of the National AI Plan

Reorient national security as a central objective, moving beyond its current prioritisation of productivity and inclusion. This includes integrating defence, dual-use AI, and intelligence considerations into public sector governance; classifying high-risk public-sector AI; and centralised coordination to address fragmented deployment and supply chain vulnerabilities.

2. Integrate Sovereign AI Capability

Leverage Australia's Critical Minerals Strategic Reserve as a strategic tool to acquire reciprocal benefits with allied partners. Scale domestic computing infrastructure and reduce reliance on foreign technology providers to mitigate the risks of data exposure and external dependencies.

3. Strengthen Accountability, Governance, and Oversight

Mitigate public sector AI risks by enacting targeted AI legislation, enhancing scrutiny of AI-related infrastructure through investment and promoting responsible AI use in the public service through professional training, centralised guidance (e.g., expanding GovAI), and robust incident reporting.

4. Deepen Collaboration with Techno-Democratic Partners

Strengthen global AI supply chain resilience and security governance by aligning Australia's AI policies with allied frameworks to address shared vulnerabilities, in addition to expanding joint AI safety and R&D initiatives to shape global AI governance.

1: INTRODUCTION: DEFINING THE CONTEMPORARY TECHNOLOGICAL ENVIRONMENT

The global diffusion of AI and data-driven systems has instigated a paradigm shift in contemporary national security priorities, in which AI ecosystems, sovereign computing infrastructure, data governance, and secure technology supply intersect with the public sector. At the centre of this transformation, the US and China are leading AI superpowers. Collectively, these two nations engage 70% of the world's top machine learning researchers, control 90% of global computing power, and attract the overwhelming majority of global AI investment - a figure more than double the combined total of all other states. This concentration has reshaped geopolitical dynamics and national security, giving rise to the concept of techno-democratic power: a coalition of technologically advanced democratic nations acting in concert to secure reliable access to global supply chains of critical technology, while also championing open, rules-based innovation.

For middle powers like Australia, the global AI ecosystem presents both opportunities and strategic perils. Alignment with techno-democratic allies offers secure access to cutting-edge technology ecosystems, collaborative innovation, and industrial space. Contrastingly, the failure to expand integrated, system-level, and security-focused national AI plans leaves Australia's public sector vulnerable to a broad spectrum of AI-enabled threats, supply chain dependency, and cyber exploitation.

National security, as successive Australian Governments have underscored, is the "most important responsibility of government," which includes the protection of sovereign territory, democratic freedoms, institutions, and the safety of Australians. Against this backdrop, the following subsection outlines key definitions before examining comparative jurisdictional approaches and identifying gaps within Australia's current national AI policy framework.

1.1: KEY DEFINITIONS

Modern technological security can be conceptualised as an interconnected ecosystem comprising multiple mutually reinforcing strategic domains:

Artificial Intelligence (AI) — a diverse range of technologies that include 'self-learning, adaptive systems.' It also refers to a 'machine or computer system's ability to perform tasks' that usually require human intelligence.

AI Management Systems — a structured set of policies, controls, and processes to help organisations govern how AI systems are designed, developed, deployed and used.

Data Security — the practice of safeguarding digital information from unauthorised access, theft, or corruption throughout its lifecycle, across both digital and physical environments, ensuring secure efficient data use.

Technology — the application of scientific knowledge used for practical purposes encompasses tools, methods, and systems intended to improve efficiency and quality of life.

Quantum technologies — leverages the unique atomic-scale functions of particles to collect, process, and transmit information, offering innovation potential across sectors like healthcare, industry, and finance to address global challenges. Simultaneously, quantum technologies also pose digital security and privacy risks, such as threats to current cryptographic methods protecting transactions and communications.

2: COMPARATIVE JURISDICTIONAL ANALYSIS

2.1: THE UNITED STATES OF AMERICA (US)

The US does not have a single omnibus AI Act. Its current federal framework is Executive Order 14179, "Removing Barriers to American Leadership in Artificial Intelligence," together with "Winning the AI Race," America's AI Action Plan. Together, they treat AI leadership as economic and national-security policy, linking compute, energy, federal adoption, exports, and allied standards to US technological dominance.

National security is central to the US approach. Executive Order 14179 states that US AI dominance is meant to promote human flourishing, economic competitiveness and national security, while the Action Plan makes security one of its three pillars through "Leading in International Diplomacy and Security." A related export order treats the full US AI stack, including hardware, models, software, cybersecurity, applications, and standards, as a strategic asset to embed with allies and reduce dependence on adversary technology.

US national interests toward AI are frontier leadership, standard-setting, domestic compute, energy and semiconductor depth, and export of US-origin AI stacks to partners. OMB Memoranda M-25-21 and M-25-22 make public-sector adoption part of that project by pushing agencies to adopt and procure AI faster while retaining privacy, civil-rights, civil-liberties, and data safeguards.

Implementation is White House-led rather than statutory. Executive Order 14179 required an AI Action Plan within 180 days; the plan sets more than 90 federal actions; the OMB memoranda create agency adoption and procurement expectations; and NIST's TRAINS taskforce supports technical testing for national-security risks. This gives speed but makes continuity vulnerable to electoral cycles and administrative reversal.

Lesson for Australia: Australia should replicate the US's integration, not its deregulation — treat AI and compute as infrastructure; connect data centres, procurement, cyber resilience, standards, export controls, and alliance policy; and build secure procurement and testing for high-impact government AI. The practical lesson is central coordination and sovereign or trusted computing planning for welfare, health, migration, tax, security, and elections.

2.2: CANADA

Initially prioritising innovation and commercialisation, the focus of Canada's policies has shifted towards regulating safe and responsible AI use. An attempt to legislate AI use requirements was introduced through Bill C-27 in 2022. Discontinued in 2025, the aim to formally bind government organisations to responsible use guidelines has not yet been achieved, however its existence is indicative of Canada's ethical priorities. Commitment to these ideals is demonstrated by key frameworks such as the Directive on Automated Decision Making, Guide on Use of Generative AI, and AI Strategy for the Federal Public Service 2025-2027. Additionally, the Canadian AI Safety Institute is committed to advancing safeguards against AI risks at both a national and international level.

Canada primarily approaches security through safeguarding against public harm. The Directive on Automated Decision Making specifies frequent system testing to screen for bias. The Guide on Generative AI Use suggests ongoing review of produced content and privacy impact assessments. Based on public feedback, high-risk areas including criminal justice, employment, policy, and social services are excluded from AI input. The AI Strategy for Federal Public Service discusses risk management protocols including emergency shutdown systems. Canada's AI Safety Institute aims to align national risk management with global strategies, and has highlighted the need for sovereign infrastructure and data storage for Canada as a middle power to circumvent reliance on primarily US-based "Big Tech" companies. Underdeveloped secure data supply chains are a significant gap in Canada's security considerations.

Canadian AI policies operate around the core principles of being human-centred, internationally collaborative, and responsibly used. Priority areas include centralised implementation, up-to-date policies, increased training, and public engagement. Indicators of this commitment include the training of tools such as CANChat with secured data, as well as IRCC's AI policy disqualifying AI from application refusal. Sovereignty is also an identified interest through increased training for Canadian citizens and implementing independent centralised bodies, though this area lacks policy with direct focus.

Implementation tools include the Catalyst Grant program (financial support for research into risks associated with advanced AI systems), the mandatory Algorithmic Impact Assessment Tool for departments to evaluate risks of automated systems before official use, CANChat (a generative AI chatbot for public servants developed with confidential data input), Indigenous Perspectives in AI courses, the Standards Council of Canada, and the Canadian AI Safety Institute.

Lesson for Australia: Canada demonstrates methods to safeguard against internal risks associated with AI use, including public engagement and consideration of Indigenous data sovereignty, but remains heavily dependent on foreign infrastructure for data storage and supply chains. This is a warning to Australia that internal security considerations alone, without concurrent domestic infrastructure development, come at the cost of long-term independence from the commercial interests of foreign tech providers.

2.3: THE PEOPLE'S REPUBLIC OF CHINA

China's AI strategy is anchored in the 2017 New Generation Artificial Intelligence Development Plan (AIDP), which set the ambition for global AI leadership by 2030 and framed AI as central to economic transformation. Although not a top-down mandate, it served as a coordination tool for industry actors like Baidu and Alibaba. The 2025 Artificial Intelligence+ Action Plan expanded this vision, targeting 70% AI penetration across key sectors by 2027 and a fully AI-enabled economy by 2035. Adoption of a standalone comprehensive AI statute has been removed from recent legislative schedules, with the nation instead relying on pre-existing regulatory frameworks and targeted measures.

China's 2017 AIDP framed AI as essential to national competitiveness and security, calling for accelerated planning and systematic strategies to manage an increasingly complex security environment. The 2025 AI+ Action Plan significantly condenses this security language, reducing it to a single objective: "fostering a new pattern of multi-faceted and collaborative security governance," including applying AI to safety supervision, disaster prevention, and strengthening national-security capabilities. China clearly prioritises AI-enabled cyberspace governance, emphasising accurate information identification and real-time risk assessment.

China's national interest in AI frames it as a whole-of-state project linking technological capability to economic resilience, social governance, and global influence, with both plans presenting AI as a strategic asset for national security, long-term growth, and global rule-setting.

Implementation operates through a top-down, multi-layered system in which the central government sets direction, ministries translate strategy into regulation, and local governments compete to deploy AI through subsidised programs, backed by fiscal instruments including the ¥60 billion National AI Industry Investment Fund, government-guided funds, tax benefits, and AI pilot zones in cities such as Beijing, Shanghai, and Shenzhen. Regulation is led by the Cyberspace Administration of China, supported by national technical standards, mandatory registration for generative AI services, and the 2024 TC260 ethics framework enforcing technical requirements on data, models, risk management, and accountability.

Lesson for Australia: convert aspirational policy language into accountable, phased plans with annual reviews; develop sovereign, high-quality datasets in areas of national advantage; prioritise AI crisis planning and critical-infrastructure resilience; and favour competition-neutral incentives over selective support for state-directed champions.

2.4: THE REPUBLIC OF KOREA

In January 2025, South Korea enacted the world's second AI Framework Act, establishing the first comprehensive legal framework governing the safe use of AI. Effective January 2026, the AI Basic Act unifies 19 separate AI bills regarding the responsible development of AI. This legislation was followed by the National AI Plan 2026 to 2028, which outlined 12 strategic areas, 99 action items, and over 300 policy recommendations, with the primary objective of becoming one of the world's top 3 AI powers.

Article 4(2) of the AI Basic Act excludes AI developed and used solely for "national defence" and "national security" from its scope, and the Act does not include the term "cybersecurity" or address specific measures against cyberattacks. However, South Korea's AI approach is integrated, ensuring security considerations are embedded in every stage of the AI lifecycle even if not explicitly stated in the National Plan's core text. In May 2025, the National AI Security Consultative Group was established as a new interagency body complementary to the National AI Committee, and in June 2025 the government announced a $75 billion investment in sovereign AI development alongside a new AI presidential secretary.

South Korea's national interest is encapsulated in becoming "one of the top three AI powerhouses to become a Global Pivotal State," pursuing a "dual full-stack" strategy: domestic capability-building across all layers of the AI value chain, while aligning with the leading US AI ecosystem through the US-ROK Technology Prosperity Deal signed in October 2025.

Implementation runs through four National AI Flagship Projects (expanding national AI computing infrastructure, increasing private-sector AI investment, deploying AI across sectors, and ensuring AI safety and security through a dedicated AI Safety Institute) and four policy directions (fostering startups and talent, innovating technology and infrastructure, inclusiveness and fairness, and securing global leadership), coordinated by the National Artificial Intelligence Committee.

Lesson for Australia: enact dedicated AI legislation and establish inter-agency cooperation through a national AI committee; adopt a coherent, long-term national AI roadmap with measurable industry and public-sector adoption targets; and strengthen infrastructure and supply chain resilience by scaling national AI computing infrastructure and nurturing domestic AI talent.

2.5: AUSTRALIA

Australia has not enacted an omnibus AI Act or AI Bill. The formal frameworks are the Department of Industry, Science and Resources' National AI Plan and the AI Plan for the Australian Public Service, which position AI as productivity and public-service reform rather than a security-first project. National security enters through data centres, foreign investment, critical infrastructure, digital sovereignty, the Protective Security Policy Framework, and secure GovAI/GovAI Chat, not a dedicated public AI-security statute.

Security is present but peripheral. The National AI Plan aims to capture opportunity, spread benefits and keep Australians safe, while separating defence, intelligence and law-enforcement AI arrangements from the public plan. It therefore does not publicly map dual-use AI, AUKUS Pillar II integration, or which civilian services are security-critical.

Australia's interests are productivity, inclusion, trust and becoming a trusted Indo-Pacific AI and data-centre destination. It wants domestic capability, workforce skills, regional and SME inclusion, and foreign investment, but remains dependent on US-linked cloud, chips, and frontier models. The core tension is openness versus control.

Implementation is distributed and incentive-led. The APS AI Plan uses Trust, People and Tools pillars: agency Chief AI Officers, mandatory capability uplift, transparent reporting, GovAI/GovAI Chat, central guidance and high-risk review, but no binding economy-wide AI Act. The National AI Plan relies on existing law, standards, regulators, procurement, and the planned Australian AI Safety Institute.

3: THE AUSTRALIAN PUBLIC SECTOR AND AI: EMERGING ADOPTION AND SUBSEQUENT VULNERABILITIES

Australia's public service is at a critical juncture where AI's efficiency gains are real, but the governance scaffolding to deploy it safely is still being built and adopted across various government agencies. To address this issue, the Australian Government published a companion plan to the official National AI Plan, the "AI Plan for the Australian Public Service (APS)," in November 2025. Three mutually reinforcing pillars for adoption are identified: Trust (building confidence through transparency, ethical use, and strong governance); People (uplifting capability to support responsible use of AI, while remaining conscious of the effect change has on individuals and groups); and Tools (expanding access to fit-for-purpose AI technologies, with adequate security parameters).

Implementation of the plan over a 12-month period is shared by the Department of Finance, the Digital Transformation Agency, and the Australian Public Service Commission, while individual agencies remain accountable for their own AI adoption. As the Australian Border Force Commissioner Michael Outram noted in 2024, AI will augment, not replace, human judgment, accountability, and responsibility.

An inquiry conducted by the Joint Committee of Public Accounts and Audit identified risks including non-transparent decision-making, bias and discrimination, security and privacy vulnerabilities, legal and regulatory exposure, misinformation, manipulation, and unintended consequences. The Australian Signals Directorate has further categorised AI-related cyber risks into four groups: threats from AI, threats to AI, accidental or inadvertent threats, and threats via AI. Public awareness mirrors these institutional concerns: 77% of Australians view AI-related threats to people and businesses as major or moderate.

3.1: WORKFORCE CONCERNS

Australia has positioned the APS as a leader in responsible AI adoption, supported by the 2025 launch of GovAI, a centralised service offering hands-on training, curated guidance, cross-agency collaboration, and a secure sandbox for experimentation. Yet despite these efforts, uninformed or inconsistent AI use continues to disrupt implementation, as many APS employees first encountered generative AI outside of work in unconstrained personal settings, making the shift to authorised tools feel like a constraint on existing skills, creating governance and security risks.

AI adoption in the APS has not yet resulted in widespread displacement of entry-level or existing roles, though this stability is unlikely to persist as adoption matures. Data entry, transcription, record-keeping, communication, and clerical or office-support functions face the greatest exposure to AI-driven automation across jurisdictions.

3.2: WELFARE AND SOCIAL SERVICES ADMINISTRATION

Services Australia's long history of automation and AI has underscored the importance of stakeholder relationships with customers, staff, and strategic partners. Distrust is shaped heavily by the legacy of Robodebt (2016-2019), the Income Compliance Program that used an income-averaging algorithm to generate thousands of invalid debts for vulnerable groups. Although not an AI system, Robodebt remains a defining example of how automation can fail without adequate oversight.

More advanced automated decision-making systems now incorporate machine-learning models, increasing the risk of opaque, "black-box" outputs that are difficult to interpret without extensive human oversight, complicating accountability under traditional negligence frameworks. Within Services Australia, AI and automation are used for administrative decision-making, compliance, fraud detection, and service delivery, though some models, particularly for Centrelink fraud detection, have arguably not reached a level of maturity suitable for operational deployment.

Publicly accessible AI tools have dramatically lowered the barrier for malicious activity: deepfakes, face morphs, and AI-generated voice clones can now be produced with minimal skill, with a synthetic voice used in testing to access a Centrelink self-service account. As APS digital identity systems become increasingly interconnected, a breach in one agency could enable synthetic identity creation combining stolen personal data with fabricated documents and biometric identifiers.

3.3: TAXATION

The ATO is a prominent example of an agency integrating AI into both service delivery and internal operations, with earlier data indicating 43 ATO-built models in production and eight approved tools, though 74% lacked complete data-ethics assessments. These systems support tax assessment, compliance and fraud detection, and large-scale analysis of unstructured data.

Challenges remain around explainability, as some developing models lack documentation on how criteria are weighted, limiting the agency's ability to provide clear rationales for individuals seeking review of decisions. ATO leadership has emphasised the irreplaceable role of human judgement, guarding against "data hubris," and requires a human-in-the-loop for any high-impact decision, similar to approaches in Canada and South Korea. In parallel with welfare-related credential fabrication, the widespread availability of AI has enabled more sophisticated tax-fraud schemes, prompting the ATO to deploy AI-driven detection models via its Advanced Analytics Platform Cloud and centralised case-management system, "Centrl."

4: LEVERS AUSTRALIA HOLDS TO MITIGATE PUBLIC-SECTOR AI SECURITY RISKS

Australia continues to approach AI security through a series of parallel policy streams. Although AI adoption, critical minerals, data centres, cyber, trade, procurement and foreign investment are advancing, they have yet to be integrated into a coherent national security strategy.

4.1: TRADE AND ALLIANCE LEVERAGE

Australia's first major lever is upstream resource leverage. The Critical Minerals Strategic Reserve was created to maximise the strategic value of Australia's critical minerals for the economy and national security, backed by A$1 billion from the expanded A$5 billion Critical Minerals Facility. Its initial priority minerals include antimony, gallium and selected rare earths, all important inputs into semiconductors, magnets, defence systems and AI-adjacent technologies.

The gap lies in Australia's continued use of this position predominately to secure export relationships, rather than to leverage downstream strategic outcomes, despite an established alliance architecture (Five Eyes, AUKUS adjacency, Pax Silica, and critical-minerals partnerships with the US, Canada, South Korea, and Japan) that could link access to Australian inputs with stronger public-interest returns, such as guaranteed compute access during shortages or sovereign, ring-fenced government cloud hosted in Australia. Australia hosts more than 250 data centres and stands as the second-most-attractive destination for data-centre investment globally after the US, with generative-AI adoption and infrastructure estimated to add up to A$115 billion to the economy annually by 2030.

4.2: OWNERSHIP AND CONTROL

Australia's second major lever is control over ownership and operational influence in strategic assets. The Foreign Investment Review Board administers Australia's foreign investment review framework, under which the Treasurer assesses proposals against the national interest and national security. The new AI era extends this scrutiny beyond ports, grids or farmland to data centres, model-hosting capacity, and sensitive digital infrastructure, illustrated by Blackstone and CPP Investments' 2024 agreement to acquire AirTrunk at an implied enterprise value of more than A$24 billion.

Australia has already shown it is willing to act where critical minerals and national security intersect, having ordered foreign investors to dispose of shares in Northern Minerals in 2024 due to national security concerns, with the Federal Court imposing A$14 million in penalties in 2026 after breaches of those orders. The same logic can be adapted to AI-linked infrastructure through sovereign enclaves for public workloads, remote-access restrictions, local governance conditions, continuity undertakings, and stronger audit rights over systems used in welfare, migration, tax, health, and policing contexts.

4.3: DETERMINING WHERE SOVEREIGN AI CAPABILITIES ARE MOST CRITICAL

Australia's third lever is prioritisation. The National AI Plan is broad and politically serviceable, but does not identify which public-sector domains carry the greatest sovereign risk, nor where the Commonwealth will insist on stricter hosting, testing, auditability or fallback arrangements. Comparator jurisdictions are more explicit: Canada's Directive on Automated Decision-Making applies specifically to administrative systems that automate decisions affecting a person's legal rights, backed by its Algorithmic Impact Assessment tool; South Korea's AI Basic Act embeds a detailed governance architecture requiring an AI master plan and a national AI committee; and China's strategy has long been tied to named deployment areas such as urban governance, healthcare, transport, and city management.

For Australia, the practical implication is that sovereignty should be sequenced rather than universalised, with the most defensible first-order priorities being welfare and social-security systems, migration and border systems, tax and compliance systems, health triage and records tools, policing analytics, and electoral administration, the domains where opacity, vendor dependency or external disruption would do the most direct public harm. A targeted sequencing model would allow Australia to enforce stronger standards in those areas first: mandatory sovereign or trusted-allied hosting, stricter procurement and assurance, red-teaming, incident reporting, human review rights and clearer recourse for affected citizens.

Shaping the future of technology policy.

Subscribe and stay up-to-​date on Protocol’s latest news, upcoming events and opportunities.

Shaping the future of technology policy.

Subscribe and stay up-to-​date on Protocol’s latest news, upcoming events and opportunities.

Shaping the future of technology policy.

Subscribe and stay up-to-​date on Protocol’s latest news, upcoming events and opportunities.