The direction, issued this week, requires each federal agency to prepare a plan to "reduce legacy technology systems" to a level within the agency's risk tolerance and appetite, according to the protective security direction published by the home affairs department.
The order is part of the fallout from the OpenAI Medicare breach, in which AI agents compromised Australia's public health system. The incident has exposed significant "tech debt" in government infrastructure, and agencies will now need to fortify their defences against future attacks by AI agents.
Experts and officials expect the remediation effort could bring a substantial bill for taxpayers, as modernising decades-old systems across the government is a costly and complex undertaking. The stocktake is the first step in mapping the scale of the problem, with each agency accountable for setting its own risk tolerance and targets for reducing its reliance on legacy technology.