Skip to content

National Security

Purpose: Preserve Australian judgement, accountability and security capability as advanced AI changes the threat environment
Audience: Defence, intelligence, national-security, critical-infrastructure and senior policy leaders | Time: 20–25 minutes

Advanced AI systems could change the speed, scale and accessibility of cyber operations, influence campaigns, intelligence analysis and military decision support. If systems approaching AGI emerge, the pressure on institutions, alliances and crisis decision-making could become more acute. These possibilities are uncertain, but consequential enough to prepare for.

This guidance complements the Government and Public Institutions guidance. It does not replace current Defence, intelligence, cyber-security or legal frameworks.

The challenge is dependence under pressure

Australia will use advanced AI in a strategic environment it does not control. Many frontier capabilities, compute services and integrated defence systems will be developed offshore or supplied through commercial and allied relationships. Access may be valuable without being assured; performance in ordinary conditions may not predict behaviour under deception, disruption or crisis.

Security institutions therefore face advanced AI in three roles:

  1. As potential targets of AI-enabled cyber activity, interference, espionage and coercion.
  2. As users of AI for analysis, logistics, cyber defence, intelligence and operational decision support.
  3. As strategic actors whose acquisition, deployment and diplomatic choices may affect escalation, norms and allied behaviour.

The central risk is lost judgement

Speed is useful only while leaders can understand the basis of a recommendation, recognise manipulation, intervene and remain accountable. A faster decision process that obscures uncertainty or compresses human deliberation can weaken security rather than strengthen it.

For this audience, Resilience and Governance carry the most weight. Australia needs security functions that continue when AI is unavailable or untrusted and clear authority over where it may be used. Containment matters mainly through protection of sensitive systems and cooperation with allies. Alignment becomes concrete in the systems Australia acquires and operates: reliable behaviour, meaningful human control and evaluation under adversarial conditions.

Five decisions for security leaders

1. Where must human judgement remain decisive?

Identify decisions where an AI-generated recommendation cannot become action without an accountable human assessment. Start with uses that could cause loss of life, unlawful harm, strategic escalation, coercive state action or a serious intelligence failure.

The design question is not whether a person appears somewhere in the workflow. It is whether that person has enough time, information, authority and technical understanding to challenge the system. Defence's March 2026 policy settings preserve individual accountability for AI-enabled decisions and outcomes, require compliance with domestic and international law and call for proportionate controls.

2. Which dependencies could limit Australian freedom of action?

Map the models, cloud services, chips, data pipelines, licences, updates and overseas support arrangements behind critical AI-enabled functions. Ask what happens if access is restricted, a vendor changes a model without notice, an ally's priorities diverge or a service becomes unreliable during a regional crisis.

Strategic autonomy does not require Australia to build every component. It does require clarity about which functions need sovereign access, independent evaluation, assured supply, local operating expertise or a non-AI fallback.

3. Can systems withstand an intelligent adversary?

Testing for accuracy on historical data is not enough. Security systems should be exercised against deception, poisoned or incomplete data, prompt injection, compromised integrations, insider threats, distribution shift and coordinated attack. Evaluators need permission to challenge operational assumptions, not only confirm technical requirements.

Procurement should preserve access to the evidence required for independent assurance: system limitations, known failure modes, change history, incident reporting and the results of adversarial evaluation.

4. Could the system make a crisis less stable?

Advanced AI may create pressure to decide faster, conceal capabilities, automate warning and response or infer an adversary's intent from uncertain signals. These dynamics can increase miscalculation even when no actor intends escalation.

Before deployment, examine how an AI-enabled capability changes the other side's incentives and perceptions. Retain deliberate pauses, reliable communication channels and escalation controls where speed itself creates risk. Use exercises to test how leaders respond when several AI-supported assessments conflict.

5. Can the mission continue without trusted AI?

Continuity plans should cover more than a technical outage. A system may remain online while its data, recommendations or supply chain can no longer be trusted. Define how essential functions degrade safely, who can suspend use, what alternative sources are available and how operators retain the skills needed to work without AI assistance.

The Australian Signals Directorate's 2024–25 cyber threat report notes that AI can help malicious actors operate at greater scale and speed. It also calls for stronger national cyber resilience. For advanced-AI planning, that means exercising simultaneous failure across connected organisations rather than treating each system as an isolated asset.

AI competition is not one race

Colin Kahl and Jim Mitre describe international AI competition as a pentathlon involving frontier innovation, national-security integration, economy-wide adoption, leadership across the technology stack and avoiding a race to the bottom on safety.

For Australia, the point is not to imitate the scale of the United States or China. It is to choose where Australian capability and influence are indispensable:

  • integrate AI without surrendering accountable command;
  • preserve independent technical and intelligence assessment;
  • secure the infrastructure and expertise needed for continuity;
  • shape allied practice and international norms; and
  • avoid trading durable security for short-term adoption speed.

Threats to exercise, not merely monitor

The formal scenarios most relevant to this audience are Critical Infrastructure, Information Ecosystems, Catastrophic Misuse and Loss of Control. The exercises below translate those planning scenarios into national-security questions; they are not forecasts or operational doctrine.

AI can help malicious actors automate analysis, improve deception and operate at greater scale. Exercise attacks that combine technical compromise with convincing synthetic communications, stolen identities and pressure on operational staff.

Test whether critical functions can isolate affected systems, rebuild trusted environments and coordinate with ASD's Australian Cyber Security Centre while services remain disrupted.

Synthetic media and personalised influence can exploit a crisis faster than institutions can verify and respond. The deeper risk is not one convincing fake, but widespread uncertainty about whether any evidence can be trusted.

Exercise rapid authentication, public communication and correction across government, media and community partners. Measure whether the response preserves trust rather than amplifying the manipulation.

AI-supported warning, targeting or decision systems may shorten decision time and conceal how conclusions were reached. Exercise ambiguous alerts, conflicting model outputs and adversarial attempts to trigger overreaction.

Record where commanders need additional evidence, a deliberate pause or direct human-to-human communication before acting.

AI can help analysts process large volumes of material, but confident synthesis can hide missing evidence, bias or adversarial contamination. Exercise cases where the system's recommendation is plausible and wrong.

Require traceable sourcing, competing assessments and clear communication of uncertainty. Maintain analysts' ability to work from primary material when automated tools are unavailable.

Questions for your next planning discussion

Use these prompts to explore strategic dependencies

  • Which decisions or missions depend on human judgement remaining decisive and what makes that judgement meaningful?

  • What evidence would be needed before relying on an AI-enabled system in a high-consequence function?

  • Where do offshore providers, compute, data or specialist expertise create dependencies that may be difficult to change?

  • Could a critical function continue if an AI service remained available but could not be trusted?

  • Do operational leaders, civilian partners and oversight bodies receive enough usable information to test legality, necessity and accountability?

Connect security and civilian preparedness

The boundary between national security and civilian systems is porous. Critical infrastructure is privately and publicly operated. Information platforms shape both community trust and foreign-interference risk. Commercial models may enter government through procurement before their security implications are fully understood.

Coordination should therefore work in both directions. Security agencies can share usable threat information without exposing sources and methods; civilian regulators, researchers and organisations can report incidents, dependencies and system failures that have strategic significance. Classified activity still requires democratic accountability through appropriate parliamentary, inspector-general and internal mechanisms.

Use the Business and Communities guidance to extend preparedness beyond government. Use the advanced-AI scenarios to test cross-sector decisions rather than predict a particular future.

Current policy and operational guidance

Sources and further reading