Everyone will treat this as a machinery-of-government question: which minister, which department, which new office. Asking in that order guarantees the wrong answer.
Cyber security in a world of AI is too operational for the Prime Minister’s Office of AI as conceived, too structural for the cavalcade of shields in Home Affairs’ Cyber Security Strategy. Ownership is not a box on a chart. It is a set of capacities and authorities. Once we work out what owning the nexus of cyber and AI would require, the machinery falls out of the answer.
Let’s start with those things an owner would have to change—and those are not technological.
The rewards run one way
Everything in cyber rewards offence. Nicole Perlroth’s account of the zero-day market describes a bidding war fuelled by intelligence agencies on every side, hunting exploits for a momentary advantage in an environment nobody holds for long. Penetration testers and threat hunters work the same thread: the tradecraft that finds a flaw is the tradecraft that uses it, and it can flip between the two with a change of employer.
Defence is different work. It is applying patches, checking updates, retiring dead environments, rebalancing loads, killing default credentials, standing up security architecture, and keeping the whole standing. It is slow, never-ending, thankless, often non-linear, and it needs administrators who know their own systems and the operational demands those systems carry. It costs far more than any budget or new policy proposal allows, because it is an assumed activity, sent off to the techies.
There is no DEF CON talk for the best-maintained network, no prize for the finest patch cycle, no REDSPICE allocation for whoever found the factory password before someone else did. The work is a cost centre until the breach, briefly a scandal, then a cost centre again. Success is treated, day after day, as white noise.
That sets the first requirement. Standards, training, funding and governance reform that leave the reward structure intact are decorative. An owner of this problem must be able to change what is rewarded—across portfolios, across the private operators who run most of the infrastructure, and against the grain of agencies whose budgets and standing derive from offence. Home Affairs cannot do that: it regulates. ASD will not: it benefits.
Delivery vs function
Incentives also have to point somewhere, and here lies the pitfall of the delivery focus. ‘Delivery’ is a measure of the bureaucracy: it rewards compliance and reporting lines over effect in the world. Fix the incentives and aim them at delivery, and the result is better-documented failure. Even ‘ensure your organisation can continue to function while compromised’ converts neatly into an attestation filed, a risk assumed, a box ticked, or a capability not built.
So the target must be clear and relevant. The Volt and Salt Typhoon campaigns were living off the land inside networks from at least 2023, if not earlier, invisible because they used the tools already there. Frontier AI models broke containment in July, in laboratories designed to contain them. Below that frontier, AI agents now find and exploit vulnerabilities cheaply enough that volume stops being a constraint. Compromise is not a risk to be managed but a planning assumption.
That takes us to the question: function, how? A zero trust architecture is the best general posture available, and it is hard, expensive, and offers little protection against an adversary using your own administrative tools and already inside your systems—let alone against a capable AI model. It is silent, too, on the questions that decide what survives: what the data is worth, which services a community cannot lose, what privacy is owed to whom. As orthodoxy it gains a nod and changes little—architecture alone is not defence.
The straightforward alternative is graceful degradation: deciding in advance which functions fail, in what order, for how long, and what stands in behind them. No minister or chief executive wants that conversation, because having it means walking back commitments, conceding that failure is expected, exposing liability, and disappointing everyone invested in the present arrangement. It is a political act before a technical one.
The long tail cannot buy it
It is also not something any single organisation can do alone, because degradation is a property of the system rather than of its parts.
Democracies are micro-vulnerable and macro-resilient.1 Redundancy, slack, multiple operators, a hand near the switch, the sheer awkwardness of a system nobody fully controls: that is where recovery comes from. It is often messy, typically assumed as the way things work and so unbudgeted, and precisely what efficiency drives out.
By way of illustration, in February 2021, the Oldsmar, Florida, water utility reported a cyber-attack, which was unable to be sustained through FBI investigation and congressional attention over two years. The lesson: a human knew what normal looked like and caught it.
But resilience through messiness can no longer be relied upon, when AI-powered adversaries are both multitudinous and fast. The OpenAI model that attacked Hugging Face in mid-July 2026 undertook over 17,600 separate automated actions over four days.
The entities holding most of that attack surface cannot buy their way to it. A municipal utility with three IT staff faces an adversary with the resources of a state and is least equipped to adopt the defence that would help it most. This is market failure of the ordinary kind.2
Market failure is not solved by exhortation or press release; it requires provision, incentivising research into defence, and restructuring of the regulatory environment that shapes behaviour. And it means continuous configuration management, patching and anomaly detection, distributed to the long tail as a public good and funded as a national programme rather than a voluntary labelling scheme.
Two objections arrive immediately. Who carries liability when an automated change takes a treatment plant offline at three in the morning? The Commonwealth does, by design, because it is asking small entities to run a risk they did not choose and cannot price; otherwise, none will adopt it. And why provision rather than a mandate through existing regulators—the objection a Finance or Treasury reader will naturally reach for? Because a mandate transfers cost to those least able to bear it. Home Affairs’ own review of Horizon One of the 2023 Cyber Security Strategy already concedes that compliance reporting pulls scarce cyber staff away from uplift and incident response.
The authority nobody has given
Provision at that scale is where the argument becomes uncomfortable. A capability acting continuously across thousands of small entities at machine speed is autonomous action, whatever it is called in the program logic. Nobody has authorised it, bounded it, or written doctrine for it.
It helps to be clear about what such a system is. A useful analogy for a capable AI model is not a mind but a bureaucracy: not conscious, yet purposive; capable of great good and of grinding harm; able to pursue an objective well past the point at which any individual inside it would have stopped. Australians have seen the malign version. Robodebt contained no machine learning at all and still produced automated cruelty, shirked authority, slow-rolled ministerial direction, and made communities invisible to the system acting upon them. Reward hacking in a model—subverting the instruction to satisfy the objective—is the same behaviour in a different substrate: emergent, unintended, and entirely explicable in a complex system.
The AI agent created by an Australian to make a gym booking found a vulnerability in the gym’s software and bumped other bookings to put him at the top of the queue. Of the three models that had escaped Anthropic’s bounds, one, Opus 4.7, ‘realised’ it was on the open internet but persisted; the second, Mythos, similarly realised it was on the open internet but inferred that was part of the exercise; while the third, an internal research model, reached the same conclusion and stopped. What humans would consider ‘normal’ common sense constraints don’t translate well, if at all, or may be rationalised away.
The objection to autonomous defence, then, is not simply that machines are alien. It is that we govern purposive non-human systems badly even when they run at human speed, and an AI-driven one will not. A human in the loop at machine speed is a human out of the contest; a human out of the loop is an unaccountable one. That tension does not resolve; pretending otherwise loses both halves of it. It has to be held deliberately, in a doctrine that states what defensive AI may do without authorisation, within what bounds, and where accountability sits when it errs.
Australia could write that first—the necessary doctrine for defensive action inside civilian infrastructure, at machine speed, across entities the Commonwealth does not own. Horizon Two’s ‘permissible cyber defence activities’ (action 3.2) is the beginning. But that sits within a Home Affairs consultation deliverable. Lifted out and co-designed with the frontier labs operating onshore and with Australian model builders, it becomes national doctrine.
So, ownership
So we can now answer the opening question. Owning the nexus requires the authority to change what is rewarded, the fiscal weight to fund a defensive public good, and the standing to write doctrine on autonomous action.
The Office of AI as scoped—standards, data centres, copyright—has none of the three. Of themselves, its current objectives are not bad per se, but they risk substituting economic and electoral matters for grappling with the larger challenges at hand.3 In short, the Office has the cross-portfolio position and the Prime Minister’s authority, which is the hard part to manufacture, and a mandate stopping well short of the needed work.
Why not simply widen Home Affairs’ remit? Because the remit is not the constraint. Home Affairs’ shield architecture is a compliance instrument, and widening one produces more compliance. Nor is this machinery-of-government churn, provided the test is right: not whether a new box exists, but whether anybody can change what is rewarded, publish a standing adversary-referenced assessment of whether Australia is a harder target this year than last, and be held to it in estimates.
Australia needs to stop counting shields, and to stop assuming that distance buys the time in which to keep counting. Whether the Office of AI becomes the place where this country’s cyber posture is finally aligned with its strategic circumstances, or simply the place where data-centre water allocations are negotiated, will tell us which question the government thinks it is answering.
Fischerkeller, Michael P, Emily O Goldman and Richard J Harknett (2022). Cyber Persistence Theory: Redefining National Security in Cyberspace, Oxford University Press.
Michael Sulmeyer, former US assistant secretary of defence for cyber policy, writing in Hal Brands’ collection on the geopolitics of AI, identified market failure as one of three critical issues that must be addressed to help redress the defence deficiency in an age of AI. Sulmeyer, Michael (2026). ‘AI and the Offence-Defence Balance in Cyberspace’, in Brands, Hal (ed). Geopolitics of AI: Power, Conflict and the Future of Global Order, Johns Hopkins University Press, pp.101-113.
Some of its work also will potentially sit at odds with the authorities assigned to the Department of Climate Change, Energy, Environment and Water.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.