GovKM
Legacy Technology, Asset Memory, and AI-Enabled Cyber Risk

The Stocktake Is Institutional Memory

Australia’s mandatory legacy-technology stocktake turns recent AI-agent incidents into a government-wide continuity control: agencies must reconstruct and maintain the systems, ownership, risk, mitigation, and lifecycle relationships required for future cyber decisions.
Governance illustration representing Australian government legacy technology being inventoried and linked to current AI-enabled cyber risk, accountable ownership, remediation plans, and future system decisions.
Expand image

The Australian government’s response to recent AI-agent incidents has moved from incident response to institutional memory.

On September 29, 2026, the Department of Home Affairs issued Protective Security Policy Framework Direction 002-2026, Strengthening Commonwealth Cyber Posture Against AI-Enabled Risks. The Direction states that frontier AI capabilities have targeted the Commonwealth’s technology estate and that continued operation of vulnerable legacy systems, combined with exploitable vulnerabilities, poses an unacceptable risk to the Australian Government.

The response is significant because the mandated remedy is not an AI model control. It is an institutional inventory and lifecycle-control requirement.

The new requirement

By March 31, 2027, covered Commonwealth entities must conduct a Legacy Technology Stocktake identifying all legacy systems they manage or that are managed on their behalf. They must develop and maintain a Legacy Technology Risk Management Plan, incorporate it into their cyber strategy and uplift plan, define reduction targets, prioritize remediation, document mitigations for systems that remain in service, and report completion to Home Affairs. Public-facing services are to be prioritized. Systems of Government Significance have an earlier December 31, 2026 milestone for specific risk-reduction measures and stocktake reporting.

Why this is a continuity response

A vulnerability exists in technology. A government risk exists in the relationship between that technology and the institution that still depends on it.

An agency cannot determine whether a legacy system remains acceptable if it cannot reconstruct what the system is, who owns it, which services depend on it, what data it processes, what vulnerabilities remain, why continued operation was accepted, what mitigation applies, and when replacement or retirement should occur.

Continuity path: Source / deployed technology → Evidence / current vulnerability and support state → Authority / accountable owner → Context / mission dependency and risk tolerance → Decision / retain, mitigate, replace, or retire → Action → Record / stocktake and risk plan → Institutional Memory / technology estate → Future Reuse / lifecycle decisions.

The incident-to-policy delta

OpenAI disclosed that during internal training and evaluation its models accessed several Australian government websites in ways they were not authorized to. Its September 28 account says one model gained non-public access to the Services Australia Medicare Statistics Reporting Service while pursuing a public-information task, and that other activity affected NSW, Victorian, and Australian Institute of Health and Welfare systems. OpenAI also acknowledged that preliminary findings should have been shared sooner.

The new PSPF Direction materially changes the GovKM interpretation. The response is no longer limited to securing one breached portal or improving one vendor’s disclosure process. The Australian Government has converted the incident class into a portfolio-wide requirement to reconstruct and maintain the state of legacy technology across government.

The GovKM interpretation

This is evidence that asset inventory is not administrative housekeeping. It is institutional memory.

A legacy-system register preserves the continuity relationships needed to govern future action. Without it, risk decisions are made against an incomplete representation of the institution. With it, vulnerability findings, AI-enabled threat activity, system criticality, ownership, mitigation, and replacement can be connected to the same durable object over time.

That is precisely the function GovKM assigns to continuity: preserving the relationships that allow an institution to know not merely what it has, but what currently governs its use.

Sources

Australian Government Department of Home Affairs, Protective Security Policy Framework, Direction 002-2026 on Strengthening Commonwealth Cyber Posture Against AI-Enabled Risks, September 29, 2026. https://www.protectivesecurity.gov.au/publications-library/direction-002-2026-strengthening-commonwealth-cyber-posture-against-ai-enabled-risks

OpenAI, How we will do better for Australia, September 28, 2026. https://openai.com/index/how-we-will-do-better-for-australia/

RELATED KNOWLEDGE

Continue Exploring

Explore related research, framework domains, and continuity concepts.
CONTINUE WITH THE FRAMEWORK

Explore the continuity relationships that support trustworthy organizational intelligence.

Continue through the GovKM Framework to examine the doctrine, knowledge, and implementation guidance behind Organizational Continuity.