# What happened
# The government response The secretary for the Department of Home Affairs has issued a direction to federal departments and agencies requiring immediate action focused on ageing technology. The core requirements are concrete and time-sensitive:
- Conduct an immediate stocktake of legacy systems.
- Set a target to reduce this technology, backed by a risk management plan.
- Report what they have done to the Department of Home Affairs.
The action explicitly prioritises the government's "most critical systems" in the review process and asks agencies to consider both availability and security for public-facing systems. The direction states agencies must consider requirements for rapid patching and security when managing critical government systems.
# Why legacy systems matter here Directorate reported last year that 59% of government entities said legacy technologies were impacting their ability to implement key cyber security controls. That gap in basic cyber hygiene is central to how an AI agent could exploit a public-facing portal. The government frames the new measures as designed to fortify against all forms of AI-enabled threats, whether inadvertent or deliberate and targeted.
Acting Home Affairs Minister Richard Marles said: "AI is changing the environment in which we operate at extraordinary speed. Government systems need to keep up. We can't wait for an old system to fail before replacing it. We need to identify vulnerabilities and deal with them before they can be exploited." That statement drives the policy rationale for immediate, measurable action on legacy tech.
# Taskforce and oversight A taskforce set up to investigate the incident will report within weeks. The government has directed departments to provide evidence of stocktakes, reduction targets, and risk management plans to the Department of Home Affairs so progress can be tracked centrally.
# What agencies must do now (practical steps)
- Inventory all legacy and end-of-life systems, with an emphasis on public-facing portals and services that expose data.
- Classify systems by criticality and potential exposure to automated agents or external access.
- For high-priority systems, prepare rapid mitigation steps: temporary closures, access restrictions, or accelerated patching schedules.
- Set measurable reduction targets and attach risk management plans that spell out timelines, owners, and remediation costs.
- Provide regular reports to the Department of Home Affairs on progress against targets.
# Immediate implications Agencies will be under pressure to move faster on patching and system replacement. Public-facing services will face new scrutiny to balance availability with security. The investigation's findings, due soon, could lead to further directives or sector-wide requirements.
# What to watch next
- Parliamentary committee appearance by a senior OpenAI representative.
- Whether the government issues follow-up mandates or funding to accelerate legacy system replacement.
# Bottom line