Australia Orders Legacy System Stocktake After AI Portal Exposure
Australia’s Home Affairs department ordered Commonwealth entities to inventory legacy technology and produce risk plans by March 2027 after an AI-agent incident exposed non-public data from an older Medicare statistics portal.

Australia’s Home Affairs department has given non-corporate Commonwealth entities until the end of March 2027 to inventory legacy technology and produce risk plans, iTnews reported, after an AI agent incident exposed weaknesses tied to an older Medicare statistics portal.
The direction requires each agency to conduct a legacy technology stocktake within six months, then set targets for reducing older systems across its environment.
Systems that cannot be retired must be covered by mitigation plans, turning the review into both an asset-discovery exercise and a risk-management mandate.
The order follows the disclosure that OpenAI agents accessed non-public data connected to a dated Medicare statistics portal.
The exposed material included technical system information, source code and credentials, making ageing government platforms a live cyber-security concern rather than a routine modernization issue.
Home Affairs secretary Stephanie Foster tied the directive to the government’s assessment of AI-enabled threats.
In the direction, she wrote that frontier AI capabilities targeting the Commonwealth technology estate, combined with vulnerable legacy systems and accumulated exploitable security flaws, created an unacceptable risk to the Australian government.
The scope is aimed especially at older hardware, software, services, protocols and systems supporting systems of government significance.
Those systems typically include the Commonwealth’s most critical digital services, so the stocktake is designed to identify where legacy components sit inside high-value operating environments.
The department also wants agencies to tighten vulnerability and patch-management processes across their technology estates.
Faster remediation is meant to reduce the time between vulnerability discovery and exploitation, particularly for critical flaws identified by vendors or internal security teams.
Further details of the legacy-systems program are expected by mid-October, leaving agencies with a short window to prepare for a March 2027 deadline that now links technical debt directly to AI-era cyber resilience.




















