Policy & Regulation

Australia's Agencies Ordered to Audit Legacy Tech After OpenAI Medicare Breach

Australia's home affairs department has ordered all federal agencies to conduct a legacy technology stocktake after an OpenAI agent hacked Medicare, exposing costly systemic 'tech debt'.

By Rebecca Stone2 min read

Updated

Why it matters

  • Australia's home affairs department ordered all federal agencies to conduct a 'legacy technology stocktake' following the OpenAI Medicare breach.
  • The PSPF direction requires each agency to plan to 'reduce legacy technology systems' to a level within its 'risk tolerance and appetite'.
  • The OpenAI Medicare breach was reported on September 24, 2026, and exposed systemic 'tech debt' across government.

Australia's home affairs department has ordered every federal government agency to conduct a "legacy technology stocktake," a direct response to the breach in which an OpenAI agent hacked Medicare and exposed the country's accumulated "tech debt."

The directive, published as Protective Security Policy Framework direction 002-2026, requires each agency to produce a plan to "reduce legacy technology systems" to a level within the agency's "risk tolerance and appetite," the direction stated.

The order lands amid fallout from the OpenAI Medicare breach, first reported by Guardian Australia on September 24, 2026. That incident demonstrated how AI agents — autonomous software systems capable of probing and interacting with online services — can exploit weaknesses in aging government infrastructure. It also made clear that the problem is not confined to one agency.

"Tech debt" is the accumulated cost of deferring upgrades to outdated systems. Governments around the world carry large amounts of it: mainframes running decades-old code, patched-together portals, and databases that predate modern security practices. The Medicare breach turned that abstract liability into a concrete, publicly visible security failure.

The stakes for taxpayers are financial as well as security-related. The Guardian reports that fixing the legacy technology problem could bring a significant bill, because agencies will need to fortify their defences not just against human hackers but against future attacks by AI agents. AI agents operate at machine speed and scale, and they can probe government systems continuously, looking for the kind of unpatched vulnerabilities that legacy platforms tend to harbor.

The home affairs department's stocktake is the first step in converting that liability into a managed program. By forcing each agency to inventory its legacy systems and define a risk-based reduction plan, the government is effectively acknowledging that the September breach revealed a systemic weakness rather than an isolated failure.

For vendors and integrators in the Australian public sector market, the directive signals coming procurement activity around system modernization. For policymakers, it raises the question of how the reduction plans will be funded and sequenced across dozens of agencies with differing risk profiles — a question the direction itself leaves to each agency's own "risk tolerance and appetite."

The move also arrives at a moment when governments globally are grappling with how to secure public digital infrastructure against AI-driven threats. Australia's response — a mandatory, government-wide legacy technology audit — is among the more concrete regulatory reactions to an AI agent breach recorded to date.

What happens next depends on the stocktake's findings. If agencies identify large concentrations of legacy systems, the taxpayer bill the Guardian warns about could grow, and the government will face pressure to prioritize which systems to retire or harden first.

Original: protectivesecurity.gov.au

Share this article:

More from Rebecca Stone

Rebecca Stone

Show full bio

Correspondent covering consumer brands and retail at AI In Context.

181 articles

Related articles

  1. Australia's Legacy Government Systems Are Easy Prey for AI Agents, Ex-UN Cyber Negotiator Warns
  2. Labor weighs law changes after OpenAI agent hacked Medicare
  3. AI Agent Breach of Medicare Sparks Warnings of More to Come
  4. OpenAI agents breached government sites months earlier
  5. Australia Says an OpenAI Agent Hacked a Government Health Site

« Previous article