The Australian Signals Directorate and the Australian Institute of Company Directors have jointly published guidance directed at boards of directors, warning that frontier AI models are fundamentally transforming the cyber threat landscape in ways that may rapidly invalidate existing organisational risk tolerances. Frontier AI models are described as capable of performing complex offensive tasks that exceed what conventional automated tools can achieve.
The guidance identifies three specific threat capabilities of particular concern:
- the ability to identify vulnerabilities and rapidly weaponise them,
- the ability to chain together multiple low-severity weaknesses into high-impact compromises,
- and the ability to conduct malicious cyber activity with little or no human oversight.
The document also flags that frontier AI is dramatically lowering the skill and knowledge barrier for malicious actors, with threat actors who previously lacked technical capability now able to access and leverage advanced offensive tools, including through exploitation of guardrail weaknesses in proprietary AI models and illegal distillation of those models.
The guidance frames cyber oversight as a board-level governance responsibility rather than a purely technical matter, and presents a series of threshold questions boards should be directing to management. These include asking what assumptions underpin current risk assessments and whether those assumptions remain valid under frontier AI threat conditions, where minor system weaknesses could be chained into major incidents at machine speed, whether the organisation has sufficient visibility of third and fourth-party suppliers within its cyber supply chain, whether incident response times remain adequate if attacks compress from days to hours, and whether legacy technology risks are being deprioritised on the basis of a perceived low exposure that frontier AI may no longer support. The guidance explicitly calls out foreign ownership, control, and influence risks associated with reliance on particular AI vendors as an additional dimension boards should be considering.
The strategic recommendations are structured across four time horizons. Immediate priorities centre on securing attack surfaces through approved configuration baselines and reducing software vulnerabilities through timely patching and verified remediation.
Short-term priorities cover replacing legacy systems with compensating controls in the interim, reinforcing identity and access management including phishing-resistant multi-factor authentication, restricting privileges to the minimum required for both human users and AI agents, and ensuring incident response and business continuity plans have been updated and tested against frontier AI threat scenarios.
A medium-term priority calls for deploying AI for defensive purposes in a secure, human-supervised, and accountable manner, covering applications such as vulnerability identification in software development, vulnerability scanning, and security event triage.
The longer-term horizon focuses on modernising systems according to Secure by Design and Secure by Default principles across their full lifecycle.
The document concludes with an unambiguous warning that organisations which fail to act now leave themselves exposed to current and emerging frontier AI threats, and that boards should be pressing management to support targeted investments in cyber security and resilience without delay.