The Australian Signals Directorate (ASD) and the AICD have collaborated on guidance for boards on the increasing cyber security threats posed by frontier artificial intelligence (AI). The guidance assists boards in asking the right questions of management about how the organisation is addressing this evolving threat.
What is frontier AI?
Recent advances in ‘frontier AI’ are transforming both offensive and defensive cyber capabilities, changing the speed, scale and sophistication of cyber threats facing all Australian organisations.
Frontier AI refers to the most advanced generation of AI models, characterised by sophisticated reasoning, coding and autonomous problem-solving capabilities that approach or exceed human performance in many complex tasks. These models use enormous computing resources and can perform a broad range of activities with limited human intervention.
Common examples include OpenAI's GPT models, Anthropic's Claude, Google's Gemini and xAI's Grok.
The threat posed by frontier AI
Frontier AI models have the capability to identify system and software vulnerabilities and rapidly weaponise them, including through combining multiple low severity vulnerabilities into high-impact compromises. Malicious cyber activities can be performed with little to no human oversight. This makes them a unique cyber security risk that Australian businesses need to be specifically prepared for.
The threat posed by frontier AI has been recognised by key regulators with both ASIC and APRA in May 2026 publishing resources warning about its implications. In June 2026 leaders of the Five Eyes cyber security agencies released a statement that:
“Frontier Al models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months.”
Against this background, it is critical that boards understand how their cyber security may be affected by the proliferation of frontier AI models.
As Australian organisations have learnt over the past five years, cyber resilience is vital to maintaining business continuity, reputation and investor confidence. Given the increasing threats to cyber security (like those posed by frontier AI), it should no longer be viewed as a technical issue delegated to internal and/or external teams. Instead, cyber security is a core business risk that requires leadership at the board level. As such, directors should be taking steps to understand whether the controls in place are up to date, proportionate and the organisation can respond in the case of a cyber security incident.
AICD ASD guidance – key messages
The guidance [Link when live] has a central message that frontier AI models currently, and increasingly in the future, will fundamentally transform both offensive and defensive cyber capabilities. While it is important that boards and organisation don’t panic, it is also critical to recognise this is a rapidly changing environment that has the potential to impact all Australian organisations, large and small.
Questions the board should be asking
Informed by the ASD’s considerable intelligence gathering and technical expertise, the resource details threshold questions boards should be asking of management to understand organisational resilience to frontier cyber threats.
Questions include:
- Have we reviewed our risk tolerance in light of frontier AI threats and is that risk tolerance still appropriate?
- If frontier AI models were used to identify and exploit weaknesses across our organisation, what areas of our business would be most exposed?
- What legacy technology risks are we carrying and do we have a plan to remediate these risks? Are we delaying addressing any legacy system weaknesses due to a perceived low exposure or severity?
In totality the questions are intended to start a conversation with management to assist a board understand in greater detail the organisation’s’ cyber resilience in to frontier AI threats, and what steps need to be taken to improve it.
Responding to frontier AI threats
In addition to the questions for management, the guidance sets out a list of actions to improve cyber resilience, which are categorised as immediate, short-term, medium-term or long-term priorities.
Immediate and short-term priorities include:
- Secure attack surfaces: Systems are securely configured to approved and maintained baselines, with configurations continually monitored and consistently enforced.
- Reduce software vulnerabilities: Vulnerabilities in systems are identified, documented, validated and prioritised for remediation or mitigation in a timely manner.
- Replace legacy systems: Systems that cannot meet cyber security requirements are managed using compensating controls, along with enhanced monitoring and assurance activities until they can be decommissioned or replaced.
- Reinforce identity, credential and access management: Robust and secure identity, credential and access management is used to establish, maintain and control access to systems.
Thes actions should be interpreted and implemented in a manner that reflects the organisation's particular business context.
The ASD and AICD recognise that for many boards, particularly SMEs and NFPs, it may not be possible to follow all the steps outlined in the guidance. Instead, boards should address risks arising from frontier AI in reference to the circumstances of their organisation, including reliance on the supply of software and systems by third parties.
Practical actions
Building on the list of priorities the guidance encourages boards to oversee practical actions within their organisation to assist in addressing frontier cyber threats. These actions include:
- Identifying known software and configuration weaknesses of assets through continuous and repeatable assessment activities, including vulnerability scanning activities.
- Applying security patches or updates within defined risk-based timeframes or, where operational impact is low, automatically.
The importance of rapid patching has been reiterated by ASIC and APRA and is an area where all organisations, including SMEs and NFPs, can readily take action.
Supply chain and geopolitical considerations
It is also worth stressing that risks presented by frontier AI models extend beyond their effect on cyber security operations. They are also relevant when considering digital supply chain risks. In particular, reliance on AI vendors and the foreign ownership, and the unique risks these may create now and in the future.
The guidance encourages a board to ask:
- Are we relying on vendors and service providers without sufficient governance and oversight, including an understanding of their foreign ownership, control or influence?
- Do we have visibility of the security and resilience posture of third and fourth-party suppliers within our cyber supply chain?
Digital supply chain vulnerabilities are increasingly drawing board attention and this extends to the AI models that have been adopted by many Australian organisations. The board has a key role in testing decision making on vendor choice and seeking to understand any strategic and sovereign risks associated with these vendors.
AICD ASD Guidance and further resources:
- The AICD ASD guidance is available here AICD ASD Board Guidance – Frontier AI Cyber Threats.
- The AICD has an extensive set of digital governance publications targeted at boards and directors, including A Director’s Guide to AI Governance, Data Governance Foundations for Boards and the Cyber Security Governance Principles.
- The ASD also provides a suite of AI-related publications.
Latest news
Already a member?
Login to view this content