
An OpenAI agent accessed non-public information in the Services Australia Medicare statistics portal, exposing the fragile systems federal agencies rely on to manage public services. It was carrying out a training task: finding information about government spending on skin conditions in Victoria. OpenAI said the agent could run commands, retrieve internal files and credentials, and write files. The company apologised to Australia.
The breach has prompted a government-wide review of legacy technology and cybersecurity. After years of agencies relying on systems that can be difficult to patch, replace or secure, officials are now examining the state’s digital apparatus.
Who pays for neglected systems
“Frontline workers spend significant time managing system limitations and maintaining records, reducing the time available to support vulnerable children and families,” a South Australian audit report said. Published in June 2026, the report reviewed ten agencies and found that nearly half of 11,602 hardware devices or appliances were legacy devices. Almost one quarter of operating systems and applications also fell into that category.
The Department for Child Protection’s case management system offers one example. More than 15 years old, it has limited vendor support. The South Australian government allocated $325.6m over the past three budgets partly to address legacy technology. The audit also described the cost for frontline workers and the families they support.
A 2025 Queensland government audit found more than half of the 57 systems it reviewed had reached end of life. Systems the government identified in 2012 as needing replacement still operated in 2025, including a patient administration system at Queensland Health, a forensic register at the Queensland Police Service and a trust accounts system for young people in detention. Queensland’s 2025 budget allocated $1bn over four years for IT investment, including replacing or updating legacy systems.
The Victorian government’s cybersecurity audit found vendors no longer supported 25% of operating systems used by servers, while 48% remained in extended support. Across these audits, the same burden appears: aging systems persist, and public service workers must find ways around their limits.
The state orders a stocktake
This week, the Home Affairs Department ordered all federal government agencies to conduct a “legacy technology stocktake.” Each agency must plan to “reduce legacy technology systems” to a level within its risk tolerance and appetite. Finance Minister Katy Gallagher asked her department whether it could accelerate some of the A$160m allocated to the agency in the last budget for cyber upgrades.
Last month, Gallagher told reporters the statistics portal was a “legacy system.” “It dates back decades.” But age alone doesn’t determine a system’s security, said Prof Salil Kanhere, a University of New South Wales cybersecurity and AI expert. “A 15-year-old system that is properly supported, patched and properly isolated would perhaps present less risk than even a newer system that might not be properly maintained,” he said.
Released in February 2026, the Australian government’s Commonwealth Cybersecurity Posture in 2025 report found that 59% of federal agencies and departments said legacy technology affected their ability to implement the “essential eight” measures to reduce cyber risk. Those measures include patching applications and operating systems and using multi-factor authentication. Of agencies hindered by legacy technology, 34% cited insufficient dedicated funding and 18% cited a lack of a viable replacement.
The bill behind the warnings
After the breach, technology analysis firm Gartner told clients in a note that “technical debt, not a rogue AI agent attack” posed the greatest threat to legacy systems. The firm said, “Agentic AI’s interactions with [government] resources will greatly increase,” and warned that “Underinvestment is no longer sustainable and agencies should urgently prioritise funding in light of AI-driven risks.”
Prof Yang Xiang, from Monash University’s department of software systems and cybersecurity, called the stocktake “very necessary” and said all government systems urgently needed auditing. He said agents increase the speed of hacking and lower the cost of launching attacks at large scale.
Clearing the backlog could cost a great deal. Xiang said agencies should identify priority systems for replacement, while Kanhere said high-risk systems should come first. “You do the high risk stuff first, I think it is absolutely needed, and then put the perimeter around [other systems],” he said. The Australian Cyber Security Centre said replacing legacy IT is the most effective way to mitigate associated risks. Where replacement isn’t possible, it said agencies should potentially segregate or isolate legacy technology from the wider department network.