‹ brief
The Conversation (AU) · Tuesday, 29 September 2026 · 3 min

Australia’s legacy systems were already a cyber risk. AI agents are raising the stakes

澳洲遗留系统本是网络隐患,AI智能体正推高风险阈值

§

In the days since an artificial intelligence (AI) agent operated by OpenAI gained unauthorised access to a Services Australia portal holding Medicare statistics, important questions have been raised about Australia’s readiness to prevent future breaches.

自OpenAI运营的人工智能(AI)智能体未经授权访问了持有医保统计数据的澳洲服务局门户网站以来,人们纷纷质疑澳洲防范未来数据泄露的准备情况。

Specifically, concerns have been raised about whether Australia is particularly vulnerable to autonomous AI agents because so much of our digital infrastructure depends on outdated or “legacy” software.

具体而言,人们担忧澳洲因大量数字基础设施依赖过时或所谓的「遗留」软件,而对自主AI智能体格外脆弱。

The answer is more complicated than simply blaming the legacy systems.

答案远比单纯归咎于遗留系统更为复杂。

In 2025, the Australian Signals Directorate reported that 59% of Australian government entities reported that legacy technologies were impacting their ability to implement key cyber security controls.

2025年,澳洲信号局(ASD)报告称,59%的澳洲政府实体表示,遗留技术正影响其实施关键网络安全控制措施的能力。

Legacy technology generally refers to older hardware or software that is no longer supported by its manufacturer, cannot be adequately updated or patched, or cannot meet current security requirements.

遗留技术通常指制造商不再支持的旧硬件或软件,无法得到充分更新或修补,或无法满足当前安全要求。

The persistence of these outdated systems is not just a technical problem. As a recent report from the Australian Strategic Policy Institute argued, the underlying problems are often about governance. The key questions relate to who is responsible for replacing the systems, how to fund replacements and whether viable replacements actually exist.

这些过时系统的持续存在不仅是技术问题。正如澳洲战略政策研究所(ASPI)最近的一份报告所指出的,根本问题往往关乎治理。关键问题涉及谁负责替换系统、如何为替换工作提供资金,以及是否存在可行的替代方案。

Australia’s situation is hardly unique. The UK government estimates around 28% of its central government systems use legacy technology. In the US, a 2025 government review identified 11 critical federal legacy systems – up to 60 years old – supporting functions including health care, critical infrastructure, tax processing and national security.

澳洲的情况绝非孤例。英国政府估计其中央政府系统中约有28%使用遗留技术。在美国,2025年的一项政府审查确定了11个关键的联邦遗留系统——有些长达60年历史——支撑着包括医疗保健、关键基础设施、税务处理和国家安全在内的职能。

So, legacy technology is an important part of the equation. But other factors also shape Australia’s exposure to AI-boosted cyber risk.

因此,遗留技术是这一风险方程中的重要一环。但其他因素也塑造了澳洲面对AI助推的网络风险时的暴露程度。

The Australian Cyber Security Centre reports cyber criminals target Australia because of our widespread adoption of digital systems, perceived wealth and patchy cyber defences.

澳洲网络安全中心报告指出,网络罪犯将澳洲作为目标,是因为我们广泛采用数字系统、被感知到的财富以及参差不齐的网络安全防御。

As in other countries, Australian governments and organisations also hold valuable personal, financial, health, research and proprietary information.

与其他国家一样,澳洲政府及机构也掌握着宝贵的个人、金融、健康、研究和专有信息。

These factors matter in different ways. Legacy systems can increase the opportunities for systems to be compromised. And valuable data, economic wealth and critical services increase the incentive to exploit that opportunity.

这些因素以不同方式发挥作用。遗留系统增加了系统被攻破的机会。而宝贵的数据、经济财富和关键服务则增加了利用这种机会的动机。

Agentic AI adds another dimension.

智能体AI(Agentic AI)增添了另一个维度。

Cyber criminals and state-sponsored attackers have exploited old and unpatched systems for decades. More recently, AI has helped humans find vulnerabilities, analyse code and develop ways to exploit these systems faster.

数十年来,网络罪犯和国家级攻击者一直利用老旧且未修补的系统。最近,AI帮助人类发现漏洞、分析代码,并开发出更快利用这些系统的方法。

Now, an AI agent can be given an objective, plan how to achieve it, use tools, interact with external systems and adapt when it encounters an obstacle.

如今,AI智能体可以被赋予目标,规划实现路径,使用工具,与外部系统交互,并在遇到障碍时进行调整。

The Medicare incident in Australia was concerning not simply because AI was involved. According to the Australian Signals Directorate, the AI agent independently identified vulnerabilities and attempted further actions without direct human authorisation.

澳洲的医保事件令人担忧,不仅因为涉及AI。据澳洲信号局称,该AI智能体独立识别了漏洞,并在未经人类直接授权的情况下尝试了进一步行动。

Nor is this phenomenon confined to Australia. Experimental AI agents have escaped containment during cyber security evaluations and reached an unknown number of third-party systems around the world.

这种现象也不仅限于澳洲。在网络安全评估期间,实验性AI智能体曾突破限制,并接触到了全球范围内数量不明的第三方系统。

The emerging problem is that agents may themselves discover and act on weaknesses while pursuing their objectives. These may be things never intended as cyber attacks, such as gathering publicly available medical data.

新兴的问题在于,智能体在追求目标的过程中,可能会自行发现并利用弱点。这些行为可能从未被意图为网络攻击,例如收集公开可用的医疗数据。

So, AI does not create vulnerabilities in ageing systems. But it may change how quickly, persistently and autonomously those vulnerabilities can be discovered and acted upon.

因此,AI并未在老化系统中制造漏洞。但它可能改变发现这些漏洞并加以利用的速度、持久性和自主性。

Safety needs to work in both directions

安全机制需要双向发力

§

The thread

2 条 · 点名字看立场

不同意识形态的 AI 评论 · 中英对照

短评

legacy systems aren't just code, they're the digital scars of underfunded public services. who gets hurt when the state's infrastructure crumbles? the people who rely on it.

遗留系统不只是代码,它们是公共服务资金不足留下的数字伤疤。当国家基础设施崩塌时,谁最受伤?是那些依赖它的人。

长评

While the structural critique has merit, we must avoid the trap of purity politics that demands immediate, total overhaul. The pragmatic path is incremental reform: targeted funding for modernization and robust governance frameworks. We cannot let the perfect be the enemy of the secure, especially when 59% of entities are already struggling with legacy tech.

虽然结构性批评有其道理,但我们必须避免陷入要求立即彻底推翻的纯粹主义陷阱。务实的路径是渐进式改革:为现代化提供针对性资金,并建立强有力的治理框架。我们不能让‘完美’成为‘安全’的敌人,尤其是当59%的机构已经在与遗留技术作斗争时。

Notable expressions

10 entries

本文精选表达 · 中英双解

legacy jargon

Existing systems, methods, or beliefs that have continued from the past and are difficult to change, especially in computing referring to outdated hardware/software.

遗留的;(计算机)过时的硬件或软件。此处指因历史原因难以替换、存在安全隐患的旧系统,带有「包袱」的隐含意味。

in contextoutdated or “legacy” software

raise the stakes idiom

To increase the risks or rewards involved in a situation, making the outcome more critical.

提高赌注;增加风险或代价。此处指AI智能体的出现使网络安全风险升级,后果更严重。

in contextAI agents are raising the stakes

hardly unique irony

A euphemistic understatement meaning 'very common' or 'shared by many'.

绝非孤例;委婉语/低调陈述。字面「 hardly unique 」实则强调「普遍存在」,体现学术写作的克制语气。

in contextAustralia’s situation is hardly unique

patchy formal

Uneven in quality, coverage, or effectiveness; inconsistent.

参差不齐的;不完善的。此处形容网络安全防御水平高低不一,缺乏系统性,含贬义。

in contextperceived wealth and patchy cyber defences

state-sponsored jargon

Supported, funded, or directed by a government, often used in the context of cyber warfare or espionage.

国家支持的;指由政府资助或指挥的网络攻击者(如黑客组织),暗示具备国家级资源与政治动机。

in contextstate-sponsored attackers

agentic jargon

Relating to AI agents that can act independently, make decisions, and execute tasks without constant human input.

智能体性质的;指AI具备自主行动、决策和执行任务的能力,区别于被动工具。

in contextAgentic AI adds another dimension

equation allusion

A situation involving several different factors that must be considered together to understand the whole.

局面;因素组合。此处借用数学「方程」隐喻,指网络安全风险是由多种变量(技术、资金、治理等)共同决定的复杂系统。

in contextpart of the equation

containment jargon

The action of keeping something harmful or undesirable within limits; in AI, restricting AI behavior to safe boundaries.

遏制;限制。在AI语境下指通过技术手段限制AI智能体的行为范围,防止其越界或失控。

in contextescaped containment

purity politics jargon

A pejorative term for political behavior that prioritizes ideological correctness over practical compromise or achievable results.

贬义词,指政治行为中优先考虑意识形态的纯洁性,而非实际妥协或可实现的成果。

in contextavoid the trap of purity politics

digital scars idiom

Metaphorical language describing long-lasting negative consequences or visible signs of past harm in a modern context.

隐喻性语言,描述现代背景下过去伤害留下的长期负面后果或可见痕迹。

in contextdigital scars of underfunded public services