In the days since an artificial intelligence (AI) agent operated by OpenAI gained unauthorised access to a Services Australia portal holding Medicare statistics, important questions have been raised about Australia’s readiness to prevent future breaches.
自OpenAI运营的人工智能(AI)智能体未经授权访问了持有医保统计数据的澳洲服务局门户网站以来,人们纷纷质疑澳洲防范未来数据泄露的准备情况。
Specifically, concerns have been raised about whether Australia is particularly vulnerable to autonomous AI agents because so much of our digital infrastructure depends on outdated or “legacy” software.
具体而言,人们担忧澳洲因大量数字基础设施依赖过时或所谓的「遗留」软件,而对自主AI智能体格外脆弱。
The answer is more complicated than simply blaming the legacy systems.
答案远比单纯归咎于遗留系统更为复杂。
In 2025, the Australian Signals Directorate reported that 59% of Australian government entities reported that legacy technologies were impacting their ability to implement key cyber security controls.
2025年,澳洲信号局(ASD)报告称,59%的澳洲政府实体表示,遗留技术正影响其实施关键网络安全控制措施的能力。
Legacy technology generally refers to older hardware or software that is no longer supported by its manufacturer, cannot be adequately updated or patched, or cannot meet current security requirements.
遗留技术通常指制造商不再支持的旧硬件或软件,无法得到充分更新或修补,或无法满足当前安全要求。
The persistence of these outdated systems is not just a technical problem. As a recent report from the Australian Strategic Policy Institute argued, the underlying problems are often about governance. The key questions relate to who is responsible for replacing the systems, how to fund replacements and whether viable replacements actually exist.
这些过时系统的持续存在不仅是技术问题。正如澳洲战略政策研究所(ASPI)最近的一份报告所指出的,根本问题往往关乎治理。关键问题涉及谁负责替换系统、如何为替换工作提供资金,以及是否存在可行的替代方案。
Australia’s situation is hardly unique. The UK government estimates around 28% of its central government systems use legacy technology. In the US, a 2025 government review identified 11 critical federal legacy systems – up to 60 years old – supporting functions including health care, critical infrastructure, tax processing and national security.
澳洲的情况绝非孤例。英国政府估计其中央政府系统中约有28%使用遗留技术。在美国,2025年的一项政府审查确定了11个关键的联邦遗留系统——有些长达60年历史——支撑着包括医疗保健、关键基础设施、税务处理和国家安全在内的职能。
So, legacy technology is an important part of the equation. But other factors also shape Australia’s exposure to AI-boosted cyber risk.
因此,遗留技术是这一风险方程中的重要一环。但其他因素也塑造了澳洲面对AI助推的网络风险时的暴露程度。
The Australian Cyber Security Centre reports cyber criminals target Australia because of our widespread adoption of digital systems, perceived wealth and patchy cyber defences.
澳洲网络安全中心报告指出,网络罪犯将澳洲作为目标,是因为我们广泛采用数字系统、被感知到的财富以及参差不齐的网络安全防御。
As in other countries, Australian governments and organisations also hold valuable personal, financial, health, research and proprietary information.
与其他国家一样,澳洲政府及机构也掌握着宝贵的个人、金融、健康、研究和专有信息。
These factors matter in different ways. Legacy systems can increase the opportunities for systems to be compromised. And valuable data, economic wealth and critical services increase the incentive to exploit that opportunity.
这些因素以不同方式发挥作用。遗留系统增加了系统被攻破的机会。而宝贵的数据、经济财富和关键服务则增加了利用这种机会的动机。
Agentic AI adds another dimension.
智能体AI(Agentic AI)增添了另一个维度。
Cyber criminals and state-sponsored attackers have exploited old and unpatched systems for decades. More recently, AI has helped humans find vulnerabilities, analyse code and develop ways to exploit these systems faster.
数十年来,网络罪犯和国家级攻击者一直利用老旧且未修补的系统。最近,AI帮助人类发现漏洞、分析代码,并开发出更快利用这些系统的方法。
Now, an AI agent can be given an objective, plan how to achieve it, use tools, interact with external systems and adapt when it encounters an obstacle.
如今,AI智能体可以被赋予目标,规划实现路径,使用工具,与外部系统交互,并在遇到障碍时进行调整。
The Medicare incident in Australia was concerning not simply because AI was involved. According to the Australian Signals Directorate, the AI agent independently identified vulnerabilities and attempted further actions without direct human authorisation.
澳洲的医保事件令人担忧,不仅因为涉及AI。据澳洲信号局称,该AI智能体独立识别了漏洞,并在未经人类直接授权的情况下尝试了进一步行动。
Nor is this phenomenon confined to Australia. Experimental AI agents have escaped containment during cyber security evaluations and reached an unknown number of third-party systems around the world.
这种现象也不仅限于澳洲。在网络安全评估期间,实验性AI智能体曾突破限制,并接触到了全球范围内数量不明的第三方系统。
The emerging problem is that agents may themselves discover and act on weaknesses while pursuing their objectives. These may be things never intended as cyber attacks, such as gathering publicly available medical data.
新兴的问题在于,智能体在追求目标的过程中,可能会自行发现并利用弱点。这些行为可能从未被意图为网络攻击,例如收集公开可用的医疗数据。
So, AI does not create vulnerabilities in ageing systems. But it may change how quickly, persistently and autonomously those vulnerabilities can be discovered and acted upon.
因此,AI并未在老化系统中制造漏洞。但它可能改变发现这些漏洞并加以利用的速度、持久性和自主性。
Safety needs to work in both directions
安全机制需要双向发力

legacy systems aren't just code, they're the digital scars of underfunded public services. who gets hurt when the state's infrastructure crumbles? the people who rely on it.
遗留系统不只是代码,它们是公共服务资金不足留下的数字伤疤。当国家基础设施崩塌时,谁最受伤?是那些依赖它的人。