What the document is

PSPF Policy Advisory 001-2026, Cyber Security Readiness in the Frontier AI Era, is final version 1.0 dated 26 May 2026 and was published to the Protective Security Policy Framework on 27 May. Its stated audience is Accountable Authorities, Chief Security Officers, Chief Information Security Officers, Procurement Officers and entity personnel, which is a wider list than most advisories carry.

As we set out when we corrected our map of these instruments, a PSPF policy advisory is guidance rather than obligation. What gives this one force is that almost everything it asks for is already mandatory somewhere else, and it spends most of its two pages pointing at exactly which requirement.

What it says frontier AI actually changes

The framing is not the usual one. Frontier AI models are described as the most advanced, cutting-edge AI models available representing an anticipated step change in capability, and the risk is put as a clear dual-use challenge: the same models that strengthen cyber defence can be exploited by malicious actors to conduct cyber activities and other forms of harm faster, cheaper and at greater scale.

Then the sentence that does the analytical work. Frontier AI increases the risks posed by, and accelerates the consequences of, known vulnerabilities, legacy systems and weak cyber hygiene, creating a ‘vulnerability storm’ for entities.

Read that carefully, because it is a claim about what the technology does to an existing problem rather than a claim that it creates a new one. The exposure is the unpatched system you already had. What changes is how fast it is found and used, which the attached ASD material puts as bluntly as a government document ever does: Frontier AI is collapsing exploit timelines from days to hours.

The answer, which is not to buy frontier AI

Having described a step change in offensive capability, the advisory's response is deliberately unglamorous. Entities must ensure they are appropriately protected in the frontier AI era through the consistent application of cyber security fundamentals, which remain the Commonwealth’s most effective defence.

And then, in bold in the original: Australian Government entities do not need access to the most advanced frontier AI models to stay protected. Effective readiness, it says, is achieved through existing mitigations and practices consistent with existing Australian Signals Directorate technical advice and the PSPF.

Four things are named as immediate priorities: review and assure compliance with the PSPF, the Information Security Manual and the Essential Eight; confirm executive accountability for cyber security risk management for frontier AI; engage with ASD and Home Affairs guidance; and identify and remediate material gaps that could be exploited by AI-enabled threat actors.

The requirements it points at

The advisory is guidance, but the table below is not. Each row names a PSPF requirement that already binds non-corporate Commonwealth entities.

Existing PSPF requirements the advisory says entities must follow, as listed in Policy Advisory 001-2026
AreaRequirementWhat it obliges
Internet-facing systems0211A Technology Asset Stocktake and a Technology Security Risk Management Plan, including network segregation and separation
Secure procurement and supply chains0039 to 0049Proportionate security terms in contracts and outsourcing, including considering foreign ownership, control or influence risks
Reduce attack surfaces0105Essential Eight user application hardening to Maturity Level Two
Patching(Essential Eight)Patch applications and operating systems to Maturity Level Two
Zero trustPSPF Table 24The Guiding Principles to Embed a Zero Trust Culture, as entity-wide transformation
Gateways0214Classified-information infrastructure protected by a Gateway or Security Service Edge under the Gateway Security Standard
Threat sharing0214 and 0215Connect to ASD's Cyber Security Partnership Program and Cyber Threat Intelligence Sharing Platform
Information Security Manual0084 and 0085ISM principles across the whole system lifecycle, controls applied on a risk-based approach

The procurement row is the one that connects to the rest of this beat. Foreign ownership, control and influence is the same test that produced the DeepSeek ban and the unpublished Deny List, and here it reappears as a standing obligation on anyone buying AI into a Commonwealth entity.

Where adopting AI actually sits

Attached as Annex A is ASD's practical guidance, How to Act Now to Prepare for Frontier AI. It sets out six strategies with time horizons, and the ordering is the story.

ASD's six strategies, from Annex A to Policy Advisory 001-2026
#StrategyHorizonAction
01SecureShort-termReduced attack surface, approved configuration baselines
02ReduceShort-termSecure software vulnerabilities, patch within risk-based timeframes
03ReplaceShort-termReplace legacy information technology, or isolate it
04PrepareMedium-termPrepare for cyber security incidents, exercise response and recovery
05AdoptMedium-termAdopt AI for cyber defence purposes
06ModerniseLonger-termSecure by Design and Secure by Default across the lifecycle

Four strategies come before adopting AI, three of them short-term while adoption is medium-term. And when adoption does arrive it is scoped narrowly: deploying AI models for augmenting system assurance activities such as vulnerability scanning and assessment, and for augmenting system monitoring activities, such as identifying and triaging cyber security events. Scanning and triage, not autonomy. The strategy also requires that AI used this way be secure, controllable, human-supervised, and used in an ethical and accountable manner.

Our view

This is the most useful document the Commonwealth has published on AI this year, and it is useful precisely because it refuses the framing everyone else uses. The pitch an entity hears from the market is that frontier AI changes the threat so fundamentally that only frontier AI can answer it. The Commonwealth's own advice, written by the department that issues the binding Directions, is that the threat is mostly an acceleration of failures you already have, and that the answer is to fix those.

We think that is right, and the reasoning holds without any special knowledge. If the change is that discovery-to-exploitation compresses from days to hours, then the value of being patched went up and the value of being clever went sideways. An unpatched internet-facing system does not become defensible because you bought a model.

The part we would push on is the same one we pushed on with the AI policy: this is an advisory, so none of it binds on its own. It works by pointing at requirements that do bind, which is elegant, and it also means an entity that ignores the advisory is not in breach of the advisory. The obligations it names were already there and the Essential Eight maturity levels it cites are long-standing. What the document adds is a reason to prioritise them now rather than a new lever to make anyone.

Worth noticing too that this is the third PSPF instrument on AI in under a year, alongside the generative-AI advisory of October 2025 and the DeepSeek Direction of February 2025, and the three have different characters: one permits, one bans, one prioritises. Read together they are a more coherent programme than the AI-specific policy set most coverage focuses on.

What we would check next: whether the Essential Eight Maturity Level Two obligation the advisory leans on is actually being met, since the Commonwealth publishes assessment data on exactly that, and whether the promised ASD guidance is being taken up.