What the document is
PSPF Policy Advisory 001-2026, Cyber Security Readiness in the Frontier AI Era, is final version 1.0 dated 26 May 2026 and was published to the Protective Security Policy Framework on 27 May. Its stated audience is Accountable Authorities, Chief Security Officers, Chief Information Security Officers, Procurement Officers and entity personnel, which is a wider list than most advisories carry.
As we set out when we corrected our map of these instruments, a PSPF policy advisory is guidance rather than obligation. What gives this one force is that almost everything it asks for is already mandatory somewhere else, and it spends most of its two pages pointing at exactly which requirement.
What it says frontier AI actually changes
The framing is not the usual one. Frontier AI models are described as
the most advanced, cutting-edge AI models available
representing
an anticipated step change in capability
, and the risk is put as a
clear dual-use challenge
: the same models that strengthen cyber defence
can be exploited by malicious actors to conduct cyber activities and other forms of harm
faster, cheaper and at greater scale
.
Then the sentence that does the analytical work. Frontier AI
increases the risks posed by, and accelerates the consequences of, known vulnerabilities,
legacy systems and weak cyber hygiene, creating a ‘vulnerability storm’ for
entities
.
Read that carefully, because it is a claim about what the technology does to an existing
problem rather than a claim that it creates a new one. The exposure is the unpatched system
you already had. What changes is how fast it is found and used, which the attached ASD
material puts as bluntly as a government document ever does:
Frontier AI is collapsing exploit timelines from days to hours.
The answer, which is not to buy frontier AI
Having described a step change in offensive capability, the advisory's response is
deliberately unglamorous. Entities must ensure they are appropriately protected in the
frontier AI era through the consistent application of cyber security fundamentals, which
remain the Commonwealth’s most effective defence
.
And then, in bold in the original: Australian Government entities do not need access to
the most advanced frontier AI models to stay protected.
Effective readiness, it says, is
achieved through existing mitigations and practices consistent with existing Australian
Signals Directorate technical advice and the PSPF.
Four things are named as immediate priorities: review and assure compliance with the PSPF, the Information Security Manual and the Essential Eight; confirm executive accountability for cyber security risk management for frontier AI; engage with ASD and Home Affairs guidance; and identify and remediate material gaps that could be exploited by AI-enabled threat actors.
The requirements it points at
The advisory is guidance, but the table below is not. Each row names a PSPF requirement that already binds non-corporate Commonwealth entities.
| Area | Requirement | What it obliges |
|---|---|---|
| Internet-facing systems | 0211 | A Technology Asset Stocktake and a Technology Security Risk Management Plan, including network segregation and separation |
| Secure procurement and supply chains | 0039 to 0049 | Proportionate security terms in contracts and outsourcing, including considering foreign ownership, control or influence risks |
| Reduce attack surfaces | 0105 | Essential Eight user application hardening to Maturity Level Two |
| Patching | (Essential Eight) | Patch applications and operating systems to Maturity Level Two |
| Zero trust | PSPF Table 24 | The Guiding Principles to Embed a Zero Trust Culture, as entity-wide transformation |
| Gateways | 0214 | Classified-information infrastructure protected by a Gateway or Security Service Edge under the Gateway Security Standard |
| Threat sharing | 0214 and 0215 | Connect to ASD's Cyber Security Partnership Program and Cyber Threat Intelligence Sharing Platform |
| Information Security Manual | 0084 and 0085 | ISM principles across the whole system lifecycle, controls applied on a risk-based approach |
The procurement row is the one that connects to the rest of this beat. Foreign ownership, control and influence is the same test that produced the DeepSeek ban and the unpublished Deny List, and here it reappears as a standing obligation on anyone buying AI into a Commonwealth entity.
Where adopting AI actually sits
Attached as Annex A is ASD's practical guidance, How to Act Now to Prepare for Frontier AI. It sets out six strategies with time horizons, and the ordering is the story.
| # | Strategy | Horizon | Action |
|---|---|---|---|
| 01 | Secure | Short-term | Reduced attack surface, approved configuration baselines |
| 02 | Reduce | Short-term | Secure software vulnerabilities, patch within risk-based timeframes |
| 03 | Replace | Short-term | Replace legacy information technology, or isolate it |
| 04 | Prepare | Medium-term | Prepare for cyber security incidents, exercise response and recovery |
| 05 | Adopt | Medium-term | Adopt AI for cyber defence purposes |
| 06 | Modernise | Longer-term | Secure by Design and Secure by Default across the lifecycle |
Four strategies come before adopting AI, three of them short-term while adoption is
medium-term. And when adoption does arrive it is scoped narrowly: deploying AI models for
augmenting system assurance
activities such as vulnerability scanning and assessment,
and for augmenting system monitoring activities, such as identifying and triaging cyber
security events
. Scanning and triage, not autonomy. The strategy also requires that AI
used this way be secure, controllable, human-supervised, and used in an ethical and
accountable manner.
Our view
This is the most useful document the Commonwealth has published on AI this year, and it is useful precisely because it refuses the framing everyone else uses. The pitch an entity hears from the market is that frontier AI changes the threat so fundamentally that only frontier AI can answer it. The Commonwealth's own advice, written by the department that issues the binding Directions, is that the threat is mostly an acceleration of failures you already have, and that the answer is to fix those.
We think that is right, and the reasoning holds without any special knowledge. If the change is that discovery-to-exploitation compresses from days to hours, then the value of being patched went up and the value of being clever went sideways. An unpatched internet-facing system does not become defensible because you bought a model.
The part we would push on is the same one we pushed on with the AI policy: this is an advisory, so none of it binds on its own. It works by pointing at requirements that do bind, which is elegant, and it also means an entity that ignores the advisory is not in breach of the advisory. The obligations it names were already there and the Essential Eight maturity levels it cites are long-standing. What the document adds is a reason to prioritise them now rather than a new lever to make anyone.
Worth noticing too that this is the third PSPF instrument on AI in under a year, alongside the generative-AI advisory of October 2025 and the DeepSeek Direction of February 2025, and the three have different characters: one permits, one bans, one prioritises. Read together they are a more coherent programme than the AI-specific policy set most coverage focuses on.
What we would check next: whether the Essential Eight Maturity Level Two obligation the advisory leans on is actually being met, since the Commonwealth publishes assessment data on exactly that, and whether the promised ASD guidance is being taken up.