What it requires, and by when

The Direction is two pages, signed by Stephanie Foster PSM, Secretary of the Department of Home Affairs, in September 2026, and listed on the Protective Security Policy Framework site with a publication date of 29 September. Its one-sentence summary is that it requires Australian Government entities to reduce cyber security risks arising from vulnerable legacy technology systems and to strengthen cyber posture across Australian Government systems. It binds non-corporate Commonwealth entities under the Public Governance, Performance and Accountability Act, and the Accountable Authority of each one must adhere to it. Corporate Commonwealth entities and the states are outside it.

The obligations are numbered, and they carry two dates.

What Direction 002-2026 requires of non-corporate Commonwealth entities
ByEvery entity must
31 December 2026If it operates Systems of Government Significance: incorporate the SoGS Risk Reduction Measures set out in Policy Explanatory Note 002-2026 for its declared systems, and report completion of the legacy technology stocktake of those systems
31 March 2027Conduct a Legacy Technology Stocktake of every legacy system managed by or on behalf of the entity, prioritising public-facing services
31 March 2027Develop and maintain a Legacy Technology Risk Management Plan, folded into the entity’s cyber security strategy and uplift plan, with a reduction target, prioritisation strategies, mitigations for systems that stay, and procedures to rationalise the estate
31 March 2027Report completion of the stocktake and send a copy of the plan to the department’s Commonwealth Security Policy Branch

The reduction target is the part with teeth, and it is softer than it sounds. The plan must include a target to reduce legacy systems in the estate commensurate with entity’s risk tolerance and appetite. Each entity sets its own number, and the plan goes to Home Affairs rather than anywhere a reader can see it. The Direction also leaves the depth of the stocktake to the entity: agencies remain responsible for determining the appropriate depth and scope of their assessment.

The exemption is narrower than in the earlier Directions. An Accountable Authority may seek a reporting exemption for a legitimate business reason, limited to national security functions. That is an exemption from reporting, not from doing the stocktake or holding the plan, and the only qualifying ground is national security. The Deny List Direction offered three grounds, including marketing.

What counts as legacy

The definition is borrowed from PSPF section 13.7 by footnote, and it is a two-column test: a product is legacy when it meets one or more criteria in both Category A and Category B. Category A is about the vendor: the product is end-of-life, out of support, or on extended support from its manufacturer, vendor or developer. Category B is about the entity: the product is impractical to update or support in house, no longer cost-effective, above the current acceptable risk threshold, offering diminishing business utility, or obstructing the entity’s IT strategies.

Both columns have to be met. An unsupported product the entity can still patch and afford is not legacy under this test, and a costly, awkward product the vendor still supports is not either. For a vendor, the first column is the one you control: a product whose support you have ended is a product your government customers are now required to count, plan around and, where their own target says so, remove.

Where the AI is

The title says AI-enabled risks. The requirements say legacy technology. The link between them is in the reasoning, which states that frontier AI capabilities have targeted the Commonwealth’s technology estate, and that in that environment the continued operation of vulnerable legacy systems, together with accumulated exploitable vulnerabilities, poses an unacceptable risk to the Australian Government. The Direction tells entities to apply Policy Advisory 001-2026, Cyber Security Readiness in the Frontier AI Era, published 27 May, and the argument is that advisory’s argument: frontier AI, in the advisory’s words, increases the risks posed by known vulnerabilities and legacy systems, creating a vulnerability storm. We read the advisory in August, and its answer was that entities do not need frontier models to stay protected; they need the fundamentals. The Direction is the advisory turned into an obligation with dates on it.

Two further instructions sit in the preamble rather than the numbered list. Entities must balance system availability with security, particularly where systems are public facing, and they should strengthen vulnerability and patch management across the whole estate by recognising the shortened time between vulnerability discovery and exploitation and rapidly patching what vendors or their own processes deem critical. Neither carries a date or a reporting step.

Nothing in the Direction names an AI product, bans one, approves one, or adds a condition to buying one. If you sell AI tools to the Commonwealth, the instruments that gate you are unchanged: the Deny List under Direction 004-2025, the foreign ownership, control or influence assessment, and Policy Advisory 001-2025. What this Direction does to a vendor is indirect and shows up in the second column of the legacy test, and in the reduction target each customer now has to set.

Two lineages of Direction, and which one this is

Read the Directions index as a whole and two families appear. One is about who supplies the technology: TikTok in 2023, the foreign ownership, control or influence Direction of 2024, DeepSeek and Kaspersky in February 2025, then Direction 004-2025, which replaced named bans with a standing Deny List. The other is about what the technology is exposed to and orders an inventory: the Technology Asset Stocktake of July 2024, which the index describes as requiring entities to identify and actively manage the risks of vulnerable technologies they manage, and Direction 001-2026 in February, which required entities to inventory Cisco SD-WAN systems, apply updates and report potential compromise.

Direction 002-2026 is in the second family. It is a stocktake-and-plan instrument, and the SoGS deadline follows the Cisco pattern of a shorter clock for the systems that matter most. It is the first Direction with AI in its title, and the AI is in the threat model rather than the subject matter, which is the same place the advisory put it.

What is not published yet

The 31 December obligation points at a document that does not exist in public. The SoGS Risk Reduction Measures live in Policy Explanatory Note 002-2026, which the Direction says is to be issued by 13 October 2026, with policy advisory sessions run by the department. Entities operating critical systems therefore have a deadline before they have the measures it is measured against, though the note is due within a fortnight of publication.

Whether that note will be public is a separate question. We enumerated all 40 items in the PSPF publications library on 3 October. The Direction is there. No Policy Explanatory Note of any number is, which matches what we found in August for the note the Deny List Direction relies on. If the pattern holds, the measures that define compliance for the Commonwealth’s most critical digital services will be shared with entities and not with the public.

Our view

This is a sensible instrument wearing a fashionable title. The advisory said the right thing in May: the exposure frontier AI creates is the unpatched system you already have, and the defence is fundamentals. A dated order to find every legacy system and plan its retirement is exactly the follow-through that argument called for, and reading the title as an AI procurement rule would be a mistake. Two things weaken it as a public commitment. The reduction target is whatever each entity decides its appetite allows, so there is no Commonwealth-wide number to hold anyone to. And the plans and the measures both travel to Home Affairs rather than to the public, so the only verifiable fact a reader will ever have is that the Direction was issued. That is a lot of trust to ask on the strength of two pages.

Sources

  1. PSPF Direction 002-2026, Strengthening Commonwealth Cyber Posture Against AI-Enabled Risks, protectivesecurity.gov.au, two pages, signed by Stephanie Foster PSM, Secretary of the Department of Home Affairs, September 2026 (PDF downloaded and read in full 3 October 2026): the scope and summary sentence; the reference to Policy Explanatory Note 002-2026 to be issued by 13 October 2026 and to Policy Advisory 001-2026; the frontier AI reasoning and the unacceptable-risk determination; the availability, patching and SoGS priority instructions; the four numbered requirements with their 31 March 2027 and 31 December 2026 dates; the legacy definition in footnote 1 and the uplift plan reference in footnote 3; and the reporting exemption limited to national security functions.
  2. Protective Security Directions under the PSPF, protectivesecurity.gov.au (read 3 October 2026): the 29 September 2026 publication date and one-sentence summary of Direction 002-2026; that the Accountable Authority of each entity must adhere to any Direction issued; and the full list of Directions from 001-2023 to 002-2026 with their published summaries, which is the basis for the two-lineage reading and the description of Direction 001-2026 on Cisco SD-WAN.
  3. Direction 002-2026 on Strengthening Commonwealth Cyber Posture Against AI-Enabled Risks, PSPF publications library entry (read 3 October 2026): publication date and last updated date of 29 September 2026.
  4. PSPF Policy Advisory 001-2026, Cyber Security Readiness in the Frontier AI Era, protectivesecurity.gov.au (PDF, read in full 30 August 2026 and re-read 3 October 2026): the vulnerability storm passage and the statement that entities do not need access to the most advanced frontier AI models to stay protected.
  5. Protective Security Policy Advisories, protectivesecurity.gov.au (read 3 October 2026): the 27 May 2026 publication date of Policy Advisory 001-2026 and the statement that advisories are guidance products.
  6. PSPF publications library, protectivesecurity.gov.au (all four pages enumerated 3 October 2026): the full set of 40 items, which is the basis for the statement that no Policy Explanatory Note appears there.

How we checked this. The Direction was downloaded from the link on the PSPF Directions index and read in full; every requirement in the table and every quotation is from that document. The day of signature is handwritten on the PDF and not legible in our copy, so we give the month and the site’s publication date. The two-lineage reading is our grouping of the published Directions by what their index summaries say they do, not a classification the department uses. We have not asked Home Affairs for Policy Explanatory Note 002-2026 or whether it will be public; the absence claim is about what the publications library listed on 3 October. The “our view” section is opinion based on the documents cited.

Work in an entity that is doing the stocktake, or read the Direction differently? Tell us and we will check it against the document and log the outcome here.