Could your organisation withstand a cyberattack accelerated by AI?
The Australian Institute of Company Directors and the Australian Signals Directorate have just published practical guidance for boards on frontier AI cyber threats. The timing is not accidental. Frontier AI models can now find vulnerabilities, chain minor weaknesses into serious compromises, and run malicious activity with little human oversight. The window between a flaw being discovered and it being exploited has collapsed from days to hours.
If your board has not yet asked management how ready the organisation is for that reality, this guidance is the prompt you needed. Below is an overview, then a straight debate on where it helps and where it falls short.
What the guidance actually says
The document is built for directors, not engineers. It opens with threshold questions boards should put to management, groups them into four themes, then lays out a priority list on a timeline from immediate to longer term, with concrete actions under each.
The threshold questions
Four threads run through the questions. How vulnerable are we to AI enabled attacks, and which assumptions in our current risk assessment might already be invalid? Where could minor weaknesses in our systems or supply chain combine into a major incident? Do we actually control our cyber fundamentals, or are we assuming someone else does? And the one that matters most: could we keep operating if an attack moved from taking days to taking hours?
The priority timeline
Immediate: secure attack surfaces and reduce software vulnerabilities. Short term: replace legacy systems, reinforce identity and access management, restrict unnecessary privileges (including for AI agents), and prepare for incidents. Medium term: adopt AI for cyber defence. Longer term: modernise using Secure by Design and Secure by Default principles.
The practical actions are unusually specific. Scan codebases for unsecured keys. Disable legacy authentication. Use phishing resistant multifactor authentication. Give AI agents the minimum access they need. Exercise the incident response plan against AI driven scenarios. That is a usable checklist, not vague principle.
Where the guidance is strong
It is written for the boardroom. Most cyber guidance drowns directors in technical language or settles for slogans. This one translates the AI shift into governance themes a board can actually oversee.
It names AI agents explicitly as an access subject. That is rare and forward looking. As autonomous software spreads through enterprises, treating an AI agent the same as a human account in your least privilege rules is exactly the right instinct, and most guidance has not caught up.
It also tackles supply chain and foreign ownership, control or influence risk from AI vendor reliance. That geopolitical maturity is missing from most comparable documents, and it is becoming central as organisations hand critical functions to offshore AI platforms.
The tempo framing, days to hours, gives directors a concrete mental model for why last year’s risk tolerance no longer holds. That single idea may do more to shift board behaviour than any checklist.
Where it falls short
The guidance is voluntary and non binding. Its only lever is “press management”. For boards that have already ignored years of mandatory adjacent cyber advice, a gentle nudge may not move them. There is no metric, no reporting cadence, no board ready KPI. “Challenge management” stays a subjective exercise without a measuring stick.
The timing of defence side AI adoption is the biggest gap. The document lists adopting AI for cyber defence as a medium term priority. Offensive AI is already here and running at machine speed. Telling a board to treat defensive AI as something to get to later leaves the organisation exposed in the interim. A reasonable board should pull that forward to now.
AI agent restrictions are only short term, not immediate. Given how fast agents are being wired into workflows, that delay opens a window for autonomous lateral movement. Treat it as immediate.
The guidance also frames AI as a tool to adopt, not as a live attack surface today. It does not address prompt injection, agent misbehaviour, or model supply chain poisoning as incidents a board should be planning for right now. Small organisations get little tailored help, since “engage management” assumes a management layer a small business may not have. And there is no guidance on cost prioritisation, insurance, director liability, or disclosure obligations when a frontier AI incident lands.
The question the guidance does not answer
It asks whether your operations would remain effective if attacks accelerated. It does not tell you how to prove it. The single most important question a board should add is direct: what specific, measurable metric, such as mean time to detect, shows our defences can keep pace with an attack moving at machine speed? Without that number, you are relying on assurance, not evidence.
What to do this week
Put the four threshold question themes on the next board agenda. Pull AI for defence and AI agent least privilege to the top of the list, ahead of the document’s own timeline. Ask for one metric that proves detection and response can operate at machine speed. And review your AI vendor reliance for foreign ownership, control or influence exposure. The threat is moving faster than the guidance’s calendar. Your oversight should move faster than the guidance too.
Related Reading
Clone Your Voice and Make Real Phone Calls with Telnyx and a Hermes Agent Skill