An adversary’s numerical advantage is something Australia faces across all domains, but the cyber domain is one area where Australia can offset that advantage, building true asymmetric capabilities.
The cyber battlespace has undergone a step change with the arrival of frontier AI models. What took penetration testers two years to accomplish, Tom Scully from Palo Alto Networks completed in three weeks when paired with Claude’s Mythos model. That compression has collapsing vulnerability windows and forces a fundamental rethink of how Defence operates its security operations centres.
The asymmetry cuts both ways. Attackers now possess tools that dramatically compress exploitation timelines. But for the first time in cyber space, defenders can achieve parity through agentic AI – autonomous agents embedded in security operations that multiply human operator capacity by orders of magnitude.
Palo Alto’s own security operations centre covers 23,000 users across eight data centres and 85,000 customers with just 15 people across two global locations operating 24/7/365. That scale is impossible without AI and machine learning disciplined into an integrated platform. Now, agentic AI adds the next layer: individual security operators deploying multiple AI agents to handle discrete tasks – network analysis, endpoint evaluation, reverse engineering – with each agent maintaining human oversight yet operating with delegated authority.
The critical challenge is governance. Only 6 per cent of organisations possess AI governance frameworks. Scully emphasises that the framing is not about free will; it resembles a military command structure. Commanders delegate authority, set rules of engagement, define reporting protocols and remain accountable for outcomes. AI agents operate identically – given clear direction, guardrails and escalation paths.
Australia must urgently establish governance standards aligned to ISO 42001 or NIST frameworks, then enforce those standards through security tooling. Without that foundation, organisations will struggle to defend against attackers armed with frontier AI.
The decisive question is not whether to deploy agentic AI, but whether Defence can implement it faster than adversaries exploit the window before our cyber defences mature.
Enjoy the podcast,
The Defence Connect Spotlight team