Blog
Recent Articles
My personal vault of deep dives, field notes and tradecraft on Applied AI within Defence, National Security, Intelligence and Enforcement. Filter by topic to find your way around.
All articles

Obsolete the Day You Sign It: Australia Needs a Continuous ATO, and It Already Has the Missing Piece
Australia has already written down continued authorisation. The Protective Security Policy Framework carries a section headed "Continued Authorisation" which states that authorisation to operate "is generally ongoing once the system is operational", with the system owner monitoring so that the risks of operating the system stay inside the entity's tolerances (Department of Home Affairs, 2026, s 13.3.1.1). The familiar complaint, that we still run annual certificates while the Americans moved on, does not survive the text.

Doing More With Less Is a Trap: Why Cheaper AI Will Not Save Government
Your agency's AI bill will keep climbing even as the price per token falls, because "do more with less" is the wrong promise and cheaper inference does not bank a saving. It buys more inference, more sprawl, and a bigger bill (Jevons, 1865). The assurance we wrap around it measures the wrong thing and then gets gamed until the dashboard is green and the risk is not managed (Strathern, 1997). And because every platform your agency already owns now ships its own model, government AI is fragmenting to mirror the shape of the org chart, one captive feature at a time (Conway, 1968). The public value never turns up, because none of this compresses the thing that actually matters: the time it takes to turn raw information into a decision a person can defend and a citizen can contest.

The Undeclared Dependency: Every Technical Supply Chain Has a Strait of Hormuz
AI cannot secure a supply chain that has never been written down: detection coverage has a ceiling set by what you have actually declared, and no model can flag an edge it was never shown. Australia's fuel stocks, your cloud builds, and the defence industrial base are all exposed through the same weakness, dependencies nobody wrote down, and the unglamorous act of declaring the graph and then verifying it continuously is the actual security control. The clever model you point at the problem comes a distant second.

Exempt by Design: The AI Governance Gap in the National Intelligence Community
It is fair to assume the agencies wielding AI on the most consequential decisions carry the tightest rules governing it; in Australia, for the national intelligence community, that assumption is exactly backwards. The mandatory framework for government AI, the Digital Transformation Agency's policy now at v2.0 with a mandatory use-case register, exempts the Defence portfolio and the national intelligence community (Digital Transformation Agency, 2025). The National AI Plan shelved the proposed mandatory high-risk guardrails and stood up an AI Safety Institute instead (Department of Industry, Science and Resources, 2025). What is left for the community is point-in-time authorisation under the Protective Security Policy Framework and an oversight office that has appointed a single Chief AI Officer (Inspector-General of Intelligence and Security, 2025).

Starved by Design: The Sovereign AI Paradox
Sovereign AI is being pitched to the national security community as a straightforward capability upgrade, yet the paradox holds regardless of vendor: the more classified the network, the worse the artificial intelligence running on it tends to be, because every technique that makes modern AI capable, live retrieval, fine-tuning, a connection to a frontier model, needs data to move, and a classified network's entire purpose is to stop data moving. That gap is a structural feature of how these systems are currently built, not simply a funding shortfall Australia can spend its way out of, though it narrows as local techniques improve. As Australia invests in sovereign and next-generation capability through programs like the Australian Signals Directorate's REDSPICE and the National AI Plan (Australian Signals Directorate, 2022; Department of Industry, Science and Resources, 2025), we owe ourselves an honest conversation about what a sealed enclave can and cannot do.

The 80,000-Entity Wave: Why Tranche 2 Is an Entity Resolution Problem, Not a Compliance One
Roughly 80,000 new reporting entities are about to start filing into Australia's financial intelligence system, and the anti-money-laundering reforms known as Tranche 2 are being sold to those newly captured professions as an onboarding and compliance exercise, when the real problem sits downstream, inside the financial intelligence system that now has to resolve, monitor and make sense of all of them without drowning its analysts in false positives (Australian Transaction Reports and Analysis Centre, 2025).

The Double-Edged Sword of AI in Law Enforcement: Navigating the Deep Fake Dilemma
The same AI that helps investigators can also fabricate convincing evidence. A look at how deepfakes cut both ways in law enforcement, and what accountable governance requires.