Latest/22 min read
Obsolete the Day You Sign It: Australia Needs a Continuous ATO, and It Already Has the Missing Piece
Australia has already written down continued authorisation. The Protective Security Policy Framework carries a section headed "Continued Authorisation" which states that authorisation to operate "is generally ongoing once the system is operational", with the system owner monitoring so that the risks of operating the system stay inside the entity's tolerances (Department of Home Affairs, 2026, s 13.3.1.1). The familiar complaint, that we still run annual certificates while the Americans moved on, does not survive the text.
AIContinuous AuthorisationSecurityGovernanceSovereign AI
Read article→