Australian boards should treat the foreign ownership, control and influence of their artificial intelligence (AI) providers as a cyber risk in its own right, the Australian Signals Directorate advises.
That is one of the four key action points in new guidance from the ASD, co-written with the Australian Institute of Company Directors (AICD), that asks boards to assess the risks of relying on AI providers.
ASD and AICD do not refer to any particular reason for the advice in the guidance, which comes after the highly-publicised United States government access restriction order placed on American AI provider Anthropic's Mythos-class models in June this year.
Currently, nearly all leading frontier AI model developers are headquartered in the US, while China has emerged as the only other country with multiple companies developing competitive AIs.
Outside the US and China, France's Mistral remains one of the few credible independent alternatives.
Similar AI and digital sovereignty concerns have appeared in Australian public discourse recently.
"The inescapable lesson of the global instability of the 2020s, is that if we are always dependent on someone else, somewhere else, we will always be vulnerable," prime minister Anthony Albanese said in a speech at the University of Sydney on July 15.
Beyond the foreign control of AI, the guidance asks boards to review how frontier AI models could affect their organisations' security posture, which includes new AI-enabled threats.
Countering agentic AI-powered threat environments is another action item for boards, along with improving governance, processes and capabilities to mange use of the technology within their organisations.
The guidance also reiterates how frontier models accelerate the tempo of attacks.
It warns that vulnerability discovery and exploitation timelines could compress "from days to hours" lowering the technical skill barrier for malicious actors, while allowing frontier models to chain multiple low-severity vulnerabilities into high-impact compromises.
Boards are advised that models can now conduct malicious activity with "little to no human oversight", and that AI agents operating inside an organisation should be granted only the minimum access their duties require.

SAP NOW AI Tour ANZ
Forrester's AI Forum Sydney
The 2026 iAwards
Integrate 2026
Security Exhibition & Conference



