ChannelLife Australia - Industry insider news for technology resellers
Australia
AI's next cyber threat has arrived, identity security is key for survival

AI's next cyber threat has arrived, identity security is key for survival

Mon, 7th Sep 2026 (Today)
Morey J. Haber
MOREY J. HABER Chief Security Officer BeyondTrust

Australia's most senior cyber defence agency has delivered a candid warning to executives and board members. The next generation of artificial intelligence will not simply help businesses work faster, but will also help cyber criminals attack faster.

The Australian Signals Directorate's (ASD) new guidance on frontier AI signals a shift in how executives should think about cyber risk. Rather than treating AI as another technology investment, the ASD argues organisations must prepare for a future where AI dramatically reduces the time and expertise required to launch sophisticated cyberattacks.

For Australian businesses, the implications extend well beyond deploying generative AI tools internally. Frontier AI introduces a new class of adversary capable of automating reconnaissance, identifying vulnerabilities, and deploy working exploits at a pace that traditional security operations were never designed to manage.

Rethinking cyber resilience

The ASD's publication, Frontier AI Cyber Threat Considerations for Boards of Directors, is aimed squarely at executives rather than IT departments. Its recommendations focus on governance as much as technology, urging organisations to identify their most valuable assets and embed cybersecurity into core business processes instead of treating them as afterthoughts.

None of these recommendations is new. Australian businesses have spent years discussing Zero Trust, visibility, vulnerability and patch management, and secure-by-design architectures. What changes in the era of frontier AI is the urgency to ensure all disciplines, including identity security, are operating efficiently and effectively.

The ASD argues organisations should assume compromise verse determining if an incident exists. This reflects a growing recognition that threat actors no longer need to breach perimeter defences when compromised identities provide a faster path to log in to enterprise systems.

This changes the economics of defence. Rather than attempting to secure every endpoint equally, businesses need greater precision about which identities (human, machine, and agent AI) possess privileged access and which pathways attackers are most likely to exploit to escalate privileges.

Identity the new security perimeter

If frontier AI accelerates attacks, identity security becomes the mechanism for slowing them down. The ASD's emphasis on protecting an organisation's "crown jewels" aligns with a privileged-centric approach to cybersecurity.

Instead of focusing exclusively on networks and devices, organisations are being encouraged to gain continuous visibility into privileged identities, hidden attack paths, and unnecessary access rights before those weaknesses become exploitable.

This reflects the broader evolution of Zero Trust, as authentication is no longer viewed as a one-time event. Every identity must be continuously verified, with elevated privileges granted only when explicitly required and removed as soon as the task is complete. The shift is particularly important for organisations operating hybrid environments, where employees, contractors, and machines interact across multiple platforms.

Visibility without context generates overwhelming volumes of security data. The ASD instead points towards continuous monitoring that connects privileged activity with behavioural analysis and forensic evidence, allowing security teams to understand not only what happened and whether the behaviour was unusual.

Third-party access now a bigger risk

The report also elevates supply chain security from an operational issue to a board-level concern.

External identities, including suppliers, contractors, and managed service providers, increasingly require privileged access into enterprise environments. These accounts often sit outside traditional identity governance processes while retaining extensive permissions, making them attractive targets for threat actors.

As organisations outsource more technology operations and adopt cloud-native architectures, privileged remote access becomes a significant attack surface. The ASD argues businesses should minimise credential sharing, enforce approval workflows, and monitor privileged sessions involving third parties to reduce supplier-related risk.

For sectors including financial services, healthcare, energy and government, where interconnected suppliers are essential to operations, identity governance increasingly extends beyond organisational boundaries and requires focused scrutiny.

AI agents a growing threat

Perhaps the most significant challenge identified in the guidance is one businesses have barely begun addressing: AI itself possesses its own characteristics as a dynamic identity.

Autonomous agents, APIs, and machine identities now perform tasks that previously required human administrators. Each carries permissions, secrets, and entitlements that must be governed like any other privileged user. Without oversight, these AI identities risk becoming a new form of shadow IT. Rather than external threat actors compromising employees, organisations could inadvertently deploy internal AI agents capable of accessing sensitive systems without sufficient controls.

That possibility fundamentally changes identity governance. Businesses are no longer protecting only people but also software capable of making autonomous decisions across enterprise infrastructure.

Improved governance

Finally, one of the more practical conclusions in the ASD guidance is that defending against frontier AI does not necessarily require dramatically expanding security teams or purchasing every new AI-powered cybersecurity product entering the market.

Instead, the report advocates maturing existing cybersecurity disciplines and strengthening proven controls around privileged access, credential management, endpoint privilege reduction, and identity security and visibility.

This represents a governance challenge as much as a technology one. Boards need confidence that identity risk is measurable, continuously monitored, and aligned with broader cyber resilience objectives. Investments that reduce unnecessary privilege, eliminate hidden attack paths and verify identities continuously become strategic enablers rather than incremental security upgrades.

Frontier AI is poised to reshape cybercrime by making sophisticated attacks faster, cheaper, and more scalable than ever before. Australian organisations cannot prevent that technological shift, but they can influence how exposed and prepared they are when it arrives.