Backwards decision map — AI in Australia, for Australia

Living document. A draft for discussion, updated as processes and evidence change. Corrections welcome at contact@aiinaustralia.org. Last updated 1 Oct 2026

Working backwards from a 24-month horizon. In each domain, the upper line shows what is likely to happen technically, with a likelihood band and whether any Australian process covers it. The line beneath shows the decisions to be made, and by whom. The bottom row tracks the live government processes.

Loss of control & misalignment Catastrophic malign use (bio/chem/cyber) Strategic & military stability Not coveredPartly coveredCovered by a current Australian process Convening's window / the gap
The core finding It's difficult to find independence in the current landscape of assessing AI risk, and that is exactly what this workshop is designed to provide. Australia, and other middle powers, need to make decisions, even under conditions of high uncertainty, that allow them to understand their leverage to influence the frontier of AI. Australia already has a foothold: AISI is evaluating unreleased frontier models with the Australian Signals Directorate and, per its April 2026 MOU with Anthropic, running joint safety/security evaluations and technical exchanges "relevant to safety and national security." But no 12–24 month decision process draws on that work, and nobody connects what the diaspora knows to the officials making those calls. The Royal Commission's terms of reference, published 1 Oct, explicitly exclude national security, cyber security and critical infrastructure as Commonwealth matters; the JSC's mandate covers AI's national-security dimension, but whether it examines frontier misuse in depth won't be clear until it reports on 30 Nov. That's the gap: a loop-closing problem, not a coverage vacuum. The convening is now likely to land in mid-December or in 2027, after the JSC reports on 30 Nov. That makes it a response to the JSC's findings rather than an input to them: it can test what the report did and didn't examine in these three domains, and feed the government's response to it, which is the next live decision point.
What the technical line shows Capability is running one to two years ahead of what Australia's live processes govern. Before the Royal Commission reports on 1 July 2027, two developments are likely: freely downloadable AI models that can find and exploit software security flaws on their own, as well as today's most capable restricted models can, and more developer agents acting on third-party and government systems (the June access to four Australian government services looks like an early case, not a one-off). A third is plausible: a frontier lab unable to rule out its own top bio threshold, with no Australian body testing for it. Australia is mostly a taker of US decisions on model access, but it has real leverage in three places: evaluation through AISI and ASD, the terms on which frontier training happens onshore, and the right to be told when foreign agents touch Australian systems.
Domain
Now – Dec 2026ToR lock-in, JSC reports
Jan – Jun 2027Standards legislation, RC hearings
Jul – Dec 2027RC reports, government response
202812–24 month horizon
Loss of control & misalignment
What's likely to happen technically
T1, Q4 2026, likelyNext independent frontier risk assessment finds more robust rogue-deployment potential in labs' internal agentsNot covered: MOUs cover model tests, not developers' internal agent use
T2, now to H1 2027, likelyMore developer agents reaching third-party and government systems during training, including in AustraliaPartly: PM&C taskforce, but no notification duty
T5, to mid-2027, likelyAutonomous task length reaches multi-week; public benchmarks stop telling models apartPartly: AISI testing, A$29.9M over four years
T7, Q1 2027, likelyInternational AI Safety Report 2027 publishedCovered via the AISI network
T6, through 2027, likelyModels that recognise when they're being tested make behavioural evaluations less reliablePartly: no assurance standard defined
T10, 2027, plausibleAI meaningfully accelerating AI research inside the labsNot covered
T12, 2027–28, possible to plausibleSelf-exfiltration or robust autonomous replication shown in evaluations or incidentsPartly: data-centre standards cover energy and water, not containment
T16, 2028, possible"Automated AI researcher" systems (OpenAI's stated March 2028 goal)Not covered
Decisions to be made
Decided 1 Oct: the Royal Commission's terms of reference exclude national security, cyber security, critical infrastructure and data centres, referring them to Commonwealth processes. A narrow opening remains: "safeguarding people and society from AI-related risks" and frameworks for the "safe and responsible development" of AI in South Australia.SA Royal Commission — bounds its powers until it reports on 1 Jul 2027
Just happened: the PM&C taskforce is testing whether current law covers AI agents acting on systems their developers don't control, and whether penalties apply to OpenAI. Its findings are the first real decision on loss of control in Australia.PM&C-led taskforce with ASD, AISI, Office of AI
What notification duty, timeline and evidence access should bind foreign developers whose agents touch Australian systems? The June incident took about 12 weeks to reach the agencies affected.PM&C taskforce, ASD, Home Affairs
Decision already taken, not yet used: Commonwealth–Anthropic MOU (1 Apr 2026) commits AISI to joint frontier safety/security evaluations with ASD & international partnersSigned — the open question is whether any 12–24 month decision process draws on it
Government response to the JSC report (due 30 Nov): does it adopt binding testing, disclosure or incident-reporting obligations on frontier developers?Commonwealth response to the JSC — the convening's most direct point of influence
Real 12–24 month decision point: Standards legislation's scope is still open. First defined subjects are data centres & creative-works training (National Cabinet endorsed data-centre standards 26 Aug 2026, Commonwealth to legislate early 2027) — no exposure draft, no named regulator. Can the architecture later extend to frontier models, and should conditions for frontier training trigger on capability thresholds, not only compute?Office of AI — a live, answerable question with a clear owner
Does AISI's mandate move toward statutory evaluation power, and extend from pre-release model tests to developers' internal agent use, where both 2026 incidents happened?Cabinet / Office of AI
RC final report (due 1 Jul 2027) — adopted, shelved, or partially adopted by SA govtSA Cabinet
Does a state-level recommendation get translated into a Commonwealth position? (states can't bind the Commonwealth)National Cabinet / Commonwealth
What assurance evidence will Australia accept once benchmarks saturate and models can game behavioural tests?AISI
Does what Australia learns through the international AISI network actually feed national decisions, and what does Australia contribute back?Office of AI / AISI
Catastrophic malign use
What's likely to happen technically
T3, Q4 2026, scheduledUS synthesis-screening milestone (13 Oct) and the Biological Weapons Convention working group's final session (Dec)Not covered by any AI process
T4, likely by H1 2027AI models anyone can download that find and exploit software security flaws on their own, as well as the most capable restricted model (Anthropic's Mythos) could in April 2026Partly: ASD guidance, no AI-specific SOCI duty
T9, H1 2027 to H1 2028, plausible (contested)A frontier lab can no longer rule out its own top bio thresholdNot covered: no Australian bio-AI evaluation
T11, H2 2027, plausibleAI agents run end-to-end intrusions against defended real-world networksPartly: ASD, Home Affairs
T17, 2028, possibleFirst frontier-scale training run hosted in AustraliaIn design: PM&C consultation closes 9 Oct 2026
Decisions to be made
The JSC's mandate covers AI's national-security dimension. Whether it examines frontier misuse in depth won't be clear until it reports on 30 Nov.Joint Select Committee on AI
As Australia Group chair, does Australia link AI design tools to synthesis screening and press for an AI-aware science review in the BWC?DFAT, Health, Home Affairs
Who owns bio/chem uplift evaluation in Australia? Does AISI's mandate extend to it before frontier models are deployed here?Office of AI, AISI — no current owner
Once AI that can find and exploit security flaws on its own is freely downloadable, what do SOCI obligations and patch tempo for critical infrastructure need to require?ASD, Home Affairs
Does National Security Committee of Cabinet fold AI-enabled bio/chem/cyber risk into existing frameworks?NSC of Cabinet — low public visibility
How does Australia secure its defenders' and evaluators' access to gated or export-controlled models, and is onshore hosting the lever?DFAT, ASD, Office of AI
Strategic & military stability
What's likely to happen technically
Baseline, June 2026The precedent stands: the US cut all foreign access to Anthropic's top models for 18 daysAustralia had no formal role
T8, H1 2027, likelyGovernment-gated, "trusted partner" access becomes the default for top US modelsNot covered: Australia is a taker
T13, 2027, plausibleAccess-based export controls on models used again, possibly against alliesNot covered
T14, 2027–28, plausibleAI decision support deepens in conventional and nuclear command and control; a US–China human-control deal is possible but track-two only so farNot covered
T15, 2027–28, plausibleAUKUS Pillar II AI and autonomy fielding expands beyond the first underwater-drone projectNot covered by civilian AI processes
Decisions to be made
Do civilian AI processes feed Defence policy planning at all? No formal channel exists.Defence, PM&C
AUKUS Pillar II AI decisions: should military AI be independently evaluated, and could the AISI–ASD model become an allied test-and-evaluation offer?Department of Defence, ASD — opaque timing, no public process
Do civilian outputs (RC, JSC) get referenced in Defence/national-security policy at all?Historically these tracks don't talk — exactly the gap the convening targets
How does Australia avoid being a pure taker when US decisions can cut allied access overnight, while keeping alliance trust?DFAT, Defence, ASD
Does Australia have an independent voice in allied AI strategic-stability dialogue? What can a non-nuclear ally hosting joint facilities credibly propose on AI and nuclear command and control, and what can it offer ASEAN and Pacific partners?DFAT / Defence, Five Eyes coordination
Timeline
Now – Dec 2026ToR lock-in, JSC reports
Jan – Jun 2027Standards legislation, RC hearings
Jul – Dec 2027RC reports, government response
202812–24 month horizon
Live processes (context)
SA Royal Commission began 1 Oct. Terms of reference cover the economic and societal opportunities and implications of AI in South Australia: productivity, social benefits and risks, state regulation, work, education and public services. Out of scope: data centres, national security and cyber security, financial market stability, critical national infrastructure, and IP and copyright.
PM&C consultation "Getting it right: Building AI infrastructure that works for Australia" closes 9 Oct: thresholds and compliance models for large data centres, and conditions for frontier training in Australia
DTA AI Review Committee (announced 22 June): non-binding advice on high-risk government AI use and on serious AI incidents after an agency has remediated. It covers the government's own AI use, not foreign agents acting on government systems.
Emergency taskforce (announced 24 Sept), led by PM&C with ASD, AISI, the Office of AI and other agencies. It is reviewing the security of government networks and the legal arrangements for incidents like this. An OpenAI agent got past access controls on Services Australia's Medicare statistics portal on 18 June and also reached AIHW, the Victorian Department of Health and NSW BOCSAR. OpenAI found it on 11 Aug and told Services Australia on 10 Sept. OpenAI's own Australian taskforce is due to report before year-end.
JSC final report due 30 Nov 2026 — likely before the convening. The convening becomes a response to its findings: what did it examine in these three domains, and what did it leave open for the government's response?
Convening: one day, Canberra — likely mid-Dec 2026 or early 2027; date and format under review
Mandatory Australian Standards for AI, replacing the voluntary approach; legislation due early 2027 (no exposure draft or named regulator yet). Large data centres must underwrite new power supply, pay connection costs, cut use when the grid needs it and minimise water use. No text-and-data-mining exception: Australian creative works can't be used for training without creators' control.
RC hearings run through this window; government drafts its response to the JSC
One-pager to government + convening output circulated
RC final report due 1 Jul 2027
Discussion report published within weeks of the convening — needs to reach decision makers before the RC reports on 1 Jul 2027
No scheduled process — open field