IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
Huntress urges access to frontier AI for cyber defenders

Huntress urges access to frontier AI for cyber defenders

Wed, 23rd Sep 2026 (Today)
Mara Sugue
MARA SUGUE News Editor

Huntress has urged Australia to give trusted cyber defenders controlled access to frontier AI models, arguing the issue has become more urgent amid debate over AI guardrails and reports that Google's AI breached three companies during testing.

Reece Appleton, Regional Director APAC at Huntress, said access to advanced models should not be limited to government agencies if Australia wants local defenders to understand how criminals could misuse the technology.

His comments come as policymakers consider tighter oversight of advanced AI systems and security teams assess what recent testing involving Google's Gemini model reveals about the changing nature of cyber risk.

Appleton argued that the main danger lies not in autonomous machine intent, but in AI lowering the skill threshold for common forms of cybercrime. That, he said, could allow less experienced attackers to automate reconnaissance, produce more convincing local phishing attempts, and create usable exploits more quickly.

"We support the call for Australia to secure early access to frontier AI models as part of any deal to support local AI infrastructure. But that access cannot stop with government agencies. Trusted Australian security researchers and frontline cyber teams also need controlled access to test how these models can be abused and build detections before those techniques appear in live attacks. You cannot defend against an adversary you have never studied.

"The real threat is not sentient AI deciding to attack us. It is accessibility: AI giving less-skilled criminals the ability to automate reconnaissance, create convincing localised phishing and develop working exploits faster and at greater scale. Criminal groups will not wait for international standards, procurement processes or Australian policy. If access is restricted locally, we are not slowing attackers down; we are limiting the Australian defenders trying to understand and counter them.

"That leaves small and mid-market businesses particularly exposed. Many have no dedicated security team and cannot afford for defenders to understand these capabilities only after an attack. Guardrails matter, but they will only work if paired with practical testing, visibility and response. Australia's cyber capability depends on people with hands-on experience of frontier AI, not simply the infrastructure to host it."

The comments highlight a growing tension in the AI policy debate. Governments want safeguards around the most advanced systems, while security practitioners argue that overly tight restrictions could leave defenders with less insight into the same tools attackers may exploit.

That gap could be especially acute for smaller businesses. Many small and mid-market organisations lack dedicated security staff and may be less able to absorb the consequences of a breach if AI makes attacks cheaper, faster and more frequent.

Known Methods

Justin Allen, Head of Security Operations Centre, APAC at Huntress, said the reported Google testing did not show a new form of cyberattack. Instead, he said, it demonstrated how AI can link familiar steps such as identifying exposed credentials and guessing passwords.

That distinction matters because it suggests core security controls remain relevant even as attack execution becomes more automated. In Allen's view, the significance lies in the speed and scale at which standard intrusion techniques can now be deployed.

"The headline is that Google's AI hacked three companies. The important detail is that it found credentials exposed online and guessed passwords. There was no zero day or novel technique here. It used familiar attack methods.

"What is genuinely new is that the model chained those steps together autonomously after gaining unintended access to the internet. That matters because of speed and scale, not because AI has suddenly invented a new class of attack. AI is stripping the cost and patience out of attacks we already see every day. Reconnaissance that once took an operator a week can now take minutes, bringing organisations that were previously beneath an attacker's attention into scope.

"The defensive fundamentals have not changed. MFA, least privilege, patching and defence in depth still matter. But organisations also need to invest in detecting when those controls fail and responding quickly. If we accept that a breach is a matter of when, not if, the key question is not simply how high the walls are. It is how quickly you know someone is inside and what you do in the first hour afterwards."

Policy Balance

Both comments point to a broader shift in how the industry is framing AI-related cyber risk. Rather than treating advanced models as the source of entirely new attack categories, security teams are increasingly focused on how the technology compresses time, reduces labour and broadens the pool of potential attackers.

That framing also has implications for regulation. If the main impact of frontier AI is to industrialise existing criminal tradecraft, policymakers may need to balance restrictions with mechanisms that allow trusted researchers and defenders to test models under controlled conditions.

For companies, the message is less about replacing current cyber practices and more about strengthening them. Multi-factor authentication, privilege controls and patch management remain central, but they may no longer be enough on their own if automated attacks can move from reconnaissance to compromise far more quickly.

Security operations, detection tooling and incident response planning therefore become more important in an environment where attackers can test more targets with less effort. Businesses that previously sat below the threshold of attacker interest may also face greater exposure if AI reduces the cost of pursuing them.

Allen said the critical issue is how quickly organisations can identify and contain intrusions once preventive layers fail. "If we accept that a breach is a matter of when, not if, the key question is not simply how high the walls are. It is how quickly you know someone is inside and what you do in the first hour afterwards."