
Australians received two security assessments on separate days this week but need to see them as directly related. The first was a rare joint statement from the Five Eyes cybersecurity agency heads on digital threats and resilience in an era of AI. The second was the most operationally candid Annual Threat Assessment yet delivered by Director-General of Security Mike Burgess – focused on threats to social cohesion and national resilience.
Media coverage is treating them as separate stories: one a corporate governance advisory, the other a terrorism and espionage briefing shadowed by the grief of Bondi. But leaving any gap between them is precisely where strategic exposure lives.
That’s because the separation between offline and online has collapsed: virtual vulnerabilities now produce real-world consequences. The timing and openness of the assessments reflect a growing view of democracies that public safety and social cohesion cannot be managed by obscuring the nature of the threats. Both are designed not to merely inform but to shape a collective response – from government, industry and civil society.
On Monday, the Five Eyes cybersecurity chiefs warned that AI was no longer a future risk vector. Frontier models are already compressing the window between vulnerability discovery and active exploitation from weeks to days, or even hours. The timeline, they said, was months, not years. The advisory was directed at boards and executives: cyber resilience isn’t an IT issue, it’s central to operational continuity and market trust. ASPI has argued in these pages that phrases such as ‘secure by design’ and ‘don’t trust, verify’ remain aspirations without the frameworks that give them teeth – and that without those frameworks, slogans don’t alone become standards.
On Wednesday evening, Burgess opened his seventh annual threat assessment by acknowledging the grief surrounding the December attack on Jews at Bondi – then contextualised it. What followed was a present-tense picture of a security environment his 2025 assessment had forecast for 2030: a complex, challenging and changing security environment becoming more dynamic, more diverse and more degraded. Burgess made clear the concurrent, cascading and compounding convergence of these conditions is what is testing Australia’s capacity to respond – not at some point in the future, but now.
The instinct will be to read these two assessments as belonging to separate registers. But what Five Eyes cybersecurity heads described – AI accelerating the offensive toolkit – is precisely the capability uplift that makes everything Burgess confirmed qualitatively more dangerous. They weren’t giving parallel warnings; they were completing each other’s sentences.
Burgess illustrated the compounding logic through a single working week randomly drawn from his operational diary. His teams were managing simultaneously: a decade-long foreign regime campaign to coerce an Australian resident into repatriation through threats against overseas relatives; Iranian-directed terrorism against Jewish Australians, orchestrated through the Islamic Revolutionary Guard Corps’ Qods Force networks via criminal proxies; active foreign intelligence collection against AUKUS through a fabricated consulting persona – disrupted when ASIO borrowed the target’s phone and rang the spy directly; and nation-state hackers who had compromised the network of an Australian critical infrastructure provider, mapping the system to cripple it at a time of their choosing. The scale of that activity, led by one nation state in particular, is in Burgess’s words difficult to overstate.
This is what concurrent, cascading and compounding threats look like in practice. Not a theoretical taxonomy. A documented working week.
The espionage operation that harvests credentials enables the infrastructure access that enables the sabotage positioning. The foreign interference campaign that erodes institutional trust creates the social environment in which politically motivated violence takes root. The criminal proxy model the IRGC used to direct attacks against Jewish Australians was, structurally, the same model Burgess warned in 2025 could be increasingly deployed for sabotage. These pathways are documented, operational and active – and Burgess confirmed that counter-terrorism and counter-intelligence teams routinely swapped leads mid-operation as traditional distinctions broke down in real time.
AI does not add new pieces to this architecture. It changes the dynamics between them. It compresses the cycle from access to exploitation, automates reconnaissance and vulnerability discovery, scales the influence operations already degrading the social fabric Bondi so painfully exposed, and lowers the expertise threshold required to act on pre-positioned access inside Australia’s energy, communications and defence-adjacent networks. The gap between intent and capability – between access already gained and sabotage that could be activated – is narrowing. That narrowing is the joint warning both assessments are issuing.
The threat environment Burgess described does not respect the boundaries between critical infrastructure protection, cybersecurity uplift, counter-espionage, counter-foreign-interference, counter-terrorism and AI governance. Each domain is managed with genuine seriousness in isolation. But cascading threats require integrated governance, and compounding threats demand frameworks that account for the interactions between categories – not each one managed in sequence, within its own domain. The rapid pace of frontier AI development means cyber risk assumptions can become outdated in months. That now applies equally to governance assumptions more broadly.
The question both assessments pose is not whether Australia takes these threats seriously in their separate registers or whether we have the ability to respond. It plainly does, and can. The question is whether the architecture of response – across the boardroom as much as the cabinet table – is integrated enough to match a threat environment that operates deliberately, and with increasing sophistication, across all of them at once.
Burgess closed with a line that should be read as direction, not rhetoric: when Australian critical infrastructure is disrupted, we will be shocked – but we should not be surprised. The two assessments this week explained precisely why. The measure of Australia’s response will not be whether we absorbed each warning. It will be whether we understood they were the same one.