On 7 August, iTnews reported that the Australian Signals Directorate and the Australian Institute of Company Directors had jointly issued Frontier AI Cyber Threat Considerations for Boards of Directors, and that its first ask of a board is to assess the risk of relying on AI providers subject to foreign ownership, control or influence. The guidance is direct about the framing: boards should treat that ownership and control "as a cyber risk in its own right". Coming from the country's signals intelligence agency and the body that credentials Australian directors, in one document, that is not a throwaway line.
Most boards already have something they would call third-party AI oversight. It is usually a vendor register, and it answers a specific set of questions well: who do we contract with, what do they charge, what data do they hold, and which jurisdiction is it stored in. Those are procurement and privacy questions, and they were the right ones to ask when the exposure was data. ASD has asked a different question, and it is not on the contract. Who controls this provider, and whose law can compel them. iTnews notes that the recommendation follows a restriction order placed by the United States government in June on Anthropic's Mythos-class models, which is the whole argument in one event. No data moved. The capability simply stopped being available to anyone on the wrong side of the order.
The reason that distinction matters is that data residency has been sold to Australian boards as the answer to sovereignty for about three years, and it is a decoy. Your data can sit in a Sydney availability zone while the model weights, the control plane, the update pipeline, the safety and usage policy, and the ability to switch the whole thing off all sit somewhere else entirely, under a legal system in which your organisation has no standing and your board has no visibility. Residency tells you where the data rests. It tells you nothing about who can change, restrict, degrade or withdraw the capability your operations have quietly come to depend on.
And the dependency is now material without ever having been approved as material. The same guidance warns that vulnerability exploitation timelines are compressing "from days to hours", and that AI agents should hold only the "minimum access their duties require". Read those two points alongside the first and the shape of the problem is familiar: this is supplier concentration and operational resilience, two things boards have overseen for decades, attached to a dependency that arrived through a software licence rather than a capital approval, and so never went through the gate where a board would have priced it.
- Who ultimately owns and controls each AI provider we depend on, and which government could compel that entity to act in ways contrary to our interests?
- Which of our processes would stop, degrade materially, or fall out of compliance if a single AI provider were withdrawn, sanctioned or breached, and how long could we operate without it?
- Have we ever tested a substitution, or are we relying on the assumption that providers are interchangeable because the interfaces look interchangeable?
- Where an Australian supplier resells a foreign model, does our contract give us enforceable rights against the party that actually controls the capability, or only against the reseller sitting in front of it?
- What leading indicator would tell us that a critical AI provider's ownership, control or country risk had shifted, who is watching it, and at what threshold does it reach this board?
- The vendor register records the contracting entity, the fee and the data location, and nothing about the ultimate controlling entity. That is a procurement record being used as a risk record.
- Sovereignty is being answered with a data residency clause, and nobody has asked where the model weights, the control plane and the update pipeline actually sit.
- No AI provider appears on the critical supplier list, because that list was written before the dependency existed and has not been revisited since.
- Management describes providers as interchangeable but cannot point to one substitution that was actually attempted, or to a documented exit plan with a named owner and a recovery window.
- AI agents hold standing access to production systems that was granted for a pilot and has never been reviewed against what the task genuinely requires.
The upside is that this is a bounded piece of work, which is rare in AI governance. There is no transformation programme here: a rebuilt provider list, a criticality reassessment, and one substitution actually attempted rather than assumed. Boards that do it get something more useful than compliance comfort. Substitutable dependency prices better than captive dependency, so the exercise pays for itself in the next renewal negotiation, and it almost always surfaces two or three processes that quietly became single-provider without anyone deciding they should be. Being able to evidence a considered position on provider control will also make procurement, insurance and government tender conversations materially easier over the next two years.
The downside is that the obvious answer is the wrong one. Boards will reach for sovereign branding, and most sovereign offerings in this market are Australian-registered wrappers over the same handful of foreign model providers. Changing the logo on the invoice while control sits exactly where it always sat converts a live exposure into a documented illusion, and that is worse than doing nothing, because the board now believes it has acted. The second failure is quieter. Treated as an IT procurement matter, this decision settles two levels below the people accountable for whether the organisation can keep operating, and by then the dependency is contracted, embedded and expensive to unwind.
Do three things before the next risk committee cycle closes. First, ask for the AI provider list to be rebuilt around control rather than contract: for every provider, the ultimate controlling entity, the jurisdiction whose law reaches it, and whether an Australian reseller is sitting in front of a foreign model. Second, put the material ones onto the critical supplier register and give each an exit test with a named owner and a stated recovery window, then require that one substitution be genuinely attempted rather than asserted, because an untested exit plan is a document, not a control. Third, direct that every AI agent's standing access be re-approved against the minimum its task actually requires, with the review dated and minuted. Then resist the sovereign branding answer when it arrives, and it will arrive, because the question ASD asked is who controls the capability you now depend on, and an Australian logo on the invoice does not change that answer. A board that can say who is able to switch this off, and what happens on the day they do, has done the work. Everything short of that is paperwork.
Researched and drafted by Brad's agentic AI team. Edited and published by Brad Ferris.