The Other Side of the AI Story: Three Pressures Reshaping Public Sector IT Solutions Cyber and Governance
AI is rarely framed as a pressure on government, but for public sector technology leaders, it is fast becoming one of the defining forces in their operating environment.
Most of the writing about AI in the public sector focuses on the opportunity side of the ledger. Faster citizen services. Smarter back-office processes. Reduced manual load. Those benefits are real, and they are not the subject of this piece.
This piece looks at the other side of the same story. The side that public sector CIOs, CISOs, and risk leaders are spending an increasing share of their time on: the ways AI is adding pressure to environments that were already stretched. Three pressures, in particular, that together are reshaping what it means to deliver and govern technology in Australian government today.
Face one: AI is reshaping the threat surface
The Australian Signals Directorate’s Annual Cyber Threat Report 2024–25 is unambiguous: AI is being used by malicious actors to scale phishing, data analysis, and impersonation activity more efficiently than ever before. AI-enabled botnets drove a 280% year-on-year increase in DoS and DDoS incidents responded to by ASD’s ACSC. In a joint Five Eyes statement, ASD and its international counterparts urged leaders to “act now” to strengthen resilience, integrate cyber security into core strategy, and prepare for AI-augmented attacks as a default condition rather than an emerging one.
The global picture confirms the trajectory. AI-generated phishing has surged more than 1,200% since 2023, with one industry analysis finding that 82.6% of phishing emails now contain AI-generated content. AI-generated phishing achieves a 54% click-through rate, compared to roughly 12% for traditional phishing.
Deepfake-enabled social engineering is following the same curve. Modern voice-cloning tools can replicate an individual’s voice with around 85% accuracy from as little as 3–5 seconds of audio. Globally, deepfake video scams rose roughly 700% in 2025. In April 2025, the FBI issued a public alert warning that senior officials were being impersonated using AI-generated voice messages, and Australia has not been insulated. Coordinated voice-impersonation campaigns have already been used to breach Australian banks via spoofed vendor approvals.
In May 2026, ASD’s ACSC published new guidance on AI in cyber defence, addressing adversarial techniques including prompt injection, model evasion, and data poisoning. A separate joint advisory, co-authored by ASD, CISA, NSA, the UK NCSC, the Canadian Cyber Centre, and New Zealand NCSC-NZ, has been issued on the careful adoption of agentic AI services.
The line running through all of this is an asymmetry government has not had to operate inside before. The cost of mounting a convincing attack has collapsed while its effectiveness has lifted sharply. AI is no longer a niche risk category. It is becoming a default consideration in every threat model.
Face two: AI is reshaping the governance surface
Where the first face is external, the second is internal, and it is moving faster than most agencies can write policy to address it.
Global studies suggest that around 77% of employees share sensitive company data through ChatGPT and other AI tools, with roughly 18% of enterprise employees pasting data into GenAI tools and more than half of those paste events containing corporate information. Nearly 40% of files uploaded to AI tools contain personally identifiable or payment-card data. IBM’s 2025 breach reporting found that one in five organisations experienced a breach traced to shadow AI use, with high-shadow-AI organisations facing breach costs an average of US$670,000 higher than those with minimal exposure. A further 83% of organisations lack technical controls to detect or prevent confidential data being uploaded to AI platforms.
For government, the implications are obvious, and Australia has moved decisively on the policy side. The Office of the Australian Information Commissioner has published two AI-specific privacy guidelines covering the use of commercially available AI products and the development and training of generative AI models. The National AI Centre’s Guidance for AI Adoption (October 2025) sets out six essential practices for responsible AI governance, building on the Voluntary AI Safety Standard. The DTA’s updated Policy for the Responsible Use of AI in Government came into effect on 15 December 2025, and the APS AI Plan 2025, structured around Trust, People, and Tools, is being jointly implemented by the Department of Finance, the DTA, and the APSC. Chief AI Officers will be appointed across federal agencies through 2026.
The policy scaffold is in place. The pressure now sits in the gap between that scaffold and the everyday decisions staff make about what to paste into which tool. Policy on paper is not governance in practice, and the speed at which staff have adopted AI tools is outpacing the speed at which agencies can train them to use those tools safely.
Face three: AI is stacking a new workforce shortage on top of an old one
The public sector workforce gap pre-dates AI. Around 74% of government agencies were already reporting difficulty recruiting IT staff, and the APS faces a shortfall of more than 61,000 digital professionals over the next five years. AI is not relieving that pressure. It is intensifying it.
Recent surveys show that 53% of agencies cannot find staff to build and train AI models, and 79% of agencies with digital gaps identify cyber security as a critical shortage. Industry research suggests 44% of senior executives now cite the AI skills gap as the single biggest blocker to generative AI implementation. Against this, Australia produces only around 7,000 IT graduates annually, while the APS itself needs to roughly double its digital workforce by 2030.
The arithmetic is unforgiving. The threat curve is accelerating, the governance bar is rising, and the talent pool is not growing fast enough to staff either response at the pace either now demands.
Key findings: where the discipline lies
Read across all three faces, a pattern emerges. None of these pressures will be solved by AI tools themselves. They are being navigated, where they are being navigated well, by a small set of disciplines that have always mattered in public sector technology, applied now to a faster operating reality. Four of them stand out.
1. Identity is the new perimeter
When voice, video, and text can all be synthesised convincingly, the question of who is on the other end of a system matters more than ever. The agencies moving fastest are treating identity assurance, layered verification, and zero-trust principles as foundational rather than aspirational.
2. Governance has to live inside the work
Policy documents matter, but operational governance is what closes the shadow-AI gap. Clear classification of what data goes where. Sanctioned AI tooling that is governed by default rather than blocked by default. Audit trails. Privacy impact assessments before deployment, not after.
3. Capability has to be mobilised, not just hired
With the workforce shortfall stacking and the threat curve accelerating, agencies cannot hire their way out of either gap on the timeline available. Models such as Team-as-a-Service (TaaS), embedded specialist squads, and on-demand mobilisation of AI security, model assurance, and procurement expertise have become structural rather than optional.
4. Lived knowledge of government still matters most
The agencies operating well in this environment are not necessarily the ones with the most technology. They are the ones with partners who speak fluent procurement, fluent privacy, fluent risk, and fluent public sector reality, applied at the pace AI now demands.
For agencies, this is the hard news and the good news in one. AI is amplifying problems that were already complex. But the disciplines that respond to them are well understood, and the partners who have been operating in this environment for a long time tend to be the ones best placed to help apply them at the pace the moment now requires.
For more information about how The Services Company (TSC) supports state and federal government agencies in navigating these pressures, visit theservicescompany.com.
Sources
Australian Signals Directorate, Annual Cyber Threat Report 2024–25 and AI-related advisories (cyber.gov.au); Digital Transformation Agency, Policy for the Responsible Use of AI in Government and APS AI Plan 2025 (dta.gov.au, digital.gov.au); Office of the Australian Information Commissioner, Guidance on privacy and the use of commercially available AI products and Guidance on privacy and developing and training generative AI models (oaic.gov.au); Department of Industry, Science and Resources / National AI Centre, Voluntary AI Safety Standard and Guidance for AI Adoption (industry.gov.au); IBM Cost of a Data Breach Report 2025; Five Eyes joint statement on AI and cyber risk; FBI Internet Crime Complaint Center (IC3) public service announcement, May 2025; ACS Information Age, “Australian government facing digital talent shortfall” (2025); Future Skills Organisation workforce projections.