The Australian-American Memorial eagle column at Russell, Canberra, against a blue sky
Photo: Stuart Lindenmayer · CC BY-SA 4.0 · Wikimedia Commons
The Frontier Brief · Issue 008

ASD to boards: your AI vendor is a cyber risk.

The signals directorate and the AICD handed directors a frontier AI playbook. Foreign ownership, control and influence of AI providers is named a cyber risk in its own right.
Four days later OpenAI said it cannot rule out critical cyber capability in its next model, Astra, and slowed the release. That is a first.
China's open-weight leaders started attaching terms to free. Moonshot's licence requires a separate deal above US$20 million. Alibaba plans revenue sharing on the next Qwen.
Signal over noise · Twice weekly
Curated by Roger Hanney · Throughline Advisory, Sydney
Monday 10 August 2026
Days to hours
how far ASD says frontier AI could compress vulnerability discovery and exploitation timelines
board guidance with the AICD · 3 Aug
Critical
the top cyber capability tier OpenAI says it cannot rule out for its next model. A first for the lab
release slowed · 7 Aug
US$16.8bn
SpaceX and Tesla's initial commitment to the Terafab chip plant in Grimes County, Texas
filings flag up to $119bn · 6 Aug
1 billion
weekly ChatGPT users, per OpenAI, as GPT-5.6 rolls out and free text chats go unlimited
announced 6 Aug
The Brief in Five
Commonwealth Coat of Arms
ASD and the AICD tell boards to treat frontier AI as a standing cyber risk
Foreign ownership, control and influence of AI providers is a risk in its own right. Threshold questions for directors included. · 3 Aug, reported 6 to 7 Aug
ASX
ASX will use Amazon Bedrock to open its market data to AI consumption
Company announcements, today locked in PDFs, become AI-readable. Targets set for FY27, after core modernisation. · 6 Aug
OpenAI
OpenAI cannot rule out critical cyber capability in Astra and slows its release
The first time the lab has flagged its top Preparedness tier. Extra safeguards, external testers and government agencies involved. · 7 Aug
Alibaba
Alibaba plans revenue sharing for large commercial users of its next open Qwen
Terms could land within days; the percentage is not final. Free open weights acquire a price above a size threshold. · 7 Aug
Truth Social
Trump Media's first earnings call lands 7am Tuesday AEST
The first hard revenue number for Truth API's $60,000 to $100,000 a month feed (Issue 007). Q2 results drop before the call. · notice, 5 Aug
The Russell Offices defence precinct in Canberra
Photo: Nick-D · CC BY-SA 4.0 · Wikimedia Commons
The Lead · 3 to 7 August

The board paper assumed AI attackers. By Friday, OpenAI could not rule them out.

On Monday 3 August the Australian Signals Directorate and the Australian Institute of Company Directors published frontier AI threat guidance written for boards. Four days later, OpenAI told the public its next model might clear the exact bar the guidance warns about.

The guidance gives directors four jobs. Assess reliance on AI providers, treating foreign ownership, control and influence as a cyber risk in its own right. Review how frontier models change the organisation's security position. Counter an agentic, AI-powered threat environment. And lift governance of how the organisation uses the technology.

The threat picture is specific. ASD says vulnerability discovery and exploitation timelines could compress from days to hours, and that models can now run malicious activity with little to no human oversight.

The guidance and the evidence arrived in the same week

Five days in August 2026
Mon 3 AugASD and the AICD publish board guidance: frontier AI can compress attack timelines "from days to hours".
Tue 4 AugCISA orders US federal agencies to patch an actively exploited 9.8-severity hole in agent-builder Langflow within three days.
Thu 6 AugReuters reports lab agents breaching test containment. The ASD guidance reaches the Australian trade press.
Fri 7 AugOpenAI: "we cannot rule out critical cyber capabilities" in Astra. Release slowed, safeguards raised.
The dependency question

Nearly every frontier lab is US-headquartered. NAB said last week it will use US-made models, citing their cyber and copyright standards (Issue 007, background). ASD's point cuts deeper: the dependency itself now belongs on the risk register, whoever the vendor is. The Prime Minister said it plainly in July: "If we are always dependent on someone else, somewhere else, we will always be vulnerable."

Why it matters here. This is a Commonwealth agency handing boards a defensible artefact. Table it at the next risk committee, answer its threshold questions on the record, and note where each AI vendor's control sits.

Australia

The AI gateway becomes the control room: Sportsbet builds it, ASX opens the data.

Sportsbet has put an enterprise AI gateway into production, routing its LLM traffic, agent tool calls and AI workloads through one control plane on AWS, built with TrueFoundry.

The gateway enforces policy in parallel with model calls, without adding latency. It gives the company usage, token consumption and cost attribution per application and per team. First workloads through it: a documentation agent wired into Jira, and coding assistant traffic.

"The hard part was never the pilot; it's turning AI into a core capability that runs the business at scale."Niall Keating, General Manager of Data and AI, Sportsbet · iTnews, 7 Aug 2026

The same week, ASX set FY27 goals for AI on Amazon Bedrock. Three use cases: market data distribution built for AI consumption, company announcements freed from PDF for AI analysis, and internal data access. CIO Tim Whiteley: "The old market data feeds won't work the same to support AI consumption."

1 gateway
Sportsbet's single control plane for LLM, agent and AI traffic, with per-team cost attribution
FY27
when ASX targets AI-driven access to market data, after core modernisation completes
10 Dec 2026
automated-decision transparency obligation commences under APP 1 (background, dated)

Why it matters here. The ASD guidance asks boards who is watching their AI. A gateway is the operational answer: one place where guardrails, spend and visibility are enforceable. Expect the pattern in regulated stacks well before the December transparency obligation.

Lake Ohau and the surrounding Mackenzie Basin mountains, New Zealand
Photo: Wildman NZ · CC BY-SA 4.0 · Wikimedia Commons
Closer to Home · ANZ + APAC

New Zealand's data-centre debate now has two named towns.

Invest New Zealand confirmed Ōhau and Twizel, in Canterbury's Mackenzie Basin, as candidate sites for high-energy data centres on Friday. The selection criteria: existing grid capacity, fibre backhaul and renewable development potential.

The response was immediate. A public meeting is set for this Wednesday at the Twizel Events Centre. A Stop Data Centres NZ group has passed 13,000 members since June, and a petition seeks legislated restrictions. Prime Minister Christopher Luxon backs the buildout: data centres "will create jobs, will create opportunities", with "sensible rules" to come first.

The candidate sites sit inside dark-sky tourism country

Original graphic: Throughline Advisory · site locations approximate
Twizel Ōhau Mackenzie Basin: International Dark Sky Reserve, hydro lakes, tourism economy South Island
Both towns sit on the Waitaki hydro scheme, which is what makes them candidates. The same landscape underwrites a dark-sky and alpine tourism economy, which is what makes them contested.

China. Apple published a guide on Saturday letting Mac users in mainland China connect Alibaba's Qwen to Siri and Writing Tools, on macOS 26.6 or later. Alibaba cannot train on user material, per the guide. Context from the same report: Mac shipments in China fell 9% year on year in the March quarter. Localising the model is the price of the market.

Japan, Korea, India, Singapore: nothing else cleared the freshness bar this issue.

Why it matters here. Australia's buildout got a draft federal rulebook first (Issue 007). New Zealand is running the same debate with no equivalent instrument, town by town. Anyone modelling trans-Tasman capacity should price consenting risk accordingly.

Sources: 1News, 7 Aug 2026 · RNZ, 3 Aug (background) · Reuters via Yahoo, 8 Aug (single origin, syndicated).
The Pioneer Building in San Francisco, OpenAI's headquarters
Photo: HaeB · CC BY-SA 4.0 · Wikimedia Commons
Risk, Regulation & Law · AU lens

OpenAI reached its own red line and kept the model inside.

On Friday OpenAI said its unreleased model Astra performs well enough that "we cannot rule out Critical capability level at this time" for cyber operations. It is the first time the lab has flagged the top tier of its Preparedness Framework for any model.

Critical means attacks that need no human

OpenAI's published threshold, in its own words
Find and weaponise
"identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention"
Plan and run
"devise and execute end-to-end novel strategies for cyberattacks against hardened targets given only a high level desired goal"

The response: development work that does not meet raised security requirements is paused. Astra runs in isolated environments with restricted network and tool access, hardened weight protection and monitoring across agentic uses. External testers, including government agencies, are involved before any release.

The AU lens. The ASD board guidance published four days earlier asks boards to review exactly this: how frontier models change their security position. The gap it leaves is procurement. US federal testing plans reportedly exempt open-weight models (Issue 007, background), so top-end capability testing today is voluntary lab policy plus whatever diligence the deployer does.

Why it matters here. Ask each model vendor two questions in writing. Which capability framework covers the model we are buying, and what happens to our deployment when a threshold trips.

The Federal Reserve Bank of New York building
Photo: Kidfly182 · CC BY 4.0 · Wikimedia Commons
Money & Markets

The Fed starts asking the stability question about AI capex.

Reuters reported Thursday that AI infrastructure spending is now on Federal Reserve officials' financial-stability radar. The verdicts differ. New York Fed president John Williams: "I don't see this as a bubble kind of situation." Kansas City's Jeff Schmid asks whether the industry is becoming "another too big to fail". San Francisco's Mary Daly says the pace could "easily" be called "very worrisome", while noting many commitments are still announcements rather than steel.

Smaller than the housing boom. Accelerating faster.

Investment as a share of US GDP · scale starts at zero
Housing at its 2005 peak
6.6%
Data-centre buildout, 2026
<3.3%
The data-centre bar is an upper bound: Reuters puts the buildout at less than half housing's 6.6% peak. The officials' concern is the growth rate relative to GDP, which is accelerating faster than housing did before 2008.
Tonight's number

Trump Media's first-ever earnings call runs at 5pm Monday US eastern time, 7am Tuesday AEST, with Q2 results filed before it. It brings the first revenue disclosure for Truth API, the millisecond feed of the President's posts covered in Issue 007.

Why it matters here. Williams saying no bubble and Daly saying worrisome in the same news cycle is the honest state of the evidence. Boards approving AI capex should minute both readings rather than pick one.

Alibaba Group headquarters campus in Hangzhou
Photo: Thomas LOMBARD · CC BY-SA 3.0 · Wikimedia Commons
Cost & Economics

Open weights stay free until you make US$20 million.

The free era of Chinese open weights is acquiring fine print. Alibaba plans revenue sharing for large commercial users of its next open-weight Qwen model run outside Alibaba Cloud, Reuters reported Friday, citing IT Home. The percentage is not final; terms could land within days.

Moonshot wrote the template two weeks ago (28 July, background, dated). The Kimi K3 licence permits copying, modification and sale. Above US$20 million in aggregate revenue over any 12 months from running it as a service, a separate agreement with Moonshot is required. Products past 100 million monthly active users, or US$20 million in monthly revenue, must display the Kimi K3 name prominently.

Where free ends, as written into the licences

Published thresholds for Chinese open-weight models
US$20M
12-month service revenue on Kimi K3 that triggers a required separate agreement with Moonshot
100M MAU
the point where Kimi K3 branding becomes mandatory on your product
% TBD
Alibaba's planned revenue share on the next open Qwen, outside Alibaba Cloud. Not finalised

The silicon side kept moving too. SpaceX and Tesla committed an initial US$16.8 billion to the Terafab plant in Grimes County, Texas, for edge and inference chips, with filings flagging up to US$119 billion across phases.

Why it matters here. Issue 007 reported Chinese open weights above 30% of OpenRouter traffic on price. Licence terms are now part of that price. A build-versus-buy model needs a licensing line item, re-read at every model release, with the trigger thresholds mapped against your own revenue.

Aerial photograph of the Pentagon
Photo: David (Flickr) · CC BY 2.0 · Wikimedia Commons
Enterprise & Deployment

Agents clear IL5 at the Pentagon. The agent toolchain ships a 9.8.

Salesforce's Agentforce 360 was authorised at Impact Level 5 for the US Department of War, its Missionforce unit announced Wednesday. That clears autonomous agents to handle controlled unclassified national-security data, starting with logistics, recruit onboarding and administrative work; Army Human Resources Command is an early user.

The same week showed the other side of the ledger. CISA added Langflow's CVE-2026-9198 to its Known Exploited Vulnerabilities catalogue on Monday: a 9.8-severity code injection giving unauthenticated remote code execution on default deployments of the agent-building platform. The patch has existed since July. Federal agencies got three days.

650
exploitation attempts against the Langflow flaw since 6 July, from 244 IPs across 41 countries, per KEVIntel telemetry
9.8
CVSS severity of CVE-2026-9198. Fixed in Langflow 1.10.1, released July
3 to 7x
less CPU and memory than Chromium for agent browsing tasks, per Cloudflare's new Kitesurf browser. Free in beta

Check Point separately published a SQL-injection-to-RCE chain in LangGraph's checkpointer, part of a wider run of findings across agent frameworks. And Cloudflare shipped Kitesurf, an agent-first browser that runs on Workers rather than on a full Chromium stack.

Why it matters here. The frameworks your agents are built on are now the attack surface, and they are being exploited faster than they are being patched. Put agent-framework patch cadence inside the security review the ASD guidance asks boards to run.

The Long View
"If we use, to achieve our purposes, a mechanical agency with whose operation we cannot efficiently interfere once we have started it... then we had better be quite sure that the purpose put into the machine is the purpose which we really desire and not merely a colorful imitation of it."
Norbert Wiener · Mathematician, founder of cybernetics · "Some Moral and Technical Consequences of Automation" · Science 131(3410), 6 May 1960, pp. 1355-1358 · located and checked word for word in the journal text
OpenAI slowed Astra because it cannot yet be sure what capability it has built. Wiener published the operating principle 66 years ago, in the journal every lab still cites.
The Skill · one to learn this issue

Prompt injection: learn the attack your chatbot will meet first.

Use case. You are putting an AI assistant in front of customers, or giving an agent access to tools and data. Injection is how an attacker turns it against you with words alone, and it sits behind most of this issue's security stories.

Working with the skillYou can red-team your own bot before launch, write testable guardrail requirements into vendor contracts, and show a board a live failure instead of an abstraction.
Working without itNothing looks broken until production. Injection needs no code, so the gap is invisible in a demo. You also inherit whatever your vendor's guardrails miss, untested.

Tips. Treat every piece of outside text your model reads (emails, web pages, PDFs) as untrusted input. Keep instructions and data separate in your prompts. Give agents the least tool access that works. Try to break your own assistant before an attacker does.

Learn more, free, no paywall: Gandalf by Lakera, a hands-on game that teaches injection in about 20 minutes · OWASP GenAI: LLM01 Prompt Injection, the reference guide.

One thing to act on

Table the ASD guidance this month.

Download Frontier AI cyber threat considerations for boards of directors, put it on the next board or risk-committee agenda, and answer its threshold questions on the record. Add one procurement question beside it: who owns, controls and influences each AI provider you depend on, and what is your exit if that answer changes.