For the better part of two years, the debate about artificial intelligence in Canberra has revolved around a single question: what rules should govern the technology? The Albanese Government has run consultations, floated mandatory guardrails for high-risk uses, published a voluntary safety standard and prodded industry to think harder about accountability. Now a fresh argument is gaining traction, and it reframes the whole conversation. Rules, the thinking goes, are only the starting line. The harder work is making the country resilient to what AI does once it is woven through banks, hospitals, power grids, government services and the everyday tools people use without a second thought.
That is the case put by Independent Australia, which argues that AI resilience should be the next step after the Government’s regulatory framework. The essay’s core point is deceptively simple. A rulebook tells organisations what they must not do. It does not, on its own, prepare a society for the moment an AI system behaves in ways nobody predicted, whether that is a model quietly making biased decisions at scale, a critical service falling over because an automated pipeline broke, or a wave of synthetic content designed to deceive voters and consumers. Resilience is about absorbing those shocks, recovering quickly and learning from them, rather than assuming they can be legislated away.
From compliance to survivability
The distinction matters because it changes who is responsible and how success is measured. Regulation tends to be judged by compliance, whether a company ticked the right boxes, filed the right risk assessment and disclosed the right things. Resilience is judged by outcomes under stress, whether the lights stay on, whether a hospital can still triage patients when an AI triage tool is taken offline, whether an agency can spot and reverse an automated decision that went wrong. It is closer in spirit to how Australia already thinks about cyber security and natural disasters, where the assumption is not that failure can be prevented entirely, but that the system must be built to bend without breaking.
Australia has spent recent years developing the regulatory scaffolding for this. The Department of Industry, Science and Resources ran the Safe and Responsible AI in Australia consultation, which fed into proposals for mandatory guardrails in high-risk settings alongside a voluntary AI safety standard for businesses that want to move sooner. Those measures lean heavily on transparency, testing, human oversight and record-keeping. They are sensible foundations. The resilience argument does not dismiss them, but it insists they are incomplete, because a framework that governs how AI is built and deployed says very little about how the nation copes when a deployed system misfires.
Two ways to read the gap
There are competing views on whether that gap is real or overstated. One camp, broadly aligned with the resilience thesis, warns that Australia is repeating an old mistake by treating a new general-purpose technology as a compliance problem. On this reading, the risk is not a single dramatic robot-gone-rogue event but a slow accumulation of dependencies, where more and more essential functions quietly rely on models few people fully understand, until a failure in one corner cascades through others. The remedy they favour is structural: stress-testing critical systems, mandating fallback processes that work without AI, investing in the skills to audit and interrogate models, and treating AI outages the way the finance and energy sectors already treat operational risk.
A more sceptical camp counters that resilience risks becoming a buzzword that lets governments look busy without committing to enforceable rules. From this angle, the danger is that talk of building resilience becomes a soft alternative to hard regulation, giving large technology companies room to argue that markets and voluntary standards will sort out safety on their own. Industry groups such as the Tech Council of Australia have consistently pushed for light-touch, principles-based approaches that avoid locking in prescriptive rules before the technology settles. Consumer advocates and unions, by contrast, have warned that voluntary measures leave workers and the public exposed. Resilience, in that contest, can be read either as a genuine next frontier or as a convenient way to defer the harder decisions.
Why this lands hard in Australia
The stakes are unusually concrete here. Australia is a medium-sized economy that imports most of its frontier AI from a handful of overseas firms, which means the country has limited control over the systems it increasingly depends on. Sovereignty concerns already run through debates about data centres, cloud infrastructure and defence, and resilience folds neatly into that same anxiety. If a critical model is trained, hosted and updated offshore, a domestic rulebook can only do so much when something goes wrong at the source. That is a very different position from the United States or the European Union, both of which have far more leverage over the companies building the technology.
There is also a workforce dimension. Australia has been candid about its shortage of AI and cyber skills, and resilience is skill-intensive by nature. It requires people who can probe a model, understand its failure modes and design the manual backstops that take over when automation fails. Without that capability spread across the public service, critical infrastructure operators and the broader economy, a resilience strategy risks being a policy on paper. The same gap that complicates regulation, a thin bench of expertise, complicates resilience even more, because resilience cannot be outsourced to a compliance form.
For government, the practical challenge is coordination. Resilience does not sit inside a single portfolio. It touches industry, home affairs and cyber security, health, energy, finance and defence, and it overlaps with the critical infrastructure protection regime already in place. Building it would mean threading AI-specific thinking through frameworks that were not designed with machine learning in mind, and doing so without smothering the productivity gains the Government keeps promising the technology will deliver.
What comes next
The immediate question is whether resilience makes it from opinion pages into policy design. The Government has signalled that mandatory guardrails for high-risk AI are still on the table, and any move in that direction would be the natural place to bake in resilience obligations, from stress-testing to mandated human fallbacks in essential services. Watch too for how the critical infrastructure rules evolve, since that regime is the most obvious vehicle for treating AI failures as national risks rather than private ones. The broader test, though, is cultural. Australia has become comfortable talking about AI as an opportunity to be seized and a risk to be regulated. The resilience argument asks it to add a third, less comfortable idea: that failure is inevitable, and the real measure of good policy is how well the country recovers when it happens.
Sources: Independent Australia.


















































