For the better part of two years, the phrase “AI and national security” has functioned in Canberra as a kind of shorthand for one country. Chinese models, Chinese chips, Chinese-owned apps and the fear that sensitive Australian data might quietly flow back to Beijing have dominated the risk register. That framing is neat, politically comfortable and, according to a pointed new argument in the Australian Financial Review, dangerously incomplete.
Writing in the masthead’s policy pages, the AFR makes the case that China is not the only artificial intelligence threat to Australia’s national security. The provocation is deliberate. Yes, the piece accepts, there are real reasons to be wary of powerful and untrustworthy systems built under an authoritarian government. But treating Chinese technology as the sole hazard, it argues, lets policymakers avoid a harder and less flattering question: what happens when a nation outsources the machinery of its economy, its bureaucracy and its critical infrastructure to foreign AI of any origin, allied or not?
The narrowing of a broad problem
The context here matters. Australia has spent the past year assembling the scaffolding of an AI policy state. A national framework has been floated, an Office of AI stood up, and debates over copyright, data centres and sovereign compute have moved from the fringe to the front bench. Running underneath all of it is a security instinct that keeps circling back to a single geopolitical rival.
That instinct is not irrational. Governments around the world have restricted Chinese-built applications on official devices, and defence and intelligence agencies have legitimate concerns about supply chains that touch a strategic competitor. The problem the AFR identifies is one of proportion. When the entire national security lens is trained on one flag, the far larger exposure sitting in plain sight, namely Australia’s near-total reliance on a handful of overseas platforms for the models, chips and cloud that will soon underpin everything from tax administration to the electricity grid, escapes serious scrutiny.
Put bluntly, a system does not have to be malicious to be a vulnerability. It only has to be indispensable and beyond your control.
Two ways to read the risk
There are broadly two camps in this argument, and both have a point.
The first treats provenance as the decisive factor. On this view, the nationality and governance of the entity behind a model is what determines trust. A system answerable to a liberal democracy and a mutual defence partner sits in a fundamentally different category to one answerable to Beijing, and Australia’s job is to sort technologies by that line and act accordingly. It is the logic that has driven app bans and procurement carve-outs, and it is intuitive to voters.
The second camp, which the AFR piece leans toward, treats dependence itself as the risk. In this reading the crucial question is not only “who built it” but “what happens to Australia if access is withdrawn, repriced, degraded or weaponised by whoever controls it”. Commercial terms can change overnight. Export controls imposed by a friendly capital can strand you just as effectively as sabotage by a hostile one. A cloud outage, a licensing dispute or a shift in another government’s foreign policy could all leave critical Australian services suddenly without the intelligence they have come to assume. Friendliness today is not a guarantee of availability tomorrow.
Neither camp is wrong so much as incomplete on its own. A serious security posture has to hold both ideas at once: some threats are about intent, and some are simply about leverage.
What it means for Australia
For a middle power with a small domestic technology base, the leverage problem is acute. Australia does not build frontier models, manufactures almost none of the advanced silicon that trains them, and hosts a data centre fleet that, while growing fast, is overwhelmingly tenanted by offshore hyperscalers. The sovereign AI push, the enthusiasm for local data centres in places such as Tailem Bend and the Macquarie Technology listing story all trace back to the same anxiety: the country consumes far more artificial intelligence than it makes, and consumption is not the same as control.
That gap turns an abstract security debate into a concrete one. If a state government runs citizen services on a foreign model, if a bank routes fraud detection through an overseas API, if the energy market operator leans on imported forecasting tools, then the resilience of those services is only as strong as Australia’s continued access to systems it neither owns nor governs. The threat there is not espionage. It is dependency, and dependency is agnostic about which country you are dependent on.
This is where the AFR framing sharpens the local policy conversation. It suggests that measures aimed squarely at Chinese technology, while defensible, address a slice of the problem and can create a false sense of security. A device that has been scrubbed of one country’s apps is no more sovereign if everything else on it still runs on infrastructure that can be switched off from abroad.
What’s next
The practical implications point in a few directions. One is diversification, so that no single vendor or jurisdiction becomes a single point of failure for essential services. Another is genuine sovereign capability in the parts of the stack that matter most, whether that is compute capacity on Australian soil, locally governed data or the skills to audit and, if necessary, run critical models without a foreign hand on the switch. A third is honest procurement rules that weigh resilience and exit options as heavily as price and performance, rather than treating cloud AI as a utility that will always be there.
None of that is cheap, and none of it fits comfortably into a single-adversary narrative that is easy to campaign on. That may be the uncomfortable core of the argument. The security question Australia most needs to answer about artificial intelligence is not only which countries it distrusts, but how much of its own future it is prepared to build on systems it cannot ultimately command. The Office of AI and the national framework now taking shape will be judged, in part, on whether they engage with that broader definition of the threat or settle for the narrower one.
Sources: Australian Financial Review (Policy).



















































