Australian organisations are pouring artificial intelligence into everything from call centres to loan approvals, yet the security thinking behind those rollouts has struggled to keep pace. A widely shared piece in the Australian Cyber Security Magazine sets out a useful way of thinking about the problem: that a serious AI security strategy has to work across five distinct layers of risk, not one. Miss a layer, the argument goes, and the whole system is exposed no matter how strong the others look.
The framing matters because a lot of corporate security still treats AI as if it were just another application to be patched and firewalled. It is not. An AI system carries risks that traditional software does not, and those risks stack on top of one another rather than sitting neatly in a single box a security team can guard.
What the five layers actually cover
The first layer is the data that trains and feeds a model. If that data is poisoned, biased or quietly leaking sensitive records, every decision downstream inherits the flaw. The second is the model itself, which can be stolen, reverse-engineered or manipulated into behaving in ways its builders never intended. The third is the infrastructure the model runs on, the same cloud and compute layer that has always been a target, now holding far more valuable assets.
The fourth layer is the application and interface that sits between the model and the user, where prompt injection and manipulation attacks have become the fashionable new intrusion method. The fifth is the human layer, covering the staff who use these tools, the access they hold and the mistakes they make. Read together, the layers describe a chain, and the point of the framework is that attackers only need one weak link.
None of these ideas is exotic on its own. What the piece does well is insist they be considered as a single system. A business can spend heavily on securing its cloud infrastructure and still be undone by an employee pasting confidential client data into a public chatbot, or by a model trained on records it was never cleared to use.
Two ways of reading it
Security practitioners tend to welcome this kind of layered map because it gives them a checklist to argue for budget and to structure testing. It turns a vague board-level anxiety about AI into something concrete that can be audited, and it makes clear that responsibility cannot sit with one team alone. Data governance, machine learning engineering, cloud operations and staff training all own a piece of the problem.
There is a counter-view worth airing, and it is not that the layers are wrong. It is that frameworks like this can lull organisations into a false sense of completeness. Ticking five boxes is not the same as being secure, and the threat landscape for AI is moving faster than any static model of it can capture. Attack techniques that barely existed two years ago, such as sophisticated prompt injection and model extraction, are now routine. A five-layer map is a snapshot, and the risk is that businesses treat it as a finished job rather than a starting point for continuous testing. The more honest reading is that the framework is a way to organise thinking, not a guarantee, and it needs to be paired with red-teaming and monitoring that assume the picture will keep changing.
Why this lands hard in Australia
The Australian context sharpens all of this. Local enterprises have been unusually quick to adopt generative AI, and the country’s banks, insurers and health providers are among the most enthusiastic users of automated decision-making anywhere. That enthusiasm runs headlong into one of the strictest incoming regulatory environments in the region.
The Privacy Act reforms passed in late 2024 tightened the rules on automated decisions and on how personal information can be handled, and the federal government has signalled a move toward mandatory guardrails for AI in high-risk settings. The Australian Signals Directorate and its Australian Cyber Security Centre have repeatedly warned that AI expands the attack surface for exactly the kind of critical infrastructure the country is trying to protect. A layered view of risk maps neatly onto those obligations, because a regulator asking how a bank secured its lending model will want to know about the data, the model, the infrastructure and the people, not just the firewall.
There is a skills dimension too. Australia already has a documented cyber security workforce shortage, and AI security demands a rarer blend still, people who understand both machine learning and adversarial defence. Most organisations do not have that capability in house, which pushes them toward external providers and cloud platforms, and that in turn deepens the very infrastructure and supply-chain dependencies the third layer of the framework warns about. The country’s push for sovereign AI capability, from local model builders to domestic data centres, is partly an attempt to keep those dependencies on home soil.
What comes next
For boards and chief information security officers, the practical takeaway is not to adopt one particular framework but to stop treating AI security as a bolt-on. The organisations that fare best will be the ones that build security into AI projects from the design stage, run continuous adversarial testing rather than one-off audits, and make plain who owns each layer of risk before an incident forces the question.
Expect Australian regulators to keep tightening expectations through 2026, and expect the first high-profile AI security failure, whether a leaked model, a poisoned dataset or a manipulated chatbot, to concentrate minds far more than any framework can. The value of a layered map is that it lets an organisation find its weak link before an attacker does. The businesses still treating AI as ordinary software are the ones most likely to learn the difference the hard way.
Sources: Australian Cyber Security Magazine.


















































