In May 2026 the ACSC published a document called Opportunities for AI in cyber defence, co-sealed by its counterparts in Canada, New Zealand, and the United Kingdom, and it quietly updated it again on 12 August. Most coverage read it as AI guidance. That is the less interesting reading.
The more useful one: this is the first substantial guidance the ASD has published since announcing the retirement of the Essential Eight, and it is not organised around the eight controls at all. It is built entirely on the Information Security Manual’s six functions: Govern, Identify, Protect, Detect, Respond, and Recover. The Essentials series that replaces the Essential Eight is grounded in the same ISM. If you want to know what Australian cyber guidance looks like after the Essential Eight, you are looking at it.
The guidance is aimed at security leaders and answers a question most businesses are already wrestling with: where can AI genuinely strengthen cyber defence, and how do you adopt it without creating new problems? It covers the full spectrum, from AI features embedded in security tools through to frontier models, and it gives agentic AI its own treatment: systems that plan, decide, and act towards a goal rather than answering one prompt at a time.
It is blunt about why this matters now. Attackers are using AI to automate reconnaissance, build tooling, and compress the gap between a vulnerability being discovered and being exploited, which leaves defenders less time to respond. The document’s position is that defence has to speed up to match, with AI handling scale and humans keeping judgement. We made the same argument in our piece on the ASD’s AI threat warning; this guidance is the constructive half of that story.
Structure is strategy in government guidance. The Essential Eight framed security as eight specific mitigations with a maturity ladder. This document frames it as six functions with AI applied inside each. That is the same ISM skeleton the ASD says the Essentials series will hang off, which makes this a preview of how the replacement thinks.
| ISM function | Where the guidance says AI helps |
|---|---|
| Govern | Spotting inconsistent risk decisions, analysing supply chain exposure, policy interpretation, prioritising by risk |
| Identify | Finding unmonitored assets, prioritising patching by real exploitability, chaining low-severity weaknesses into attack paths |
| Protect | Prioritising hardening, catching excessive permissions and privilege creep, scanning code for flaws pattern-based tools miss |
| Detect | Triaging alerts across identity, endpoint, network, and cloud telemetry, separating genuine threats from noise |
| Respond | Correlating alerts and forensic artefacts into a coherent incident picture, running response playbooks at machine speed with human approval on high-impact calls |
| Recover | Planning restoration order, validating systems against known baselines before they come back online |
Notice what that table describes. It is not a compliance checklist. It is an operating model for a security programme, which is precisely the shift the ASD flagged when it said the Essentials series would be prioritised, threat-informed mitigations rather than a fixed control list.
The guidance dedicates real space to agentic AI, both as a defensive capability and as a risk to be governed: human approval for high-impact actions, sandboxing, least privilege for agents, and audit trails on everything an AI system touches. The ASD has separately flagged agentic AI as a likely chapter of the Essentials series, for the same reasons: autonomous agents on a network raise identity, access, and prompt-injection problems that conventional controls were never designed to handle.
This is territory we operate in daily. Our security operations already run the model the guidance describes, an agentic SOC where AI handles correlation and triage at machine speed and humans hold the decisions that matter. Reading a Five Eyes document formally endorse that architecture is validating, and slightly surreal.
Nothing here weakens the case for finishing your Essential Eight uplift. The guidance is explicit that AI supplements strong fundamentals rather than replacing them, and it names the Essential Eight as the baseline to build on. Patching, MFA, application control, and backups are the raw material the six functions operate on.
What it does change is the direction of travel. The framework your controls report into is moving from an eight-item checklist to a function-based operating model with AI assumed on both sides of the fight. We track every step of that shift, including timelines, what is confirmed, and what remains open, on our Essential Eight to Essentials transition tracker.
Read the guidance, or at least the vendor questions. The two appendices give you ready-made questions for any vendor selling AI-enabled security, covering measurable outcomes, data handling, and what happens when the AI fails. Use them in your next renewal conversation.
Ask where AI already sits in your security stack. Most businesses run AI-assisted detection without knowing its limits or its data flows. Map it against the six functions and the gaps become obvious, usually in Respond and Recover.
Get your fundamentals and your AI posture reviewed together. The guidance treats them as one system, and so should you. We run a free AI and cybersecurity readiness review that covers both, built on our Essential Eight implementation and AI governance work.
Opportunities for AI in cyber defence is ACSC guidance first published in May 2026 and co-sealed by the Canadian, New Zealand, and UK cyber security agencies. It explains where AI can strengthen cyber defence across the ISM’s six functions, and how to adopt AI tools securely, including agentic AI.
No. The Essential Eight remains the live baseline, and the guidance treats it as the foundation AI builds on. But its ISM-function structure previews how the Essentials series, the Essential Eight’s announced replacement, will organise security guidance.
There is no mandate. The practical pressure is that attackers are using AI to move faster, and the guidance in Opportunities for AI in cyber defence exists because manual-only defence increasingly cannot keep pace. Most businesses already use some AI-assisted security through their EDR or email filtering; the question is whether it is governed.
Agentic AI refers to systems that plan and take actions towards a goal with limited human involvement, rather than responding to single prompts. In security, that means AI that investigates alerts, correlates evidence, and executes response steps, with humans approving high-impact decisions. It needs its own guardrails, which is why the ASD has flagged it as a likely Essentials series chapter.