endoflife.ai
EOL Checker Exploited & Unpatchable End-of-support edge devices API

ASD Warns Legacy Technology Will Be First Hit in AI-Enabled Attacks

By Scott Bissett  ·  Published: September 19, 2026  ·  Analysis  ·  ASD guidance read at cyber.gov.au on the day of publication; the speech as reported by Australian press.

The head of the Australian Signals Directorate has said that legacy technology will almost certainly be the first thing compromised in a major AI-enabled attack, unless organisations replace it first. Director-General Abigail Bradshaw made the remarks at the Sydney Dialogue in September 2026, describing Australia as sitting on "an enormous legacy technology debt" and suggesting that the most meaningful response would be to set legacy technology reduction targets and work towards them, as reported by Cyber Daily. The warning is about Australia. The reasoning applies anywhere.

Why AI changes the arithmetic. Unsupported software has always been risky because its flaws are never fixed. What limited the damage was effort: someone had to find the flaw and write the attack. ASD's guidance on frontier AI for boards says these models can significantly reduce the time it takes to discover and exploit a vulnerability, and put that ability in the hands of attackers who previously lacked the skills. It asks directors to consider whether they could still respond if attacks moved from taking days to hours, and puts the question plainly: what legacy technology risks are we carrying, and do we have a plan to remediate them? A system that will never be patched is the target where that speed-up pays off for longest.

What ASD actually means by "legacy"

"Legacy" is often used loosely for anything old. ASD's practitioner guidance on managing the risks of legacy IT uses a precise definition from the Australian Government's Protective Security Policy Framework. A product, which can be hardware, software, a service, a protocol or a system, is legacy when it meets at least one condition from each group:

Category A: its support statusCategory B: its place in the organisation
It is an end-of-life product, or
it is out of support, including extended support from the manufacturer, vendor or developer
It is impractical to update or support, or
it is no longer cost-effective, or
it is above the current acceptable risk threshold, or
it offers diminishing business use, or
it obstructs the organisation's IT strategy

The first test is a matter of fact with a date attached: has the vendor ended support, or not. That is the part that can be measured across a whole estate, and it is where a reduction target has to start, because a target needs a number.

Facing an end-of-life deadline?
Tell us which product and we’ll reply with vetted extended-support options and pricing guidance — free, no obligation. Vendors don’t pay for placement.

Free · No obligation · Independent · dates verified against vendor sources · Not urgent? Follow the EOL radar or see the 2026 EOL calendar →

What ASD tells organisations to do

"Replace or mitigate legacy technologies" is also the first item on ASD's list of critical actions for its Cyber Action Year 2026; "prepare for AI-enabled cyber threats" is on the same list.

Turning a reduction target into something you can count

  1. List what runs. Operating systems, databases, runtimes, frameworks, network devices. An asset inventory or an SBOM is enough to start.
  2. Attach a support end date to every line. Our EOL Checker does this one product at a time; the API does it for a whole list, and accepts a CycloneDX or SPDX SBOM. Every date carries its source, which matters when the number goes to a board or an auditor.
  3. Count three groups: already past end of support; ending within twelve months; supported beyond that. The first group is the legacy technology debt in ASD's Category A sense. The second is the debt you can still avoid.
  4. Rank by exposure, not age. An end-of-life system with a vulnerability that attackers are already using comes first. Our Exploited & Unpatchable list tracks exactly that overlap, and the end-of-support edge device list covers the firewalls, VPN gateways and routers that sit on the internet.
  5. Set the target as a date and a number, and report the count each quarter.

What becomes legacy next

A few widely deployed products whose support ends in the coming weeks, from our tracked data:

ProductSupport ends
FortiOS 7.2September 30, 2026
Microsoft Office 2021October 13, 2026
Next.js 15October 21, 2026
Python 3.10October 31, 2026
.NET 8November 10, 2026

Everything else reaching end of life this year is on the 2026 end-of-life calendar.

Frequently Asked Questions

What did the Australian Signals Directorate say about legacy technology and AI?

Speaking at the Sydney Dialogue in September 2026, ASD Director-General Abigail Bradshaw said Australia carries a very large legacy technology debt, and that AI will either prompt organisations to replace legacy technology or, if they move too slowly, legacy technology will almost certainly be the first thing compromised in a major AI-enabled attack. She suggested setting legacy technology reduction targets.

What does ASD count as legacy IT?

Under the Protective Security Policy Framework definition that ASD's guidance uses, an IT product is legacy when it meets at least one condition from each of two groups. The first group is about support: it is an end-of-life product, or it is out of support including extended support. The second is about the organisation: it is impractical to update or support, no longer cost-effective, above the acceptable risk threshold, of diminishing business use, or an obstacle to the IT strategy.

What does ASD tell organisations to do about legacy IT?

Replace it before it becomes legacy, which ASD calls the most effective mitigation. To do that, keep an accurate IT register, supported by a Software Bill of Materials where possible, and systematically monitor when products will reach end of life or go out of support. Where replacement is not yet possible, ASD lists temporary, low-cost mitigations, and says they reduce risk only temporarily.

Related

© 2026 endoflife.ai · How we verify our dates · API · About