{"id":561609,"date":"2026-03-24T18:03:25","date_gmt":"2026-03-24T18:03:25","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/561609\/"},"modified":"2026-03-24T18:03:25","modified_gmt":"2026-03-24T18:03:25","slug":"govern-ai-twins-before-they-arrive","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/561609\/","title":{"rendered":"Govern AI twins before they arrive"},"content":{"rendered":"<p><img fetchpriority=\"high\" decoding=\"async\" width=\"2121\" height=\"1414\" class=\"alignnone size-full wp-image-99444\" src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2026\/03\/GettyImages-2225558626.jpg\"  \/><\/p>\n<p class=\"font-claude-response-body\">Australia has no legislation and policy designed specifically for AI digital twins\u2014systems that train on an employee\u2019s emails, meetings, documents and chat messages to create an AI-human replica that can answer questions. The technology is already running overseas and heading here fast.<\/p>\n<p class=\"font-claude-response-body\">A compromised twin trained on defence or critical-infrastructure personnel would be an intelligence windfall, but existing legislation and policies weren\u2019t designed for non-human workers holding years of institutional knowledge. Australia needs to close this gap before the technology arrives.<\/p>\n<p class=\"font-claude-response-body\">A Silicon Valley startup, Viven, raised US$35 million (A$49 million) in October to build personalised AI twins to represent each employee in a given company. Colleagues could then query that person\u2019s digital twin and get answers even if the real person were on leave or had quit. Viven is already running inside enterprises with tens of thousands of workers.<\/p>\n<p class=\"font-claude-response-body\">Australia\u2019s appetite for AI is insatiable. Consulting firm Deloitte says 61 percent of Australian companies report improved efficiency from AI. The government\u2019s National AI Plan <a href=\"https:\/\/www.industry.gov.au\/news\/australia-launches-national-ai-plan-capture-opportunities-share-benefits-and-keep-australians-safe\" target=\"_blank\" rel=\"noopener nofollow\">commits<\/a> more than A$460 million to the technology\u2019s development. Every signal points the same way: more AI, faster.<\/p>\n<p class=\"font-claude-response-body\">That makes it worth asking a question nobody in Canberra seems to have considered: what happens when malicious actors target a digital twin trained on the full working life of a government contractor\u2019s project lead?<\/p>\n<p class=\"font-claude-response-body\">Think about the pieces of data that a twin may hold: project plans, client emails, internal strategy, contract terms, and personnel decisions, to name a few. Gaining access to the twin of someone who\u2019d worked across Australia\u2019s defence supply chain would be an intelligence windfall. Compromise one twin and you get all recorded information that the person knew: suppliers, timelines, technical details\u2014all in one place, only a query away.<\/p>\n<p class=\"font-claude-response-body\">No AI twin is known to have been breached yet. But there is a strong parallel in what has already happened to enterprise copilots, which share similar underlying architecture. AI twins and enterprise copilots work by pulling an employee\u2019s emails, documents and messages into an AI that generates answers. The main difference is that a copilot retrieves context for the person using it, whereas a twin concentrates that person\u2019s entire recorded working knowledge (and personality) into a permanent system that others can query. This is a ready-made vulnerability, a richer target.<\/p>\n<p class=\"font-claude-response-body\">In June 2025, researchers disclosed a flaw in Microsoft 365 Copilot that allowed an attacker to steal sensitive data with a single crafted email, no clicks required. The AI mistook hidden instructions for legitimate commands and quietly handed over whatever it had access to. The Open Worldwide Application Security Project, the global authority on software security, ranks this kind of attack as the number-one vulnerability in AI applications.<\/p>\n<p class=\"font-claude-response-body\">Separately, a project called Pharmaicy has shown that code-based modules can alter how an AI thinks, much as a drug can alter a human mind: making it hazy, speeding it up and scrambling its judgment. Apply that principle to a twin trained on years of someone\u2019s working life and you aren\u2019t distorting a conversation; you\u2019re corrupting a career\u2019s worth of knowledge.<\/p>\n<p class=\"font-claude-response-body\">There\u2019s also a departure problem. When employees leave, if their AI twins stay behind, who owns those twins? For a government agency or defence contractor, that is a question about data sovereignty as well as intellectual property. Australia\u2019s Privacy Act 1998, the Defence Industry Security Program, contract law and employment law all touch on aspects of this problem. But none was designed for non-human workers holding years of institutional knowledge.<\/p>\n<p class=\"font-claude-response-body\">The biggest gap is probably in critical civilian infrastructure. The Security of Critical Infrastructure Act 2018 requires risk management plans across 11 sectors including communications and data storage. But the act was designed for human identities, not digital ones.<\/p>\n<p class=\"font-claude-response-body\">Defence is arguably better placed than most to deal with threats through digital twins. It is more alive to the risk of leaks and already operates under stricter personnel security regimes. Nonetheless, it would be good to see an Australian public framework for governing AI in defence and national security settings, like those that have been set up in the United States and Britain. The Australian Parliamentary Library\u2019s latest research on AI and the Australian workforce focuses entirely on productivity, jobs and inequality. Security does not rate a mention.<\/p>\n<p class=\"font-claude-response-body\">Several things should happen as AI digital twins such as Viven\u2019s arrive in Australia. The AI Safety Institute, costing A$29.9 million and due to launch this year, should examine AI twins as a priority threat. The risk management rules outlined in the Security of Critical Infrastructure Act should be updated so critical infrastructure operators account for digital workers in their threat plans. And the Defence Industry Security Program should be extended to explicitly cover AI twins in the supply chain.<\/p>\n<p class=\"font-claude-response-body\">Australia has the chance to get the rules right before the technology emerges further. It would be a waste not to take it.<\/p>\n","protected":false},"excerpt":{"rendered":"Australia has no legislation and policy designed specifically for AI digital twins\u2014systems that train on an employee\u2019s emails,&hellip;\n","protected":false},"author":2,"featured_media":561610,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[256,254,255,64,63,105],"class_list":{"0":"post-561609","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-artificial-intelligence","8":"tag-ai","9":"tag-artificial-intelligence","10":"tag-artificialintelligence","11":"tag-au","12":"tag-australia","13":"tag-technology"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/561609","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=561609"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/561609\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/561610"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=561609"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=561609"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=561609"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}