Australia's whole-of-government cloud policy takes effect on 1 July 2026, mandating cloud as the default when modernising IT infrastructure. The policy, prepared by the Digital Transformation Agency (DTA), outlines five key requirements: prioritising cloud technologies for all new digital and ICT initiatives unless an alternative is justified; leveraging cloud to drive innovation including artificial intelligence (AI); adopting cloud securely and responsibly; actively managing and optimising cloud computing costs; and nurturing cloud skills across the Australian Public Service (APS). While the directive aims to modernise government systems, industry analysts and technology providers warn that a blanket mandate could backfire if implemented without careful planning.
Expert warnings on rushed migrations
Gartner director-analyst Adrian Wong cautioned that the policy overlooks the reality that some applications are inherently poorly suited to cloud environments. Legacy systems, for example, often fail to fully utilise cloud capabilities, making them technically mismatched and sometimes unexpectedly more expensive to run in the cloud versus a local datacentre. Wong noted that while the policy frames itself as a transition away from ageing systems rather than a strict requirement to migrate every existing legacy app, aggressive timelines can drive poor decision-making. Organisations that feel rushed, especially those lacking adequate cloud planning and architectural expertise, are more likely to pursue poorly conceived lift-and-shift migrations. Such hurried efforts frequently fail to meet expectations and form the basis for cloud project failures.
According to a Gartner report on handling cloud project failures, common reasons include workloads being inappropriate for the cloud, poorly chosen providers, bad design or implementation, inaccurate cost estimates, and integration issues. Wong emphasised that some factors make workloads inherently more suited to on-premise deployment: high sensitivity to latency; strict data residency, compliance, or sovereignty mandates that cannot be satisfied with public cloud solutions; unique service-level agreements that cloud providers might not be able to meet; and environments requiring enterprise-controlled assets. He urged agencies to have the time and flexibility to perform a detailed application portfolio analysis before committing to migration.
Complexity and interoperability challenges
Vinayak Sreedhar, country manager for Australia and New Zealand at ManageEngine, observed that agencies shouldn't underestimate the complexity of what lies ahead. Migrating away from legacy systems while ensuring ongoing compliance is no easy feat. Sreedhar identified that agencies most at risk are those without a clear picture of what is being retired, when, and what depends on it. Moving fast without that clarity is how outages occur. He also stressed that workforce capability is almost always the most underfunded component of digital transformation, noting that while the DTA has been clear about the need to build skills, investments in training often lag behind technology procurement.
Ben Henshall, ANZ general manager at SUSE, highlighted that the policy language gives the impression the DTA wants to avoid another "mother of all lock-in" situation, reminiscent of historical mainframe problems. Once data is locked into a particular cloud, it becomes very hard and costly to extract. Public clouds are designed as a "land grab" to capture as many departmental workloads as possible, and providers are not incentivised to make exit easy. Hyperscalers each have their own domain-specific languages for creating templates, further complicating portability. The policy encourages open standards and APIs, but Henshall argued that practical interoperability remains a challenge, especially given that federal departments such as education, health, defence, home affairs, and Services Australia have vastly different use cases and cannot source all capabilities from a single provider.
AI and agentic automation
Cloud platforms are seen as a conduit for a more connected, responsive, and data-driven public sector, in part through the adoption of AI. The policy requires agencies to design for interoperability and portability to minimise supplier lock-in, but only encourages them to ensure cloud services support open standards and APIs. Henshall noted that agentic AI is gaining attention for automating workflows, and that different systems within a process will use different large language models (LLMs) of varying sizes. For example, soldiers may require disconnected, intermittent, and limited access (DIL) to remote systems, meaning processing must occur locally. Meanwhile, the health department processes large volumes of records to determine benefits or treatments. With many LLMs available, both open source and proprietary, Henshall stressed the importance of governments retaining sovereign control over data and models. Open source LLMs allow access to the code, ensure explainability, and enable governance.
Sreedhar added that the explicit push to embed AI readiness across cloud platforms is forward-thinking but not a switch organisations can simply flip post-migration. Questions about data structure, governance, storage, compute provisioning, and model deployment require deliberate architectural decisions from day one. Treating AI as a future add-on rather than a current design requirement will lead to expensive infrastructure rebuilds in a few years.
Security and zero-trust architectures
Henshall pointed out that federal agencies will have to navigate the cloud transition regardless of difficulty, especially regarding security. A modern, defensible architecture is an essential, non-negotiable requirement for hosting and running AI workloads safely and securely. SUSE works with government departments to apply a modern defensible architecture adhering to Essential Eight principles, the Australian Signals Directorate's information security manual, and ISO 27001. This ensures a zero-trust architecture that is portable, composable, and interoperable. Without this, agencies will struggle to tap the technical benefits of AI.
Sreedhar warned that the sheer scale of the transition creates a much larger attack surface. Recent cyber security legislative reforms have sharpened obligations for critical infrastructure operators, but agencies should treat those obligations as a baseline. The vulnerability most often seen in cloud transitions is not technical—it is the gap between IT teams and security teams during the migration itself. Security architects need to be part of the transition from procurement through to go-live and beyond.
Skills uplift and workforce development
A policy framework is only as good as the people who put it into practice. Sreedhar observed that the DTA has been clear that agencies must build the skills, infrastructure, and governance required to meet community expectations, yet workforce capability remains underfunded. Agencies should evaluate internal capability right now, well ahead of the 1 July deadline, and invest in genuine skills uplift where gaps exist. Getting the technology right matters, but so does building a public service that understands and owns what it is building. This is especially vital for the policy's fifth requirement, which explicitly demands agencies nurture cloud skills across the APS.
Sreedhar continued that agencies won't be able to satisfy the policy simply by pointing to cloud deployments; they need genuine workforce development strategies and plans to close identified skills gaps. ManageEngine addresses this at the operational layer by helping staff build fluency with hands-on training and tools spanning infrastructure, security, and FinOps—the disciplines the DTA has specifically called out. Henshall described the skills mandate as a strong starting point, offering good principles and guidelines—not a stick but a compass.
The cloud mandate represents a significant shift for Australian government agencies, requiring careful planning, investment in skills, and a focus on security and interoperability. While the goal of modernising IT infrastructure is laudable, experts warn that success will depend on avoiding rushed decisions, ensuring proper application portfolio analysis, and building the internal capabilities needed to manage the transition effectively.
Source: ComputerWeekly.com News