The APS Has AI It Doesn’t Own, Running on Context It Hasn’t Built

Every agency in the Australian Public Service is now formally required to govern its use of artificial intelligence. The APS AI Plan and the DTA’s updated policy mandate an accountable official for every significant deployment, central registration of use cases, and a formal impact assessment before any core workflow is touched. The era of handing staff a commercial chatbot and calling it an AI strategy is over, and what replaces it is considerably harder than the policy documents acknowledge.

The whole-of-government trials demonstrated genuine productivity gains on administrative work (meeting summaries, first-draft correspondence, document classification), but the moment agencies pushed the technology into the work that actually matters (complex policy development, legislative analysis, ministerial briefings etc), the productivity calculation inverted. The time saved on initial drafting was cannibalised by the time spent manually correcting outputs that had no understanding of the environment they were operating inside. Unwritten departmental rules, historical policy context, structural hierarchies, the specific legislative constraints governing a new proposal – none of that exists inside a generalised foreign model, regardless of how capable that model is.

The intelligence is there but the context is missing, and that gap will not be closed by a better model or a more generous enterprise licence. Agencies are hitting an operational ceiling that is structural rather than technical, and the only way through it is to build the contextual foundation the model is currently missing.

The Connective System of Work

The historical public sector response to new technology was a massive integration project; years spent attempting to hardcode new capabilities directly into legacy ERP systems, with multi-year delays, exorbitant costs and severe vendor lock-in to show for it. That model is broken and the APS cannot afford to repeat it in the AI era.

True operational capability requires a different architectural approach entirely. Rather than forcing integration, a System of Work connects systems through association, operating as a secure management layer that maps exactly how an agency functions, organising the unstructured data, legislation and internal policies that govern daily operations. This structure gives the intelligence layer the exact contextual parameters it needs before it generates a single word. The model stops operating in a vacuum and starts querying a governed repository of agency knowledge. DOLIUM is built precisely for this role, designed to enforce security at the data level through a digital vault that regulates access based on the actual clearance of each individual employee, not a blanket license granted at the platform level.

The result is not just better output accuracy. It is the elimination of the review bottleneck that has been quietly undermining the case for AI in government since the first pilots ran.

The False Comfort of Data Residency

Crucially, this architecture addresses the most pressing vulnerability of the wider government transition, and that vulnerability is sovereign risk.

The GovAI platform is marketed as a secure and sovereign environment. Objectively examined, it is a contractual promise dressed as a strategic position. GovAI provides agencies with dedicated cloud environments built on Microsoft Azure or Amazon Web Services, both US-headquartered corporations, and routes access to foreign models (including OpenAI’s GPT-4o and Anthropic’s Claude) through a single API gateway via Australian-based infrastructure. That keeps data onshore by contractual arrangement. It does not make it sovereign. The APS AI Plan itself acknowledges as much, noting that the inclusion of additional onshore models would “further strengthen Australia’s data sovereignty”, a concession, buried in the government’s own planning document, that what currently exists falls short.

The underlying intellectual property (the model weights, the architecture, the pre-training data) remains entirely in the hands of foreign corporations answerable to foreign governments, foreign regulators and foreign courts. By connecting to those models via the GovAI API gateway, the Australian government is leasing its digital brain on a pay-as-you-go basis. GovAI’s own documentation notes that the latest model versions may be delayed because vendor agreements must be renegotiated before they can be made available, which is precisely the dependency this architecture creates. If a foreign government tightened export controls on frontier capabilities, or a commercial vendor altered its terms of service, the APS would have no legal or technical recourse. The operational kill switch for a core government system of work sits in another country.

Supply Chain Opacity and Agentic Escalation

The risk does not stop at the kill switch. Because the government connects to these models via a reverse proxy, the models themselves remain complete black boxes to Australian cybersecurity authorities. The Australian Signals Directorate cannot independently audit the datasets used to pre-train them. If a hostile nation-state subtly poisoned the training data upstream (like embedding latent vulnerabilities or logic flaws before the model was ever licensed for commercial use), the central gateway would automatically pipe that compromised logic directly into the heart of the APS. The government is implicitly trusting the cybersecurity posture of overseas corporations with no independent mechanism to verify that trust is warranted.

That vulnerability reaches a critical threshold as agencies transition from passive generation to active execution. When a model is granted agentic capabilities (connected to agency data to automate document processing or complex legislative analysis) it is no longer answering isolated questions. It is taking action on government data. A successful prompt injection attack against a foreign model via the gateway is not merely a data breach. It is the fundamental compromise of government logic, and the blast radius expands from exfiltration to the manipulation of how Australian government processes information and makes decisions.

Building the Sovereign Foundation

The 2026 APS AI Plan is an operational reckoning as much as a technology strategy. Every agency now faces the same question: whether the AI they deploy will actually understand the environment it is working inside, and whether the foundation it runs on will still be under Australian control in five years.

Agencies relying on generalised foreign models piped through a central gateway will keep trading the time saved on initial drafting for the friction of manual technical review. The problem is context, and no commercial licence agreement resolves it. Before a model generates a single word, it needs to know the unwritten rules of the agency, the hierarchy of its decision-making, the specific legislative environment governing its outputs, knowledge that has to be structured, governed and owned onshore by the agency itself.

DOLIUM maps the actual operating logic of an agency and holds that knowledge as a governed, onshore foundation, without the multi-year integration project, without the legacy ERP dependency, and without the vendor lock-in that has defined every previous wave of government technology investment. AiDA, the agentic capability embedded natively in DOLIUM, inherits that foundation entirely, so when it moves from generating content to taking action on government data, the boundaries governing that action were set by the agency, enforced onshore, and answerable to no foreign commercial arrangement.

Owning your digital foundation means holding the governed, onshore framework that tells your AI exactly how to work, one that survives a model deprecation, a vendor repricing, or a foreign government’s decision to tighten export controls on frontier technology. The APS has a narrow window to establish that foundation before the dependency deepens. Every day that window stays open is another day the kill switch sits somewhere else.

Start the conversation.

Tell us about your operating model and we will show you where DOLIUM fits. We respond within one business day.