BIP Dallas Digital News & Media Platform

collapse
Home / Daily News Analysis / Australian government cloud mandate sparks migration warnings

Australian government cloud mandate sparks migration warnings

Jul 29, 2026  Twila Rosenbaum 5 views
Australian government cloud mandate sparks migration warnings

Australia's whole-of-government cloud policy comes into effect on 1 July 2026, establishing cloud as the default when modernising IT infrastructure. The policy document, prepared by the Digital Transformation Agency (DTA), sets out five broad requirements: prioritise cloud technologies when modernising IT infrastructure; tap cloud technologies to drive innovation including artificial intelligence; adopt cloud securely and responsibly; actively manage and optimise cloud costs; and nurture cloud skills across the Australian Public Service.

The first specific requirement is that agencies adopt cloud solutions for all new digital and ICT initiatives and upgrades unless an alternative is justified. However, Gartner director-analyst Adrian Wong warned that a blanket mandate overlooks the reality that some applications or workload components are poor fits for the cloud. Legacy applications often fail to fully utilise cloud capabilities, making them technically mismatched and sometimes unexpectedly more expensive to run in the cloud than in a local datacentre.

Risk of rushed migrations

Wong pointed out that while the policy frames the mandate as a transition away from ageing systems rather than a strict requirement to migrate every existing legacy app to the cloud, aggressive timelines can drive poor decision-making. Organisations feeling rushed, especially if they lack adequate cloud planning and architectural expertise, are more likely to pursue poorly conceived lift-and-shift migrations. These hurried efforts frequently fail to meet expectations and form the basis for cloud project failures.

According to a Gartner report on handling cloud project failures, common reasons include workloads being inappropriate for the cloud, poorly chosen providers, bad design or implementation, inaccurate cost estimates and integration issues. Some factors make workloads inherently more suited to on-premise deployment: high sensitivity to latency, strict data residency or compliance mandates that public cloud cannot satisfy, unique service-level agreements that providers might not meet, and environments requiring enterprise-controlled assets.

"Ultimately, avoiding cloud dissatisfaction requires agencies to have the time and flexibility to perform a detailed application portfolio analysis. While prioritising modern cloud solutions is a strong strategic aspiration, enforcing rigid decommissioning pressures risks forcing bad long-term fits just to satisfy policy requirements," Wong warned.

Vinayak Sreedhar, country manager for Australia and New Zealand at ManageEngine, an IT management and monitoring provider serving federal, state and local government customers, said agencies shouldn't underestimate the complexity ahead. Migrating away from legacy systems while ensuring ongoing compliance is no easy feat. "The agencies most at risk are those without a clear picture of what's being retired, when, and what is dependent on it. Moving fast without that clarity is how outages occur," Sreedhar said.

AI and interoperability challenges

Cloud platforms are seen as a way of creating a more connected, responsive and data-driven public sector, partly through AI adoption. While government entities are required to design for interoperability and portability to minimise supplier lock-in, they are only encouraged to ensure cloud services support open standards and APIs, and allow data portability.

SUSE ANZ general manager Ben Henshall suggested the policy language indicates the DTA wants to avoid another "mother of all lock-in" situation similar to historical mainframe problems. Once data is locked into a particular cloud, it becomes very hard and costly to extract into a format deployable elsewhere. Public clouds are designed as a "land grab" to capture as many departmental workloads as possible, Henshall warned. "They're not making it easy to get out because why would they? It's not in their commercial interest to be open, interoperable, more standard spaces." For example, hyperscalers each have their own domain-specific languages for creating templates that specify operating systems and software for virtual machines.

The policy highlights design and procurement principles of selecting architectures that are open, interoperable, contestable and portable, but that remains a challenge. Part of the problem is that a vast amount of money is spent simply keeping the lights on and upgrading rather than innovating. Replatforming with low cost and effort is the "secret sauce" of open source, because it is agnostic, allowing agencies to spend more time deploying new features rather than draining budgets on system upgrades.

While SUSE's cloud provider partners offer utility, Henshall admitted they also pose risks and add cost due to proprietary technology stacks, creating complications for multicloud environments. Departments such as education, health, defence, home affairs and Services Australia are complex organisations with vast use cases and cannot source all capabilities from a single provider like Amazon Web Services, Google Cloud, Microsoft Azure, Oracle or SAP, making interoperability, portability and integration vital.

Agentic AI is gaining attention for automating workflows. Different systems within a process will use different large language models (LLMs) of varying sizes, meaning data processing needs are highly varied. At one extreme, soldiers have disconnected, intermittent and limited (DIL) access to remote systems, so processing must be local. At the other extreme, the health department processes large volumes of records to determine benefits or treatments. With many LLMs available, both open source and proprietary, Henshall said it is crucial for governments to retain sovereign control over their data and models. Governments are looking to open source LLMs to access the code, ensure explainability and govern the models.

According to Sreedhar, the push to embed AI readiness across cloud platforms is forward thinking but isn't a switch organisations can simply flip post-migration. "How is the data structured, governed and stored? How much compute is being provisioned? And how will models eventually be deployed? These questions require deliberate architectural decisions from day one. Those that treat AI as a future add-on rather than a current design requirement will be hit with expensive infrastructure rebuilds in a few years' time. The time to get this right is during the transition, not after."

Security considerations

Henshall pointed out that federal government agencies must navigate the cloud transition regardless of difficulty, especially regarding security. "No one wants to be on the front page of the newspaper. Nobody wants to be the person who accidentally put information out into a public AI system that caused sovereign angst." A modern, defensible architecture is an essential, non-negotiable requirement for hosting and running AI workloads safely and securely.

As a supplier, part of SUSE's role is to help government departments apply a modern defensible architecture adhering to Essential Eight principles, the Australian Signals Directorate's information security manual and ISO 27001, ensuring a zero-trust architecture that is portable, composable and interoperable. Without this, Henshall suggested federal agencies will lag in tapping the technical benefits of AI.

Sreedhar warned that the transition's sheer scale creates a much larger attack surface. Recent cyber security legislative reforms have sharpened obligations for critical infrastructure operators, but agencies should treat those obligations as a baseline. "The vulnerability we see most often in cloud transitions isn't technical – it's the gap between IT teams and security teams during the migration itself. Security architects need to be part of the transition from procurement through to go-live and beyond."

Skills uplift

A policy framework is only as good as the people implementing it, Sreedhar observed. The DTA has been clear that agencies must build the skills, infrastructure and governance required to meet community expectations, yet workforce capability is almost always the most underfunded component of digital transformation. Agencies should evaluate internal capability well ahead of the 1 July deadline and invest in genuine skills uplift where gaps exist.

"Getting the technology right matters, but so does building a public service that understands and owns what it's building," Sreedhar said. This is especially vital for the policy's fifth requirement, which explicitly demands agencies nurture cloud skills across the APS. "Agencies won't be able to satisfy the policy simply by pointing to cloud deployments. That's the easy part. Agencies need genuine workforce development strategies and plans to close identified skills gaps. One of the ways we're addressing this at ManageEngine is at the operational layer, helping staff build fluency with hands-on training and tools spanning infrastructure, security and FinOps – the disciplines the DTA has specifically and rightly called out."

Reflecting on the skills mandate, Henshall described this aspect of the policy as a strong starting point offering good principles and guidelines. "It's there not as a stick, but as a compass."


Source:ComputerWeekly.com News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy