Executive Summary
The direct answer
Broad AI-enabled civic resilience is not yet shown to be deliverable, safeguarded and sustainable by 2035. Australia has credible institutions, real statutory authority, operational forecasting and cyber capability, increasingly detailed public-sector AI controls, and plausible civic mechanisms. Those are substantial foundations. They do not, on evidence available to 22 August 2026, form a completed broad national delivery system.
The positive case is strongest when AI is narrow and assistive. Machine-learned forecasting can extend pattern detection and scenario work. AI can help cyber defenders prioritise vulnerabilities, detect anomalies and recover faster. Commonwealth policy now requires accountable use-case owners, impact assessment, monitoring and risk-based review. Its technical standard addresses workforce, audit, robustness, continuity, rollback, incident response and decommissioning. These controls make bounded delivery more credible than a technology-first proposal with no owner or exit.
But the evidence thins at the point that matters most: demonstrated outcomes and endurance. The Australian National Audit Office found largely effective AI use at IP Australia while also finding inconsistent benefit measurement and incomplete strategic oversight. The ATO audit found partly effective enterprise governance. Defence and critical-infrastructure records identify civil preparedness, sovereign capability, intertwined dependencies, agentic-AI risk and workforce shortages; they do not publicly establish that all relied-upon packages can continue through the six conditions used here.
The broad civic case has a larger gap. A peer-reviewed UK experiment provides a credible signal that AI can help groups draft statements that preserve minority critiques. OECD work explains how deliberation can be institutionalised. Neither establishes representative Australian participation, formal decision uptake, published reasons, durable correction or resistance to capture and model failure. No complete Australian chain from AI-assisted deliberation to a named decision owner's reasoned response and sustained outcome was located.
The safeguards are also incomplete as evidence, even where they are sensible as design. Content credentials provide provenance, not truth. Election law does not generally prohibit AI-generated campaign content, and the Australian Electoral Commission's own AI use remains limited within a predominantly manual election system. Generic data-centre evidence shows material energy and water issues, but no complete Australian mission-level lifecycle account was located for the six functions. Population evidence identifies unequal access and participation, but not intervention-specific results for carers, disabled people, regional communities or people outside standard employment.
The function findings transferred from Report 2 therefore remain unchanged. Anticipation and
forecasting (FANT) and cyber/AI-driven threats (FCYB) are USEFUL NOT NECESSARY. Climate,
infrastructure and logistics (FCIL), care and living well (FCAR), information judgement
(FINF) and deliberation (FDEL) remain UNRESOLVED. None is NECESSARY. Report 3 found no
material new evidence that meets the controlled-amendment threshold for altering those accepted
classifications.
Across pathways, P1 has real institutional strengths but unclosed adequacy gaps. P2 is the most credible near-term delivery pattern because it can confine AI to bounded institutional tasks while retaining strong non-AI capacity. Its result is still partial, not a broad pass. P3 retains plausible but uneven civic experiments. P4 has the largest promised civic gain and the largest unproven coordination, distribution, ecological, information and dependency burden. It does not exceed P2 or P3 on current durable civic-mechanism evidence.
The practical conclusion is not “wait for perfect evidence”. It is “do not call the broad system delivered before the gates have evidence”. The dated backcast now makes that discipline operational: owners must establish foundations by 2027, attributable bounded results by 2029, cross-domain and formal-influence evidence by 2031, operational-scale shock and exit tests by 2033, and realised outcomes by 2035. A missed checkpoint causes narrowing, redesign, substitution, stopping or exit; it does not silently create a later deadline.
How to Read This Report
This report uses eight numbered passes. Pass 0 fixes the exact inherited state. Pass 1 tests owners and delivery capacity. Pass 2 examines safeguards and exits. Pass 3 tests whether civic processes connect to formal decisions. Pass 4 applies S0–S5 and the dated milestones. Pass 5 gives separate function and pathway results. Pass 6 synthesises the cumulative evidence without stating the final portfolio result. Pass 7 applies the accepted aggregation order and contains the single final cumulative result and exact handoff.
Claim IDs in square brackets resolve to the one canonical evidence-ledger.csv. The ledger records
source identity, exact location, verification, transfer limits, counterevidence, confidence and
owner. A search ID records a reproducible search that did not locate adequate evidence. It supports
UNRESOLVED; it never proves that a mechanism is impossible.
The four pathways are alternative implementation worlds, not forecasts. The six conditions are
stress tests, not probability estimates. A partial delivery state is not one of the five final
verdicts; it describes completion of a delivery or gate test. Function, pathway and portfolio
results are kept separate.
Confidence Scale
| Rating | Meaning in this report |
|---|---|
| High | Current Australian statutory, operational or independent-audit evidence directly supports the bounded claim; important limits are stated. |
| Medium | Evidence supports the direction, but attribution, implementation, transfer, duration, distribution or shock evidence remains incomplete. |
| Low | Evidence is early, indirect, non-Australian or highly setting-dependent. It can identify a mechanism but cannot carry a broad result. |
| Insufficient | The specified search did not locate evidence adequate for the test. An owner, checkpoint and failure response are required. |
The Direct Question, Answer and Scope
Question: Can broad AI-enabled civic resilience be delivered, safeguarded and sustained by 2035?
Answer: Not yet on the accepted evidence. Bounded institutional AI can be useful and can be designed more safely than before, but the broad pathway lacks demonstrated package-level delivery, complete safeguards, formal democratic uptake, fair distribution, mission-level ecological accounts and S1–S5 continuity and exit tests.
The scope is Australia nationally, with Commonwealth, state, territory, local, sector and service owners where they hold the relevant authority. The unit is one of 21 eligible risk–function cells, implemented under one of four pathways and tested across seven domains and six conditions. The controlled surface comprises 84 function–pathway delivery packages and 504 package–condition tests. Three accepted risk–function cells remain ineligible and receive no invented delivery finding.
The report does not estimate the likelihood of a war, disaster, care surge, information shock or AI failure. It does not recommend a vendor, build a system, redesign the Constitution, give community advice automatic binding force, generalise Rick's N-of-1 inquiry, or authorise publication or implementation.
Pass 0 — What Reports 1–2 Established
Report 1 tested Australia's launch baseline and strongest feasible non-AI reforms. It found substantial institutions and credible reforms, but did not demonstrate adequacy across every mandatory domain, group and condition. Its result was a comparator gap, not AI necessity.
Report 2 then tested six functions against that serious comparator. It found bounded usefulness in forecasting and cyber defence, but did not demonstrate necessity. It also found incomplete living- well, democratic, distribution, ecological and sovereignty evidence. Report 3 receives exactly nine items:
| ID | Accepted Report 2 OUT / Report 3 IN |
|---|---|
AHL2-OUT-01 |
No function is NECESSARY; FANT and FCYB are USEFUL NOT NECESSARY; FCIL, FCAR, FINF and FDEL are UNRESOLVED. |
AHL2-OUT-02 |
53 Report 2 evidence/search rows and 3,528 eligible scorecard updates, with inherited baseline and comparator values preserved. |
AHL2-OUT-03 |
Living-well gate partial / UNRESOLVED; functional ability, contact, skill, agency, override and group evidence remain required. |
AHL2-OUT-04 |
Democratic/information gate and veto UNRESOLVED; bounded provenance and mediation do not establish durable judgement or formal influence. |
AHL2-OUT-05 |
Civic-time/equivalent-capacity bridge UNRESOLVED; shorter-week wellbeing evidence does not prove civic conversion. |
AHL2-OUT-06 |
Fair distribution, ecology and security/sovereignty remain partial or UNRESOLVED; no averaging or exported-harm bypass. |
AHL2-OUT-07 |
OWS process-quality rules and a named-owner formal-response requirement; automatic binding authority excluded. |
AHL2-OUT-08 |
N-of-1 is protocol only, UNRESOLVED, with national evidence weight exactly zero. |
AHL2-OUT-09 |
Owner capability, override/appeal, offline fallback, vendor exit, S1–S5 continuity, lifecycle, distribution, formal response and 2029/2031 milestones remain unresolved tests. |
All 99 inherited evidence/search rows were retained. The 21 eligible and three ineligible cells, six interaction states, baseline definitions, comparators, P1–P4 and S0–S5 are unchanged. Current research did not trigger a controlled amendment.
The edge is exact: Report 1 OUT = Report 2 IN, and Report 2 OUT = Report 3 IN. The later report adds synthesis and delivery evidence without rewriting provenance.
What this means
Report 3 does not start with a blank page or a promise that broad civic AI wins. It starts with two accepted constraints: gaps in conventional capacity do not prove AI necessity, and useful AI does not prove that a broad system can be governed through stress.
Pass 1 — Delivery System and Owners
R3-T1 — What delivery requires
Delivery is more than naming a department. Every relied-upon package needs an office with authority to decide, an organisation that can operate the function, enough skilled people, usable data and infrastructure, procurement and assurance, coordination across boundaries, and a dated evidence owner. A policy owner cannot be assumed to be the incident commander. A regulator cannot be assumed to operate a service. A vendor cannot be the public decision owner.
The current Commonwealth AI architecture is useful here. Policy version 2.0 requires accountable officials, use-case ownership, internal registers, impact assessment and monitoring. The technical standard spans operational models, people capability, auditing, bias, data supply, testing, integration, continuity, rollback, incident resolution and decommissioning. Existing in-scope use cases have a 2027 assessment deadline, so present compliance cannot be assumed. Third-party responsibility is conditional in several lifecycle stages, which makes contract design and retained knowledge material delivery questions.
Function owner and capability map
| Function | Decision owner | Delivery and evidence owner | Capability result at cut-off |
|---|---|---|---|
FANT anticipation/forecasting |
The accountable portfolio secretary or statutory operational authority using the warning; Defence/Home Affairs for their decisions | Bureau of Meteorology, Australian Climate Service, Defence or another named forecasting operator; independent programme evaluator | Existing forecasting institutions and AI research are credible. The complete chain from model contribution to acted-on warning, avoided harm, fallback and S1/S2 continuity remains package-specific and incomplete. |
FCIL climate/infrastructure/logistics |
Responsible state, territory, statutory infrastructure or emergency authority | AEMO, network/sector operator, NEMA-linked delivery body or logistics owner; sector regulator holds assurance evidence | Authority is distributed and real. Cross-system workforce, supply, manual control, communications, recovery and vendor-exit proof is not complete across 21 cells. |
FCAR care/living well |
Department of Health, Disability and Ageing or responsible state authority; practitioner retains clinical/service judgement | Named provider and practitioner, with an independent evaluator and accessible complaints/appeal owner | Digital and AI strategies exist. National head-to-head evidence on functional ability, contact, skill, agency and safe fallback by material group was not located. |
FCYB cyber/AI-driven threats |
The affected system owner; a named human incident commander owns consequential response | Organisation CISO and security team, supported by ASD/ACSC and sector partners | Strongest delivery case. Current guidance supports bounded AI augmentation, human oversight, recoverability and fundamentals. Complete S1–S5 exercises and provider exits remain unresolved. |
FINF information judgement |
AEC, editor, regulator, public-service decision owner or other authority for the consequential use | Named information service owner and independent evaluator; ASD/ACSC for provenance/security advice | Provenance and literacy controls help, but source history is not truth and current Australian electoral law and evaluation do not establish durable judgement effects. |
FDEL deliberation |
A named minister, statutory authority, parliament, council or other body able to accept or reject the issue | Independent facilitator and participant-governance body; independent evaluator; action owner after response | Design requirements are clear. No complete Australian AI-assisted process with representative composition, reasoned formal response, action, feedback and durable outcome was located. |
Defence's 2026 strategy expressly names self-reliance, sovereign industrial resilience and civil preparedness. The 2025 Critical Infrastructure Annual Risk Review links energy, water, food, healthcare, transport, finance and communications to third-party, geopolitical, workforce and agentic-AI risks. These sources verify the need and high-level authority. They do not establish the operating readiness of every delivery package.
The audit evidence supplies a particularly useful warning. IP Australia's mature use was largely effective, yet benefits were inconsistently quantified and strategic oversight remained incomplete. That is a capable implementation with an evidence gap, not a failure. It shows why this report assigns “partial” to some P1/P2 delivery contexts rather than converting governance activity into an outcome pass.
The Treasury Copilot evaluation adds a second, differently bounded implementation signal. It found administrative usefulness and some accessibility value while recording limits around complex work, verification and sensitive information. The current National AI Plan supplies policy direction and capability intent. Together they strengthen the case that Australian institutions can organise and learn from bounded adoption. They do not show that an AI component is indispensable, that benefits survive a sector shock, or that a national function has passed its gates.
The 84-package result
Every eligible risk–function cell has four pathway packages in the scorecard. P1 and P2 receive a partial delivery state in ordinary conditions because existing institutions and bounded governance can plausibly operate. P3 and P4 remain unresolved because their civic-time, participation, coordination and formal-connection components are not established at the required breadth. Under S1–S5 every relied-upon package retains an explicit unresolved endurance test, owner and checkpoint.
How the delivery packages change by risk
The common template does not make the 21 cases interchangeable. War and geopolitical disruption put sovereign supply, protected communications, civil preparedness and command authority at the centre. Forecasting can support a Defence, Home Affairs or sector decision, but its delivery test is whether a responsible official receives a calibrated warning early enough to alter an action. The fallback is not another general-purpose model. It is a maintained combination of intelligence, expert analysis, conventional modelling, exercises, reserves, allied and industry coordination and manual decision procedures. For infrastructure and logistics, the relevant owners include the responsible Commonwealth and state authorities and each regulated operator. A national strategy cannot substitute for evidence that fuel, medicine, communications or transport functions continue when several sectors claim the same scarce people and inputs.
Climate and ecological disruption shift emphasis to local physical systems and compounding
failure. The Bureau of Meteorology and Australian Climate Service may generate national evidence,
but a warning becomes resilience only through state, territory, local, infrastructure, health and
community decisions. FCIL requires an operator who can dispatch people and equipment, not only an
optimisation result. FCAR requires accessible evacuation, health and support continuity. FINF
requires trusted risk communication and correction. Each AI contribution must remain usable during
power, communications, water or transport disruption, and its own infrastructure demand must remain
inside the ecological veto. A model that improves normal-condition allocation but removes manual
competence or increases a local water constraint is not a net resilience gain.
Population ageing makes service authority, professional responsibility and relationship quality central. Commonwealth policy and funding ownership does not remove the operational authority of states, providers and practitioners. A bounded documentation or scheduling aid may reduce burden; a triage or assistive system may improve access. The delivery package must still identify who acts on an unsafe output, how the person contests it, which practitioner can override it, and how the service continues by telephone, face to face or through another accessible route. Workforce capacity is not merely a cost input: it is part of the safeguard. If claimed efficiency is achieved by withdrawing valued contact or making a person verify a system they cannot use, the living-well and distribution gates have failed even if transaction time falls.
AI-driven change creates the widest set of eligible functions because the technology affects institutions, work, cyber security and information systems simultaneously. Here the formal AI governance owner and the substantive service owner must both be named. The accountable use-case owner can manage the AI lifecycle, but cannot take over an electoral decision, clinical judgement, emergency command or statutory discretion they do not lawfully hold. Conversely, the substantive owner cannot delegate model, data, vendor and incident risks away through procurement. A workable package joins both accountabilities and states the escalation path when they disagree.
These distinctions also affect procurement. Forecasting may require access to observations, calibration records and specialist compute. Infrastructure systems may require operational- technology integration, secure network segmentation and a manual control room. Care applications may handle health or disability data and require accessibility testing and clinical/service assurance. Cyber systems require least privilege, adversarial testing, audit logs and a named incident commander. Information and deliberation systems require source records, model-role disclosure, moderation, correction and an independent record of minority reasons. A generic whole-of-government contract cannot, by itself, satisfy those mission obligations.
Finally, coordination has a capacity cost. The same cyber specialists, procurement teams, evaluators, emergency managers, carers and community facilitators may be required by several packages at once. The 84-package map therefore does not imply 84 independent projects. Owners must publish where capability is shared, which function has priority under stress and what happens when two pathways depend on the same vendor, data feed, grid connection or workforce. Without that portfolio view, individually plausible packages can still fail together.
What this means
Australia has many of the right organisations, but an organisation chart is not a delivery system. Broad resilience requires proof that authority, people, infrastructure, procurement, assurance and coordination join up for each task. That proof is strongest for bounded forecasting and cyber work and weakest for broad civic and cross-system delivery.
Pass 2 — Safeguards and Dependency Exits
R3-T2 — Safeguarded endurance
The safeguard question is not whether a policy contains good principles. It is whether people and institutions retain a net gain when the AI system is wrong, attacked, unavailable, unaffordable, changed by its provider, or ecologically constrained.
The minimum package is:
- a named human with authority to override, pause or stop consequential action;
- a visible route to correction, appeal and independent review;
- privacy, rights, safety and security controls proportionate to the use;
- least privilege, auditability and bounded autonomy;
- a staffed manual, non-digital or non-AI fallback with a tested recovery time;
- substitutable vendor, model, cloud and compute arrangements where feasible;
- exportable data, documentation and organisational knowledge;
- monitoring of outcomes, drift, incidents, affected groups and unintended effects;
- a mission-level energy, water, material, emissions and rebound account; and
- explicit redesign, narrow, substitute, stop and exit triggers.
The DTA standard covers much of this design space, including continuity, safe rollback, incidents and decommissioning. ACSC guidance similarly requires strong fundamentals, human oversight, recoverability, constrained permissions and ongoing cost-benefit-risk review. These are credible control baselines. They are not evidence that each operator has practised the fallback or can replace a provider during S5. The bounded search located standards, guidance and audits, but not a complete public set of package-level continuity and exit exercises.
Human agency and living well
For care and public services, override must be real for the person as well as the operator. A telephone number that leads back to the same automated process is not a non-digital alternative. Supported decision-making, practitioner judgement, consent, complaint, explanation and service continuity must remain usable.
Australian data show why averages are unsafe. Disability and participation evidence describes
diverse access and inclusion barriers. Carer-support indicators vary by geography and age and have
important precision and coverage limits, including exclusion of very remote areas in the cited
measure. No complete intervention-specific AI comparison was located for carers, disabled people,
regional communities and people outside standard employment across functional ability, contact,
skill, agency, override and continuity. ER-06 therefore remains UNRESOLVED, owned by Health,
Disability and Ageing, Social Services, relevant state/service owners and an independent evaluator,
with the 2029 checkpoint.
Ecological lifecycle and sovereignty
AI infrastructure has real material dependencies. International energy analysis establishes potentially material data-centre electricity demand and uncertainty. Australian parliamentary work identifies energy, water, land, materials and equipment renewal across the lifecycle. The Australian Government's data-centre expectations treat energy, water, social licence and national interest as explicit issues. Yet those system and policy sources cannot tell us the net footprint of a specified forecasting, care, cyber, information or deliberation mission.
ER-05 remains UNRESOLVED. Each procuring entity owns the mission account, with operator data and
DCCEEW, AEMO or relevant state planning and water evidence. The account must cover training and
inference, shared infrastructure allocation, grid and water location, hardware renewal, embodied
materials, rebound, supplier and sovereign dependency, and the lower-resource comparator. A generic
efficiency promise cannot pass the ecological veto.
Gate and veto state
| Gate or veto | State | Why | Owner and checkpoint |
|---|---|---|---|
| Ecological no-trade-off veto | UNRESOLVED |
No complete mission-level Australian lifecycle account across the relied-upon systems. | Procurer + operator + DCCEEW/relevant state authority; 2029. |
| Democratic/information no-trade-off veto | UNRESOLVED |
Provenance and process signals do not establish durable judgement, formal influence or S4/S5 capture resistance. | Formal decision owner + AEC/regulator/evaluator; 2031. |
| Human agency | partial |
Human-owner and contestability rules exist; package-level accessibility and exercised override remain incomplete. | Service/system owner; 2029. |
| Living well | UNRESOLVED |
Functional, relational and agency outcomes over the comparator are not established by material group. | Health/service/evaluation owners; 2029. |
| Fair distribution | UNRESOLVED |
Contextual inequality is documented; intervention-specific benefits, burdens and fallbacks are incomplete. | Delivery owner + independent evaluator; 2029. |
| Security/sovereignty | partial / UNRESOLVED |
Cyber guidance is strong; sovereign supply, provider exit and S1/S5 exercises are package-specific and incomplete. | System owner + ASD/ACSC/sector assurance; 2033. |
No positive average can bypass either veto or any failed group.
What this means
Good safeguards now exist as policy and design requirements. The missing step is operational proof: people must be able to override and appeal, services must keep working without the tool, owners must be able to leave a provider, and the material footprint must be counted. Until then, “responsible AI” describes an obligation, not an achieved resilience result.
Pass 3 — Formal Democratic Connection
R3-T3 — From discussion to accountable action
Broad civic resilience relies on more than better conversation. An OWS-style or community mechanism must connect voluntary, representative and reason-giving participation to a lawful decision without pretending that participants automatically bind everyone else.
For each relied-upon mechanism, the complete object is:
- a voluntary and issue-bounded remit;
- a defined affected public and a measured representation frame;
- transparent recruitment, weighting and remedies for access barriers;
- conflict declarations and evidence rules;
- independent moderation and a disclosed, bounded AI role;
- preserved minority reasons and unresolved disagreement;
- a named formal decision owner before participation begins;
- a published acknowledgement and acceptance/rejection reasons;
- a named action owner, milestone and resources for accepted action;
- a feedback and correction loop showing what happened;
- capture, impersonation, manipulation and provider-bias resistance under S4 and S5; and
- a non-AI facilitation and record path if the model or provider is withdrawn.
Advice without acknowledgement fails this test. A published thank-you without reasons fails. A reasoned response without an action owner and milestone is incomplete. A high participant count does not establish representation. Automatic binding authority and constitutional redesign remain outside scope.
What current evidence supports
The strongest positive evidence is narrow. The UK AI-mediation experiment demonstrates that an AI system can produce statements participants prefer while incorporating minority critiques. That is useful evidence about synthesis under controlled conditions. OECD work provides authoritative design patterns for institutionalising deliberative processes and for public response and follow-up.
The transfer gap is decisive. The experiment did not test Australian representation, a formal
decision, implementation, multi-year legitimacy, adversarial S4 participation or S5 provider loss.
The OECD material is design guidance, not a causal outcome. The Australian search did not locate a
complete evaluated chain meeting ER-04 and ER-07. Those requirements remain UNRESOLVED, with
a named formal decision owner and independent evaluator responsible for evidence by 2031.
Information integrity is part of the connection
The AEC says its own AI use is limited and Australian elections remain predominantly manual. It also explains that AI-generated campaign material is not generally prohibited, while authorisation and a tightly bounded misleading-voting offence cover only part of the problem. ACSC guidance says content credentials can expose provenance but cannot determine truth; adoption is opt-in and absence of credentials is not itself evidence of falsity.
An OWS mechanism therefore cannot outsource judgement to a detector or a model. It needs source triangulation, disclosed uncertainty, slow-down rules, visible correction, an adversarial challenge route and a trusted human record. Under S4, recruitment and agenda-setting must resist coordinated capture. Under S5, the process must continue without the AI component.
The civic-time bridge
Report 2's civic-time result is preserved. Reduced working hours can improve wellbeing, but the chain from reduced hours to usable time, representative participation and formal influence is not demonstrated. Equivalent participation capacity is required for carers, retired people, disabled people, students, unemployed people and others outside standard employment. P4 cannot receive a gain merely because some workers have time or because a platform is available.
What this means
AI may help a group organise reasons. Democracy improves only when the right people can take part, dissent stays visible, and someone with lawful authority must answer and act. That full connection has not yet been demonstrated in Australia, so P4 receives no presumed democratic bonus.
Pass 4 — Shock Endurance and Milestones
R3-T4 / R3-T7 — One scorecard under S0–S5
The four pathways are compared on the same 3,528 eligible scorecard rows. No probabilities are assigned and no average hides a condition failure.
| Condition | Required proof | Current result across relied-upon packages |
|---|---|---|
S0 stable pressure |
Sustained workforce, outcomes, normal assurance, fair access and institutional learning. | P1/P2 have partial delivery foundations; P3/P4 broad civic components remain unresolved. |
S1 strategic/supply shock |
Sovereign inputs, communications, coordination, manual continuity and vendor/cloud/compute exit. | High-level preparedness and risk ownership exist; complete package exercises and exits are unresolved. |
S2 climate/infrastructure compound |
Power, water, communications, logistics, physical access, ecological limits and cross-system recovery. | Compound-risk evidence is strong; mission footprint and multi-system continuity evidence are incomplete. |
S3 care surge |
Workforce load, triage authority, consent, accessibility, fallback and disaggregated living-well outcomes. | Existing care institutions and group baselines exist; intervention-specific continuity and group outcomes are unresolved. |
S4 democratic-information shock |
Independent judgement, provenance limits, representative access, formal response, correction and capture resistance. | Layered controls are plausible; durable Australian effect and full formal connection are unresolved. |
S5 AI-system shock |
Human incident command, safe shutdown, offline operation, substitution, recovery and provider exit. | Standards require continuity and decommissioning; operational-scale evidence across all packages was not located. |
All 144 accepted interaction rows were reconciled without changing their inherited state. Supported
or qualified links remain eligible; no function result transfers between risks. ER-08 is complete
as an aggregation audit: each interaction retains its ID, affected functions/domains, pathway,
condition, owner, 2033 checkpoint and no-probability limit. Higher-order risk coupling remains a
2033 exercise question.
R3-T5 — Milestone integrity
| Date | Evidence due | Failure response |
|---|---|---|
| 2027 | Accepted package definition; accountable decision, delivery and evidence owners; baseline; interaction map; comparator; impact assessment; safeguard and funded implementation plan. | Publish the gap and pause or retest the affected package. Do not call foundations complete. |
| 2029 | Bounded trials with attributable outcome, harm, distribution, lifecycle, fallback and failure data against the inherited comparator. | Narrow, redesign, substitute or stop the function. |
| 2031 | Cross-domain evidence of any indispensability claim; living-well evidence; representative civic participation; published formal response and action. | Reclassify the necessity or civic claim; substitute the stronger pathway; do not infer influence. |
| 2033 | Operational-scale S1–S5 exercises; recovery times; manual/offline continuity; vendor/model/cloud/data/knowledge exit; both veto tests. | Suspend scale-up, strengthen fallback, exit the dependency or reject the pathway. |
| 2035 | Realised capability and outcomes compared symmetrically across P1–P4 under accepted adequacy. | Return the warranted five-state result; do not move the date. |
The canonical backcast contains 672 rows at each date. All 2,940 eligible rows now carry an R3 delivery, shock, gate, evidence, owner, review and response marker. The 420 ineligible rows carry exclusion-only reconciliation. Future dates are not marked as achieved. Their unresolved evidence state is paired with an owner and failure response.
Falsifiers and stop/exit triggers
The broad proposition is narrowed or rejected for a package if the non-AI comparator meets adequacy; the AI component supplies no material attributable gain; any group loses essential access; independent judgement or human contact deteriorates; ecological or information vetoes fail; a provider exit cannot preserve the function; an S1–S5 exercise fails recovery; or P2/P3 matches P4 without the broad coordination burden.
Stop or exit immediately where a use causes serious rights or safety harm, cannot be overridden, corrupts a consequential decision without correction, exposes protected data beyond the accepted boundary, or leaves an essential service without a competent fallback. Redesign or narrow where the mechanism helps only a defined subgroup or condition. Substitute the inherited non-AI package where it meets the outcome more safely.
What this means
The backcast is a set of promises with consequences, not a schedule for optimistic delay. Each checkpoint asks for a different kind of proof. Missing proof changes or stops the claim; it cannot be relabelled “progress” and pushed to the next year.
Pass 5 — Delivery Verdict by Function and Pathway
R3-T1–T5 function results
| Function | Inherited verdict | Delivery and endurance finding | Gate effect | Report 3 function result |
|---|---|---|---|---|
FANT anticipation/forecasting |
USEFUL NOT NECESSARY |
Credible operators, research and decision uses; attribution to acted-on outcome, S1/S2 continuity, mission lifecycle and full fallback remain incomplete. | Ecological, distribution and sovereignty evidence unresolved. | USEFUL NOT NECESSARY — medium confidence; unchanged. |
FCIL climate/infrastructure/logistics |
UNRESOLVED |
Named sector owners exist, but cross-system authority, workforce, manual control, recovery and exit are not demonstrated across the portfolio. | Ecological veto and S1/S2 continuity unresolved. | UNRESOLVED — insufficient package evidence; unchanged. |
FCAR care/living well |
UNRESOLVED |
Strategies and service owners exist; AI-over-comparator outcomes on function, contact, agency, safe fallback and material groups were not located. | Living-well, agency and distribution gates incomplete. | UNRESOLVED — insufficient outcome evidence; unchanged. |
FCYB cyber/AI threats |
USEFUL NOT NECESSARY |
Strong official case for bounded augmentation with human oversight and fundamentals; controlled necessity, sovereign exit and S5 recovery evidence incomplete. | Security is partial; ecological and provider-dependency evidence unresolved. | USEFUL NOT NECESSARY — medium confidence; unchanged. |
FINF information judgement |
UNRESOLVED |
Provenance and assistive synthesis can help, but truth, independent judgement, correction, manipulation and durable Australian outcomes remain unresolved. | Democratic/information veto unresolved. | UNRESOLVED — insufficient consequential-outcome evidence; unchanged. |
FDEL deliberation |
UNRESOLVED |
Promising bounded mediation mechanism and strong design rules; no complete Australian representative-to-formal-action chain or S4/S5 result. | Democratic/information veto and civic-time bridge unresolved. | UNRESOLVED — insufficient durable-outcome evidence; unchanged. |
No material evidence met the controlled-amendment threshold. None of the six functions is
NECESSARY.
Symmetric P1–P4 pathway comparison
| Pathway | Strongest good-faith implementation case | Delivery burden and result | Five-state pathway result |
|---|---|---|---|
P1 Trajectory Continuation |
Capable institutions, conventional technology, services, regulation, social protection, journalism and deliberation receive serious implementation. | Lowest new AI dependency; real baseline capacity, but accepted adequacy, ecological, care, information and compound-continuity gaps remain. | MIXED — substantial capability with unresolved mandatory cells. |
P2 Institution-Led AI Adaptation |
Bounded AI strengthens forecasting, services and cyber work while accountable institutions retain authority and fallbacks. | Most credible near-term AI delivery pattern; policy and technical controls exist, but outcomes, gates and S1–S5 exits are incomplete. | MIXED — useful bounded functions, no broad closure. |
P3 Partial Civic AI Transition |
Institutional AI plus literacy, shorter-work experiments and bounded civic processes may create learning without P4's full coordination burden. | Some mechanisms are plausible, but access, civic conversion, formal influence, distribution and endurance are uneven and unevaluated. | UNRESOLVED. |
P4 Broad AI-Enabled Civic Resilience |
Broad time and capability, representative communities and transparent AI-assisted reasoning could improve distributed adaptation and legitimacy. | Largest coordination and evidence burden; no demonstrated material durable civic gain above P2/P3; both vetoes and several gates unresolved. | UNRESOLVED. |
P4 is not penalised for being ambitious, and P1 is not rewarded for being familiar. All four use the same owners, outcome measures, conditions, gates and resource boundaries. P4 can outrank P2 or P3 only after a durable civic mechanism produces a material gain that narrower institutional or human-led practice cannot match.
What this means
The most credible AI uses remain narrow. P2 can plausibly deliver some of them, but that does not turn P2 into a complete resilience pathway. P4 remains a serious hypothesis worth testing, not an established destination.
Pass 6 — Cumulative Evidence Synthesis
Across three reports, the evidence resolves several confusions.
First, Australia's baseline is neither helpless nor adequate by assertion. It contains capable institutions, operational systems and feasible reforms, alongside implementation, ecology, care, information and continuity gaps.
Second, AI usefulness is real but bounded. Forecasting and cyber evidence supports assistive contribution. That evidence does not show that the strongest feasible comparator fails and AI alone closes a material gap. Adoption, model accuracy, faster drafting and policy intent remain upstream of the required outcome.
Third, delivery governance has improved. Accountable use-case owners, impact assessment, technical lifecycle standards, continuity, rollback, incidents and decommissioning are much better foundations than an ungoverned pilot. Independent audits nevertheless show that outcome definition, benefits measurement and oversight remain live problems even in mature agencies.
Fourth, the broad civic mechanism remains the least proven part of the pathway. AI-mediated synthesis has a credible experimental signal. Representative access, civic time, formal response, action, feedback, legitimacy and S4/S5 resistance have not been demonstrated as one Australian system. This is an evidence gap, not a finding that democratic innovation cannot work.
Fifth, the gates are substantive. Ecological costs cannot be inferred from generic data-centre numbers or waived by possible AI-enabled savings. Distribution cannot be inferred from population digital-access data. Human override cannot be inferred from a policy word. Sovereign exit cannot be inferred from a decommissioning requirement. Each becomes a package-level test.
Sixth, the strongest rival remains live. Institutional competence, workforces, public services, material capacity, conventional technology, regulation, social protection, journalism and trusted deliberation can supply much of the claimed resilience gain with fewer AI dependencies. P2 can add bounded assistance without requiring P4. The broad pathway must show a gain over those alternatives, not merely an attractive social vision.
Evidence limits and counterevidence
Public evidence is necessarily incomplete for defence, cyber and critical infrastructure. Protected exercise results may exist. This report does not equate public absence with operational absence; it requires an independently attestable result before assigning a pass.
Several sources are policies, strategies or standards. They establish authority and obligation, not compliance or outcome. International evidence transfers only after legal, institutional, population, infrastructure and culture tests. Future milestones cannot be evidenced in advance.
The research cut-off is also a genuine boundary in a fast-moving field. A later model, statute, audit or programme evaluation may materially improve one package while leaving the others unchanged. The stable claim IDs and dated checkpoints are designed for that case: evidence should change the smallest warranted finding, not silently rewrite the inherited comparator or the whole series conclusion.
Counterevidence prevents a simple negative story. Australian institutions do deliver at scale.
IP Australia's AI arrangements were largely effective. ACSC presents plausible and practical cyber
uses. Provenance can improve context. AI mediation can preserve minority critiques in a controlled
setting. Smaller models, clean supply and efficient infrastructure may reduce ecological costs.
Targeted assistive systems may improve access for particular people. Those findings justify bounded
testing and the two USEFUL NOT NECESSARY function results.
Where This Argument Could Be Wrong
The report may be too cautious if protected or unpublished Australian evidence already demonstrates package-level continuity, attributable avoided harm, provider exit and disaggregated outcomes. It may understate cyber necessity if machine-speed defence is indispensable to a defined response window and no feasible layered alternative can meet it.
It may be too optimistic if governance standards are not implemented, verification costs erase benefits, automation bias weakens judgement, care tools displace valued contact, infrastructure costs are larger than generic estimates, or vendor concentration makes fallback illusory. The P4 social mechanism may be infeasible at scale, or it may outperform this assessment if broad civic capacity produces coordination gains that short evaluations cannot see.
The strongest rival may also be over-idealised. Conventional reform faces political, workforce, fiscal and coordination constraints. The symmetry rule charges those constraints to P1–P3 as well as P4. Evidence that changes the answer must show the exact owner, mechanism, comparator, outcome, distribution, gates, condition and date rather than ask for credit because implementation is hard.
Implications — separate from the verdict
These are implications, not additional findings or deployment recommendations.
Any bounded programme should begin with the inherited non-AI comparator and a named decision owner. Procurement should require outcome measures, audit access, data and documentation portability, human authority, offline continuity, ecological allocation and a funded exit. Civic trials should name the formal responder before recruitment and publish reasons, action, milestones and correction. Evidence owners should report failures as carefully as successes.
The backcast can support disciplined learning. It allows a useful function to remain useful without being inflated into necessity, and a promising pathway to remain testable without being announced as delivered.
What this means
The trilogy has moved the argument from “AI might help” to a precise test of who must deliver what, under which shocks and safeguards, by which date. The answer is more cautious than the vision but more useful than a yes-or-no slogan.
Pass 7 — Final Hypothesis and Pathway Verdict
R3-T6 — Accepted aggregation order
The final sequence is: preserve the baseline and comparator; apply function additionality; test delivery and owner capability; test safeguards, fallback and exit under S0–S5; apply both vetoes and all mandatory gates; enforce the dated milestones; assign function results; assign pathway results; then aggregate without averaging.
The function layer contains two USEFUL NOT NECESSARY results and four UNRESOLVED results. No
function is NECESSARY. The pathway layer is MIXED for P1 and P2 and UNRESOLVED for P3 and P4.
The ecological and democratic/information vetoes are UNRESOLVED; human agency is partial; living
well and fair distribution are UNRESOLVED; security/sovereignty is partial or UNRESOLVED by
package. S1–S5 endurance and 2029/2031/2033 evidence remain incomplete.
Final cumulative T1–T7 / portfolio verdict: UNRESOLVED.
The accepted C2 hypothesis is not demonstrated on current evidence. It is not rejected as
impossible. A NECESSARY result cannot be aggregated because no exact function has met the
necessity test, both no-trade-off vetoes remain unresolved, other mandatory gates are incomplete,
and P4 has not shown a material durable civic-mechanism gain over P2/P3.
Function, pathway and portfolio separation
- Function:
FANTandFCYBremain useful but not necessary;FCIL,FCAR,FINFandFDELremain unresolved. - Pathway: P1 and P2 are mixed; P3 and P4 are unresolved. P2 currently has the clearest bounded delivery case, but no pathway passes the whole system.
- Portfolio: unresolved under the no-averaging, gate and veto rules.
What this means
Broad AI-enabled civic resilience remains a disciplined possibility, not a demonstrated 2035 delivery path. The evidence supports careful, reversible testing of bounded functions while strengthening the non-AI institutions and civic practices that every pathway needs. A later answer must be earned package by package and checkpoint by checkpoint.
The Bottom Line
Australia can make practical use of AI without making its resilience depend on an unproven broad system. Forecasting and cyber defence justify bounded assistance. Stronger lifecycle governance makes such work safer. The broad claim asks for much more: fair civic capacity, formal democratic influence, complete safeguards, ecological non-deterioration, sovereign exits and continuity through compound shocks.
That complete evidence does not yet exist in the controlled record. The honest result preserves what is useful, names what is missing and refuses to turn plans, standards, pilots or attractive mechanisms into delivery.
Acknowledgements
This report relies on public institutions, auditors, statisticians, scientists, researchers, service providers and communities whose records make independent scrutiny possible. Acknowledgement and source inclusion do not imply endorsement by any cited institution.
Authors
Rick Molony, Our Resilient World. AI assisted the research and drafting under human Product Owner direction.
Appendix A — References
The canonical evidence ledger is authoritative for exact claim locations, verification, counterevidence, transfer notes, confidence and ownership. This list is for readers.
EXT-005— Australian Department of Defence, 2026 National Defence Strategy and Integrated Investment Program, official overview.EXT-006— Department of Home Affairs, 2025 Critical Infrastructure Annual Risk Review, official release and linked review.EXT-011— Australian National Audit Office, Artificial Intelligence Use in IP Australia, Report No. 43 of 2025–26.EXT-012— Australian Treasury Evaluation Unit, Evaluation of a Trial of Generative AI (Copilot) in the Treasury.EXT-013— Australian Electoral Commission, AI and elections.EXT-014— ASD/ACSC and partner agencies, Content Credentials: Strengthening Multimedia Integrity in the Generative AI Era.EXT-015— OECD, Survey on Drivers of Trust in Public Institutions 2024: Australia.EXT-016— OECD, Eight Ways to Institutionalise Deliberative Democracy.EXT-019— International AI Safety Report 2026.EXT-020— Tessler et al., “AI can help humans find common ground in democratic deliberation”, Science 386 (2024), eadq2852.EXT-021— International Energy Agency, Energy and AI (2025).EXT-022— Jobs and Skills Australia, Australia's AI Transition: Jobs, Skills and the Future of Work.EXT-023— Productivity Commission, Harnessing Data and Digital Technology (2025).EXT-024— Australian Bureau of Statistics, Characteristics of Australian Business, 2024–25.EXT-025— Department of Industry, Science and Resources, current Australian AI policy and the National AI Plan.EXT-026— Australian National Audit Office, Governance of Artificial Intelligence at the Australian Taxation Office.EXT-027— Australian Treasury, 2023 Intergenerational Report.AHL2-SRC-0005— ASD/ACSC, Opportunities for AI in Cyber Defence, updated 12 August 2026.AHL2-SRC-0011— Australian Government, Data Centre Expectations.AHL2-SRC-0014— AIHW, People with Disability in Australia — Social Inclusion and Participation.AHL3-SRC-0001— Digital Transformation Agency, Policy for the Responsible Use of AI in Government 2.0 and AI use-case impact-assessment requirements.AHL3-SRC-0002— Digital Transformation Agency, Technical Standard for Government's Use of Artificial Intelligence, lifecycle statements and use-case applicability.AHL3-SRC-0003— Senate Select Committee on Adopting Artificial Intelligence, report chapter 6, environmental impacts.AHL3-SRC-0004— AIHW, Carer Satisfaction with Support, disaggregated indicator and notes.
Mandatory supplied sources SUP-005–SUP-016, SUP-022–SUP-027, SUP-029, SUP-034 and
SUP-036–SUP-039 were used within their registered provenance, method, proposal, context or
reader-pattern roles. None was treated as evaluated national proof. All inherited Report 1–2
source rows remain in the canonical ledger.
Appendix B — Glossary
Broad AI-enabled civic resilience: P4's combination of broad usable civic capacity, widespread AI/information skills, representative communities and formal decision/action connections.
Delivery package: one eligible risk–function under one pathway, with authority, workforce, dependencies, safeguards, fallback, exit, evidence owner and milestone.
Formal decision owner: the office or body with lawful or delegated power to accept, reject or act on advice and publish reasons.
Human override: a competent person's real authority and practical ability to pause, correct, substitute or stop the AI-assisted action.
Mission-level lifecycle account: an allocated account of energy, water, emissions, land, materials, hardware renewal, rebound and supply effects for the specified function and comparator.
OWS-style mechanism: a voluntary, issue-bounded, transparent, representative and reason-giving community process with no automatic binding authority.
Provider exit: the tested ability to preserve the function, data, documentation and knowledge when a vendor, model, cloud or compute service changes or disappears.
UNRESOLVED: evidence is inadequate for a stronger classification; the missing evidence,
owner, checkpoint and response must be explicit.