plain.txt

ctrl:cyber

Making sense of the stories shaping cybersecurity, privacy, AI, and everything in between. plain.txt unpacks what matters as we navigate an increasingly complex digital landscape – for individuals, organisations, and society alike – cutting through noise to focus on what’s actually happening, and what it means in practice. Hosted by Arjun Ramachandran and Jordan Wilson-Otto, bringing a practitioner-led perspective from their work at ctrl:cyber, an Australian cybersecurity firm helping organisations manage cyber risk across the full security lifecycle.

  1. 6d ago

    #159 Cyber breakout - What frontier AI means for cyber risk (part two)

    *** This is part two of our two-part series on how frontier AI is reshaping cyber risk. See part one here: https://podcasts.apple.com/au/podcast/158-cyber-breakout-what-frontier-ai-means-for-cyber/id1616386… *** Over recent weeks a wave of disclosures have lit up the technology industry about the prospect of "rogue AI". OpenAI first revealed a frontier model had broken out of its sandbox during a test and hacked into Hugging Face's network. Shortly after, Anthropic surfaced three similar incidents from its own test logs. Meta and the UK AI Security Institute admitted similar observations, while a Melbourne man made the news after claiming his AI agent hacked his gym's booking system to move him up the waitlist by cancelling someone else's reservation. We discuss what this all means, including what the cyber security industry has made of these incidents and the lessons they are drawing about how to stay safe from autonomous AI.  We also deconstruct the language and framing being used to describe these events - with phrases like "cheating" and "going rogue" investing AI with a sense of agency. The episode closes with a view of how these incidents much shape the broader public policy debate about proprietary vs open-weight models .   LinksArticle about OpenAI / Hugging Face containment incident (TechCrunch) https://techcrunch.com/2026/07/10/openai-agent-escaped-sandbox-hacked-hugging-face/OpenAI disclosure https://openai.com/index/hugging-face-model-evaluation-security-incident/ OpenAI's technical recounting of the incident at Black Hat https://www.youtube.com/watch?v=87DyyMV0kCY Anthropic disclosure https://www.anthropic.com/research/containment-disclosureUK AI Security Institute disclosure https://www.aisi.gov.ukArticle about gym incident (ABC News) https://www.abc.net.au/news/science/2026/andrew-ai-agent-gym-booking-hack/Marcus Hutchins on agentic AI attacks at Black Hat https://www.linkedin.com/posts/malwaretech_one-of-the-interesting-takeaways-from-black-share-749306…Open letter on open weight model access https://www.microsoft.com/en-us/corporate-responsibility/wp-content/uploads/2026/07/open-weight-mod…plain.txt Episode 158 — Part 1: Frontier AI and the pressure on cyber fundamentals https://podcasts.apple.com/au/podcast/this-week-in-digital-trust/id1616386683   CreditsEditing and post-production by Martin Franklin (East Coast Studio) www.eastcoaststudio.com.au

    #159 Cyber breakout - What frontier AI means for cyber risk (part two)
  2. Aug 11

    #158 Cyber breakout - What frontier AI means for cyber risk (part one)

    *** This is the first part of a two-part series on how frontier AI is reshaping cyber risk. *** In recent months the cyber security industry has been grappling with a key question: how do highly capable frontier AI models change the threat environment? In this episode we break this question down by looking at how AI has affected the cat and mouse game between attackers and defenders, and the operational reality facing most organisations. In turns out that, while the technologies behind this disruption are undoubtedly advanced, many of the lessons for businesses are pretty old school. In part two we'll explore the growing coverage of so-called "autonomous AI security incidents". Links Anthropic - Project Glasswing overview https://www.anthropic.com/glasswing UK AI Security Institute independent evaluation of frontier AI cyber capabilities https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities Mozilla vulnerability findings using Mythos (Wired) https://www.wired.com/story/anthropic-claude-ai-model-mozilla-firefox-vulnerabilities/ Why AI has not yet meant more hacks (Risky Business podcast) https://risky.biz APRA letter to regulated entities on frontier AI and cyber risk https://www.apra.gov.au/news-and-publications/apra-letter-industry-artificial-intelligence-ai ASIC letter to licensees and directors about cyber risk https://download.asic.gov.au/media/xhrf1w0e/26-092mr-open-letter-to-afs-licensees-and-market-participants.pdf Trump executive order https://www.cnbc.com/2026/06/02/trump-executive-order-ai.html Credits Editing and post-production by Martin Franklin (East Coast Studio) www.eastcoaststudio.com.au

    #158 Cyber breakout - What frontier AI means for cyber risk (part one)
  3. Jul 30

    #157 AI pendulum - How Pope Leo, Trump and the Australian public have swung sentiment

    This week we check in on what we've previously called the "AI pendulum" - the swing between a pro-safety, pro-regulation instinct that marked AI conversations a couple of years ago to the hands-off, innovation-first mindset dominating the last 12 months. Recent events indicate the pendulum may be swinging back towards a more cautious and considered view of AI. The most striking incursion came from the Vatican, with Pope Leo XIV issuing "Magnifica Humanitas" a 42,000-word encyclical on the moral challenges of AI. We also explore the Trump Administration's recent executive orders and other moves to bring more government scrutiny to frontier models, and new research from the Tech Policy Design Institute that shows strong support by Australians for AI regulation. LinksFull encyclical — Magnifica Humanitas https://www.vatican.va/content/leo-xiv/en/encyclicals/documents/20260515-magnifica-humanitas.htmlArticle about AI encyclical (Time) https://time.com/article/2026/05/25/pope-leo-encyclical-ai-magnifica-humanitas/Analysis of AI encyclical (Brookings) https://www.brookings.edu/articles/understanding-pope-leos-ai-encyclical/Article about Trump executive order (CNBC) https://www.cnbc.com/2026/06/02/trump-executive-order-ai.htmlTPDi report — Earning Trust: Unlocking AI Adoption for Australians https://techpolicy.au/news/earning-trustTPDi — AI Agency Tool and 2025 Australia AI Agency Assessment https://techpolicy.au CreditsEditing and post-production by Martin Franklin (East Coast Studio) www.eastcoaststudio.com.au

    #157 AI pendulum - How Pope Leo, Trump and the Australian public have swung sentiment
  4. Jul 13

    #156 False choice, real harm - how power asymmetries and dark patterns erode privacy

    In this episode we break down the OAIC's determination against Australia's largest rental technology platform ("RentTech") 2Apply. After a year-long investigation, Privacy Commissioner Carly Kind found that 2Apply collected personal information far beyond what was reasonably necessary, and via means deemed unfair. The ruling is another example of the Commissioner's more assertive enforcement posture. Noting the challenges in the housing market facing renters, we unpack how this determination might also matter more broadly to any situation where there's an imbalance of power. We also explore how the ruling applies the concept of "online choice architecture", in which the design of digital platforms can shape the decisions people make. LinksOAIC media release https://www.oaic.gov.au/news/media-centre/renttech-platforms-must-stop-unfair-and-excessive-personal-information-collection,-says-privacy-commissionerFull determination https://www.oaic.gov.au/__data/assets/pdf_file/0022/263254/IRE-Pty-Ltd-Privacy-2026-AICmr-24.pdf Reporting on poor real estate agent cybersecurity (Josh Taylor, The Guardian) https://www.theguardian.com/australia-news/2026/feb/02/real-estate-agents-in-australia-using-apps-that-leave-millions-of-lease-documents-at-risk-digital-researcher-says Previous plain.txt interview with Commissioner Carly Kind https://podcasts.apple.com/au/podcast/151-trust-is-built-here-privacy-awareness-week-with/id16163866... CreditsEditing and post-production by Martin Franklin (East Coast Studio) www.eastcoaststudio.com.au

    #156 False choice, real harm - how power asymmetries and dark patterns erode privacy
  5. Jun 29

    #155 Australia's AI moment - Lee Hickin, National AI Centre

    Australia is one of the world's top per capita users of AI, but outside of large enterprises many businesses aren't using it. In this episode, we speak with Lee Hickin, Executive Director of the National AI Centre (bio below) about what it will take to close the gap between awareness of AI and safe and confident adoption. We explore current attitudes to AI in Australia, what the NAIC's data says about adoption across different sectors, and where Australia should position itself in the "AI risk vs AI opportunity" narrative. Lee also shares his view of why getting this moment right matters not just for improving productivity, but to enhance Australia's place in the global economy. BIO: Lee Hickin, Executive Director, Australian National AI Centre. Lee has over 30 years’ experience in the technology industry, having been in technical, sales and business development roles. Most recently he was the CTO for Microsoft ANZ and then lead the Asia region for Microsoft’s global Responsible AI team. Lee has worked across the UK, Asia, and Australia, before joining the Federal Government. In addition to his time at Microsoft, Lee led the Internet of Things team for Amazon Web Services in Asia Pacific, he was a CISSP security architect with RSA Security and worked at both Tivoli and IBM as a software engineer. During his time in industry, Lee has supported Governments around the world as an independent contributor; having been a member of the Singapore AI-Verify Board and a founding member of the NSW AI Assurance Committee. Today Lee leads the Australian National AI Centre (NAIC), with a mission to enable and support Australian Industry and society in its adoption of and acceleration through AI technology and services. He has a clear focus on the need for consistent and appropriate responsible safety mechanisms to support AI, balanced with the need to empower Australians with the confidence and trust in the positive and transformative potential of AI. Lee brings the importance of technical understanding combined with the need for clear and unambiguous language as we help shape a future where AI will be a powerful enabler of productivity, growth and society broadly. Links Lee Hickin — Executive Director, National AI Centre https://www.industry.gov.au/national-artificial-intelligence-centre/about-national-ai-centre/lee-hic... National AI Centre https://www.ai.gov.au/about/about-national-ai-centre" target="_blank" class="redactor-autoparser-object">https://www.ai.gov.au/about/about-national-ai-centre Australia's central AI resource platform https://www.ai.gov.au Australia's National AI Plan https://www.industry.gov.au/publications/national-ai-plan US export controls force Anthropic to disable Fable 5 and Mythos 5 globally — what happened (CSIS) https://www.csis.org/analysis/department-commerce-restricted-access-anthropics-latest-models-what-co... Global implications of the White House export controls on Anthropic (IAPP) https://iapp.org/news/a/the-global-implications-of-the-white-houses-export-controls-on-anthropic Expanding AI sovereignty to AI agency (TPDi) https://techpolicy.au/aiagency Safe AI Adoption Model (SAAM) https://www.saam.com.au/ Credits Editing and post-production by Martin Franklin (East Coast Studio) ⁠www.eastcoaststudio.com.au⁠

    #155 Australia's AI moment - Lee Hickin, National AI Centre
  6. Jun 17

    #154 Shattered shield - Product liability rulings crack social media's legal armour

    This week we explore a shift in how social media platforms are perceived, which could open the door to them taking greater accountability for potential harms experienced by users. The trigger is two recent landmark verdicts in the US. In California, a jury found Meta and Google negligent for the design of their platforms while in New Mexico, a jury ordered Meta to pay $375 million after it was argued the company misled the public about the safety of its platforms. Until now, platforms have largely sheltered behind a legal theory that argues that they aren't publishers and therefore not liable for the content posted by users or the harm it cause. These cases re-direct the source of harm to the way these platforms are designed - much more akin to how we think about product safety.LinksArticle about Meta and Google found liable (NPR) https://www.npr.org/2026/03/25/nx-s1-5746125/meta-google-social-media-addiction-trial Article about New Mexico child safety verdict (Reuters) https://www.aol.com/articles/jury-orders-meta-pay-375-210501487.html New Mexico Department of Justice — official verdict statement https://nmdoj.gov/press-release/new-mexico-department-of-justice-wins-landmark-verdict-against-meta/Argument against social media verdicts (TechDirt) https://www.techdirt.com/2026/03/26/everyone-cheering-the-social-media-addiction-verdicts-against-me... Australia's digital duty of care — issues paper (Department of Infrastructure) https://www.infrastructure.gov.au/department/media/publications/digital-duty-care-australia-developi... Australia advancing digital duty of care legislation (The Conversation) https://theconversation.com/australia-will-impose-a-digital-duty-of-care-on-tech-companies-to-reduce... Australia wants social media to be safe by design — what does that actually look like? (The Conversation https://theconversation.com/australia-wants-social-media-to-be-safe-by-design-what-does-that-actuall...CreditsEditing and post-production by Martin Franklin (East Coast Studio) www.eastcoaststudio.com.au

    #154 Shattered shield - Product liability rulings crack social media's legal armour
  7. Jun 2

    #153 Labour pains - How AI is reshaping the workforce

    Is AI going to take all our jobs? This week we dig into this question, starting with a report from Anthropic released this year that cuts against the prevailing panic. We identify some deeper and more nuanced impacts of AI on the labour force beyond the possibility of jobs disappearing - including the re-design of roles, the loss of insight that comes when we handover "mundane" work to AI, and the impact of AI on the next generation of workforce leaders. We also explore the vested interests that exist to promote the narrative around mass workforce displacement. Links Anthropic research: Labor market impacts of AI https://www.anthropic.com/research/labor-market-impacts?highlight=2026 Article about "AI washing" (Fortune) https://fortune.com/2026/02/10/ai-washing-and-forever-layoffs-why-companies-keep-cutting-jobs-even-a... Anthropic CEO's dramatic labour force prediction (Forbes) https://www.forbes.com/sites/kolawolesamueladebayo/2026/02/21/dario-amodei-doubled-down-on-his-ai-jo... Goldman Sachs AI labour force prediction https://www.goldmansachs.com/insights/articles/how-will-ai-affect-the-us-labor-market Research on AI and labour market (HBR) https://hbr.org/2026/03/research-how-ai-is-changing-the-labor-market Oped about Atlassian's job cuts (AFR) https://www.afr.com/technology/the-ai-lesson-atlassian-s-cannon-brookes-doesn-t-want-to-hear-2026031... Global tech layoff numbers (RationalFX) https://www.rationalfx.com/forex-brokers/tech-industry-layoffs/ Blog on how history suggests AI-driven change isn't coming as fast as you think (Aaron Benanav) https://www.versobooks.com/en-gb/blogs/news/is-the-ai-bubble-about-to-burst Australia's National AI Plan https://www.industry.gov.au/publications/national-ai-plan Credits Editing and post-production by Martin Franklin (East Coast Studio) www.eastcoaststudio.com.au

    #153 Labour pains - How AI is reshaping the workforce
  8. May 19

    #152 Cute widget or security time bomb? The story behind website chatbots

    This week we take a closer look at the rapid spread of customer‑facing chatbots on websites and explore the growing risks that come with them.While they often look like a simple website widget, chatbots are increasingly deeply integrated AI agents with access to sensitive systems, personal data and business processes. We talk about some of the real‑world snafus that have occurred, and then step through the practical risk and governance considerations for privacy, security and AI teams. Links: Article about Air Canada chatbot misinformation case (BBC) ⁠https://www.bbc.com/travel/article/20240222-air-canada-chatbot-misinformation-what-travellers-should-know Article about swearing chatbot (BBC) ⁠https://www.bbc.com/news/technology-68025677⁠ Article about NYC chatbot telling businesses to break the law (The Markup) ⁠https://themarkup.org/artificial-intelligence/2024/03/29/nycs-ai-chatbot-tells-businesses-to-break-the-law Article about California fire agency chatbot (The Markup) ⁠https://themarkup.org/artificial-intelligence/2025/07/09/californias-fire-protection-agency-made-an-ai-chatbot-dont-ask-it-about-evacuation-orders Article about McDonald’s chatbot breach (News) ⁠https://www.news.com.au/technology/online/hacking/dystopian-mcdonalds-ai-chat-bot-olivia-hacked-with-simple-password/news-story/2c0f09f9fb0396f6ca17c56419133fee Article about Salesforce hacks (AFR) ⁠https://www.afr.com/technology/australian-boards-caught-up-in-global-hack-after-portal-breach-20251031-p5n6ui AI As normal technology (Arvind Narayanan and Sayash Kapoor) https://www.normaltech.ai/p/ai-as-normal-technology Credits: Editing and post-production by Martin Franklin (East Coast Studio) www.eastcoaststudio.com.au

    #152 Cute widget or security time bomb? The story behind website chatbots

About

Making sense of the stories shaping cybersecurity, privacy, AI, and everything in between. plain.txt unpacks what matters as we navigate an increasingly complex digital landscape – for individuals, organisations, and society alike – cutting through noise to focus on what’s actually happening, and what it means in practice. Hosted by Arjun Ramachandran and Jordan Wilson-Otto, bringing a practitioner-led perspective from their work at ctrl:cyber, an Australian cybersecurity firm helping organisations manage cyber risk across the full security lifecycle.

You Might Also Like