San Francisco Daily 360

collapse
Home / Daily News Analysis / Australian government cloud mandate sparks migration warnings

Australian government cloud mandate sparks migration warnings

Jul 30, 2026  Twila Rosenbaum 8 views
Australian government cloud mandate sparks migration warnings

Background and Policy Details

Australia's whole-of-government cloud policy, effective from 1 July 2026, mandates cloud as the default option when modernising IT infrastructure. The policy, prepared by the Digital Transformation Agency (DTA), establishes five broad requirements: prioritise cloud for new IT projects; use cloud to drive innovation including artificial intelligence (AI); adopt cloud securely and responsibly; actively manage cloud costs; and nurture cloud skills across the Australian Public Service (APS).

The first specific requirement is for agencies to adopt cloud solutions for all new digital and ICT initiatives and upgrades unless an alternative is justified. This represents a significant shift from previous permissive approaches, which allowed agencies to choose on-premise solutions more freely. The policy aims to modernise government IT, improve service delivery, and enable data-driven decision-making.

Migration Challenges and Expert Warnings

Despite the policy's strategic intent, industry experts have raised concerns. Gartner director-analyst Adrian Wong warned that a blanket mandate overlooks situations where an application or workload is a poor fit for cloud. Legacy applications, for example, often fail to fully utilise cloud capabilities, making them technically mismatched and sometimes unexpectedly more expensive to run in the cloud than in a local data centre.

Wong noted that while the policy frames the transition as moving away from ageing systems rather than a strict requirement to migrate every legacy app, aggressive timelines can drive poor decision-making. Organisations feeling rushed—especially those lacking adequate cloud planning and architectural expertise—are more likely to pursue poorly conceived lift-and-shift migrations. These hurried efforts frequently fail to meet expectations and form the basis for cloud project failures.

According to a Gartner report on handling cloud project failures, common reasons include workloads being inappropriate for the cloud, poorly chosen providers, bad design or implementation, inaccurate cost estimates, and integration issues. Some factors make workloads inherently more suited to on-premise deployment: high sensitivity to latency; strict data residency, compliance, or sovereignty mandates that cannot be satisfied with public cloud solutions; unique service-level agreements that cloud providers might not be able to meet; and environments requiring enterprise-controlled assets.

"Ultimately, avoiding cloud dissatisfaction requires agencies to have the time and flexibility to perform a detailed application portfolio analysis. While prioritising modern cloud solutions is a strong strategic aspiration, enforcing rigid decommissioning pressures risks forcing bad long-term fits just to satisfy policy requirements," Wong warned.

AI and Interoperability Requirements

Cloud platforms are seen as a way to create a more connected, responsive, and data-driven public sector, in part through AI adoption. While government entities are required to design for interoperability and portability to minimise supplier lock-in, they are only encouraged to ensure cloud services support open standards and APIs, and allow for data portability.

SUSE ANZ general manager Ben Henshall suggested the policy language indicates the DTA wants to avoid another "mother of all lock-in" situation that repeats historical mainframe problems. Once data is locked into a particular cloud, extraction becomes very hard and costly. Public clouds are designed as a "land grab" to capture as many departmental workloads as possible, he warned. "They're not making it easy to get out because why would they? It's not in their commercial interest to be open, interoperable, more standard spaces." For example, hyperscalers each have their own domain-specific languages for creating templates that specify operating systems and software for virtual machines.

Part of the problem for governments and businesses alike is that vast amounts of money are spent simply keeping the lights on and upgrading, rather than on innovation. Replatforming with low cost and effort is the "secret sauce" of open source, and of companies like SUSE, because they are agnostic, Henshall said. This allows agencies to spend more time deploying new features rather than draining budgets on system upgrades.

While SUSE's cloud provider partners offer utility, Henshall admitted they also pose risks and add cost because they rely on proprietary technology stacks, creating complications for multicloud environments. Departments such as education, health, defence, home affairs, and Services Australia are complex organisations with vast use cases and cannot source all capabilities from a single provider. This makes interoperability, portability, and integration vital.

Agentic AI and Data Sovereignty

Agentic AI is gaining attention as a way to automate workflows. Different systems within a process will use different large language models (LLMs) of varying sizes, meaning data processing needs will be highly varied. At one extreme, soldiers in disconnected, intermittent, and limited (DIL) environments require local processing. At the other extreme, health departments process large volumes of records to determine benefits or treatments. With many LLMs available—both open source and proprietary—Henshall said it is incredibly important for governments to retain sovereign control over their data and models. Governments are looking to open source LLMs to access the code, ensure explainability, and govern the models autonomously.

Vinayak Sreedhar, country manager for ANZ at ManageEngine, noted that the explicit push to embed AI readiness across cloud platforms is forward-thinking and necessary, but it is not a switch that can be flipped post-migration. "How is the data structured, governed and stored? How much compute is being provisioned? And how will models eventually be deployed? These questions require deliberate architectural decisions from day one. Those that treat AI as a future add-on rather than a current design requirement will be hit with expensive infrastructure rebuilds in a few years' time," Sreedhar said.

Security Considerations

Federal government agencies will have to navigate the cloud transition regardless of difficulty, especially regarding security. Henshall emphasised that no one wants to be responsible for accidentally putting information into a public AI system causing sovereign angst. A modern, defensible architecture is essential for hosting and running AI workloads safely and securely. SUSE helps government departments apply such architectures, adhering to Essential Eight principles, the Australian Signals Directorate's information security manual, and ISO 27001, ensuring zero-trust architecture that is portable, composable, and interoperable.

Sreedhar warned that the sheer scale of the transition creates a much larger attack surface. Recent cyber security legislative reforms have sharpened obligations for critical infrastructure operators, but agencies should treat those obligations as a baseline. "The vulnerability we see most often in cloud transitions isn't technical—it's the gap between IT teams and security teams during the migration itself. Security architects need to be part of the transition from procurement through to go-live and beyond," Sreedhar said.

Skills Uplift and Workforce Development

A policy framework is only as good as the people who implement it. The DTA has been clear that agencies must build the skills, infrastructure, and governance required to meet community expectations. However, workforce capability is almost always the most underfunded component of digital transformation. Agencies should evaluate their internal capability now, ahead of the 1 July deadline, and invest in genuine skills uplift where gaps exist.

"Getting the technology right matters, but so does building a public service that understands and owns what it's building," Sreedhar said. The policy's fifth requirement explicitly demands agencies nurture cloud skills across the APS. "Agencies won't be able to satisfy the policy simply by pointing to cloud deployments. That's the easy part. Agencies need genuine workforce development strategies and plans to close identified skills gaps. One of the ways we're addressing this at ManageEngine is at the operational layer, helping staff build fluency with hands-on training and tools spanning infrastructure, security and FinOps—the disciplines the DTA has specifically and rightly called out."

Reflecting on the skills mandate, Henshall described this aspect of the policy as a strong starting point offering good principles and guidelines. "It's there not as a stick, but as a compass," he said.

Preparing for the July 2026 Deadline

Agencies across Australia are now racing to meet the 1 July 2026 deadline. The policy applies to all non-corporate Commonwealth entities under the Public Governance, Performance and Accountability Act 2013. The DTA has provided a series of guidance documents and tools, but implementation remains a significant challenge. Many agencies still rely on legacy mainframes and custom-built applications that may be difficult or costly to migrate. The policy allows for exceptions where justified, but the burden of proof rests with the agency.

Industry observers suggest that the most successful agencies will be those that start early with thorough portfolio analysis, invest in cloud architecture expertise, and engage with multiple cloud providers to avoid lock-in. The focus should be on outcomes rather than simply ticking boxes. As Wong noted, the goal is not to move everything to the cloud but to modernise IT in a way that delivers better services to citizens while managing risks and costs.

Ultimately, the Australian government's cloud mandate represents a bold step toward digital transformation, but its success will depend on careful execution. The warnings from experts highlight the need for flexibility, planning, and sustained investment in people and processes—not just technology. The next few months will be critical as agencies finalise their migration strategies and prepare for the new default.


Source:ComputerWeekly.com News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy