All episodes

AI & Tech Daily

Australia’s AI gap is organisational, not technological

20:43

Treasury finds that Australian businesses are experimenting widely with AI but rarely changing work deeply enough to unlock substantial productivity gains. OpenAI expands advertising around ChatGPT conversations, NVIDIA invests in MediaTek as NVLink reaches custom accelerators, and Broadcom brings private AI infrastructure and agent controls into VMware. We also examine urgent ServiceNow security patches, GitHub’s evolving agent-session tools, Google DeepMind’s double-blind evaluation pilot, and Google Cloud’s open-source Data Agent Kit.

Full transcript

Read the episode.

I'm Jesse Owen. This is AI and Tech Daily.

Australia’s Shallow AI Adoption

About two-thirds of Australian businesses say they use AI. Fewer than one in ten say they’ve adopted it significantly. That gap could decide whether the technology actually lifts productivity.

Australia’s access to AI isn’t the immediate problem worth dwelling on. Treasury advice provided to Treasurer Jim Chalmers suggests businesses are getting hold of the tools, but relatively few are integrating them deeply enough to produce substantial organisational change.

That distinction between using AI and changing around AI is crucial. A business can give staff access to a chatbot, add an assistant to office software or run a few trials without redesigning a single important process. The technology may save pockets of time, but those scattered gains don’t automatically change how the organisation operates.

Treasury’s view is that stronger productivity gains require changes to processes, business models, management practices and workforce skills. In plain terms, buying an AI product is the easy part. The harder work is deciding which decisions can be supported by it, which tasks need to be rebuilt, where human review belongs, how performance should be measured and whether staff have the skills to use the system safely.

The advice considered annual productivity growth of between 1.5 and 2 per cent as a plausible upside scenario. It also considered a downside range of 0.5 to 0.8 per cent. Those figures weren’t forecasts, and they shouldn’t be treated as promises about what AI will deliver. They were scenarios illustrating how much the outcome could depend on whether adoption is effective or superficial.

There’s a similar note of caution on employment. Treasury said a large AI-driven jobs shock hasn’t yet materialised in Australia. Officials are, however, monitoring overseas evidence concerning young and entry-level workers. That’s a sensible place to watch because junior roles often contain the structured research, drafting and administrative tasks that current systems can perform most readily.

There’s an important evidence limit here. The underlying Treasury note wasn’t published with the report, so we can’t inspect its methodology or see exactly how officials defined significant adoption. The headline figures still describe a recognisable pattern, but the categories aren’t transparent enough for precise comparisons between industries or company sizes.

My read is that Australia’s binding constraint may now be institutional capability rather than frontier-model access. Organisations don’t need another vague mandate to use more AI. They need managers who can redesign work, staff who can test outputs critically, and governance that allows useful experiments without turning customer data or consequential decisions into uncontrolled trials.

For policymakers, that points towards workforce development and support for operational change, not simply greater spending on tools or data centres. For business leaders, it makes the next question much more demanding than whether the company has an AI strategy. The useful question is whether any important workflow has become measurably better because of it.

Advertising Enters More ChatGPT Markets

That’s the Australian challenge. Now, a more immediate shift in how one of the biggest AI services pays its way.

OpenAI has expanded self-service advertising access around ChatGPT conversations across India, Europe, the Middle East and North Africa. The company also says ChatGPT Ads has reached a one-billion-dollar annualised revenue run rate and is used by tens of thousands of advertisers. Through its sales and partner network, advertising is available in more than 40 countries.

Those numbers are company claims, and OpenAI hasn’t supplied independent trust or privacy measurements alongside them. It also hasn’t given a country-by-country account of user availability, so the commercial footprint and the experience seen by individual users aren’t necessarily the same thing.

The more revealing detail is how ads are selected. OpenAI says advertisements are labelled, kept separate from answers and don’t influence answer generation. Selection can use the context of the current conversation. Where local settings permit, it may also draw on context from a person’s broader ChatGPT activity.

OpenAI says advertisers don’t receive access to private conversations. That’s an important separation, but it doesn’t remove the need for users to understand how their activity shapes what they see. Contextual advertising inside a conversational assistant feels different from an ad beside a search result because the conversation may involve personal plans, purchases or decisions. Even a clearly labelled placement can inherit some of the assistant’s perceived relevance and authority.

The trade-off is straightforward. Advertising can help finance wider access to a capable free service, while self-service buying allows more businesses to reach that audience without negotiating a managed-sales deal. But the cost of misplaced trust rises when commercial messages sit inside a tool people use to reason through choices.

For the general public, my practical judgement is to preserve a firm mental boundary: the answer and the advertisement may be visually separated, but they still share conversational context. OpenAI’s stated controls matter, yet long-term effects on behaviour haven’t been independently demonstrated. Labels deserve attention, especially when the conversation concerns money, health, travel or any other decision where commercial incentives could alter what feels like a neutral suggestion.

NVIDIA Extends Its Reach into Custom Chips

The business model around AI is changing, and so is the hardware bargain underneath it.

NVIDIA has announced a 3.5-billion-dollar investment in MediaTek through convertible bonds, alongside a broader partnership spanning data-centre accelerators, local AI computers and automotive systems. The most consequential technical element is MediaTek’s adoption of NVLink Fusion as a foundation for customer-designed XPUs.

An XPU here is a custom processor built for a customer’s particular workloads rather than a standard accelerator sold unchanged to everyone. Designing that chip is only part of the problem. It also needs to communicate quickly with CPUs, memory and other accelerators, fit into rack-scale systems and work with the surrounding software and infrastructure.

MediaTek plans to offer customers a route that combines custom accelerators with NVIDIA’s NVLink interconnect, chiplets, CPUs, memory architecture and rack systems. In effect, cloud providers and chip designers could differentiate the compute silicon while avoiding some of the engineering involved in building an entire data-centre platform around it.

The partnership also covers RTX Spark and DGX Spark-class local AI systems, as well as automotive platforms. But this is still a forward-looking announcement. There are no shipping dates, named customer commitments or independently measured performance results for the future products. Both companies caution that development, manufacturing and market acceptance may not match their plans.

For organisations considering custom accelerators, the potential advantage is a shorter and less risky integration path. Custom silicon may become more practical when it can slot into an established high-speed fabric and rack architecture. The strategic cost is dependence. If NVLink becomes a common bridge between outside accelerators and NVIDIA-centred systems, NVIDIA can strengthen its position even when it doesn’t manufacture every major compute chip in the rack.

My inference is that this could lower the initial cost and complexity of differentiation while raising the eventual cost of leaving the ecosystem. Buyers will need to assess the custom chip and the architecture around it as one decision, because an accelerator designed for deep integration with NVLink may not preserve much negotiating freedom later.

VMware Builds a Private AI Stack

For companies keeping sensitive data close, the pitch is shifting from raw compute to controlled operation.

Broadcom has introduced VMware Private AI Cloud, combining VMware Cloud Foundation infrastructure with model serving, private data pipelines, security controls and governance for AI agents. It’s aimed particularly at existing VMware customers that want inference and agent workloads beside on-premises data rather than sending everything to a public service.

Broadcom says its VMware AI Factory can operate more than 150 open and commercial models through VMware Cloud Foundation. The number is less interesting than the attempt to put models, infrastructure and operational controls into one managed environment.

AgentMinder is presented as a central control plane for binding agents to approved missions, tools and resources, while recording what they do. Broadcom also says the Tanzu agent runtime uses a deny-by-default approach: access to APIs, networks, MCP servers and the internet is blocked unless explicitly granted. Credentials are kept outside the agent’s visibility.

Those controls address a real enterprise problem. An agent that can act across internal systems needs a tighter security model than a chatbot that only returns text. Identity, tool permissions, network access, secrets and audit records all become part of the application. Putting those policies into the platform could make deployments easier to review, particularly in regulated environments or organisations with data-sovereignty constraints.

There are substantial unknowns. Broadcom hasn’t published pricing, independent security tests or a complete availability schedule for every named capability. Claims about production readiness, cost efficiency and security come from the vendor, so buyers still need to test how the controls behave in their own environment.

The judgement for existing VMware organisations is finely balanced. A joined-up private stack may make governed AI deployment faster because infrastructure teams can work with tools and operating patterns they already understand. It may also consolidate the models, runtime, policy layer and underlying private cloud with one supplier.

That lock-in isn’t automatically disqualifying, but it needs to be priced into the architecture. The more agent permissions and operational records become tied to a vendor-specific control plane, the harder a later migration may be. The sensible evaluation is therefore not only whether Private AI Cloud can run a useful model, but whether its identity rules, logs and agent policies remain portable enough for the organisation’s risk tolerance.

Maximum-Severity ServiceNow Flaws

Control planes only help when the control plane itself holds. ServiceNow has just provided a sharp reminder of that.

The company disclosed and patched four vulnerabilities in its AI Platform, including three with the maximum CVSS score of 10.0. The highest-severity flaws could allow code execution, privilege escalation or arbitrary database queries.

CVE-2026-18885 affects the GraphQL Composite Data API. It can permit arbitrary code execution and access to or modification of instance data. CVE-2026-18886 is an access-control flaw that can enable data modification and privilege escalation. CVE-2026-74820 is an SQL-injection vulnerability.

ServiceNow says those three flaws require no authentication and no user interaction, and have low attack complexity. That combination is why the maximum scores deserve attention. An attacker wouldn’t first need to compromise a staff account or persuade someone to open a file. Public reporting doesn’t establish whether any of the vulnerabilities were exploited before fixes became available, so there’s no basis for claiming a known campaign.

ServiceNow deployed fixes to hosted instances and supplied hotfixes for self-hosted installations running its Xanadu, Yokohama, Zurich and Australia releases. Hosted customers therefore received vendor action, while self-hosted administrators have a direct patching responsibility.

Still, neither group should treat the platform model as proof that remediation is complete. Self-hosted teams need to verify the relevant hotfix and confirm that exposed services are no longer vulnerable. Hosted customers should confirm their particular instance received the update and review available logs for suspicious activity, rather than assuming that an automatic rollout settles every operational question.

The potential blast radius is unusually serious because ServiceNow environments can connect HR, finance and operational workflows. As AI capabilities gain permission to retrieve data or take actions across those functions, a pre-authentication failure can reach far beyond the model interface itself.

For organisations, my assessment is that patch verification is the urgent task, followed by a review of how much authority the AI Platform can exercise. The lesson isn’t that agent platforms are inherently unsafe. It’s that their connections turn an ordinary application vulnerability into a possible route across many sensitive systems. Security teams need to map those permissions before an incident, because the CVSS score describes technical severity, not the full business impact of whatever the platform can reach.

Agent Sessions Become the Product

At the developer level, competition is moving into the less glamorous work of keeping agent sessions manageable.

GitHub’s August releases for Copilot in VS Code added side conversations, portable agent plugins, continuation of external sessions, multi-window access and browser-based feedback on page elements.

The slash B-T-W command opens a side conversation that shares the main chat’s context and prompt cache while the primary task keeps running. That gives a developer somewhere to ask a related question without interrupting the longer job or starting again with none of its context.

Developers can also continue recent Copilot or Claude sessions created in other applications. Multiple VS Code windows can connect to one Agent Host session, which should reduce the awkwardness of supervising work that spans repositories or parts of an application. In the integrated browser, feedback can be attached to selected HTML elements and handed to an agent as a batch, bringing interface review closer to the code-editing loop.

Several of these features remain experimental or vary according to the configured agent provider, API key, Copilot plan and current VS Code release. GitHub hasn’t published evidence that they reduce delivery time or defect rates, so workflow convenience shouldn’t be confused with demonstrated engineering quality.

Still, the product direction is useful. Once code generation is widely available, the differentiator becomes how well developers can preserve context, inspect changes, separate concurrent tasks and recover sessions across tools. My take is that teams should assess coding agents partly by those control surfaces, not only by impressive one-shot outputs. Continuity and review ergonomics may make agent work easier to supervise, but the gains only count when the resulting code survives the same testing and review expected of any other contribution.

Double-Blind Model Evaluation

Here’s a quieter experiment that could improve how closed AI models are tested without forcing either side to reveal its most sensitive material.

Google DeepMind has begun a pilot for cryptographically double-blind model evaluation. Outside evaluators can test a proprietary Gemini Flash Lite model on confidential benchmarks without exposing the benchmark prompts to Google or the model weights to the evaluators.

The pilot involves the Singapore AI Safety Institute, OpenMined, AVERI and MLCommons. It uses Google Cloud Confidential Space to verify cryptographically that the evaluation runs inside the intended protected environment.

The problem it addresses is benchmark contamination and mutual distrust. Evaluators may hold cyber, government or safety test sets that lose value if their prompts become known to model developers. The developer, in turn, may be unwilling to hand model weights to an outside organisation. A protected execution environment offers a middle layer: the benchmark and model can meet for evaluation while each remains concealed from the other party.

That could make testing closed models more credible and allow qualified safety institutes to use sensitive material they couldn’t otherwise share. It doesn’t eliminate trust. Some of that trust moves from contracts and organisational procedures into confidential-computing hardware, software and the cloud attestation process used to prove what ran.

This is a limited pilot, not an established evaluation standard or a broadly available service. DeepMind’s description of it as the world’s first evaluation of this kind is a company claim. The work also hasn’t shown that the approach scales across multiple providers, larger models or infrastructure operated by an independent cloud.

My judgement is that the mechanism is worth watching because it targets a genuine weakness in closed-model assessment. Public benchmarks can leak, while private benchmarks are difficult to run without revealing them. Cryptographic isolation may create a more useful compromise. Its credibility, though, will depend on whether the method can be reproduced across competing infrastructure and whether evaluators can independently verify the complete execution chain, rather than merely accepting another provider’s assurance.

What Changes for You

One release this week is immediately practical for people building data systems, provided their work already sits largely inside Google Cloud.

Google Cloud has released Data Agent Kit, a freely available open-source extension and coding-agent plugin for managing data assets, running queries, authoring pipelines and diagnosing failures from supported development environments. It’s intended for data engineers, data scientists and developers building data applications.

The kit works in VS Code-compatible IDEs and through plugins for coding agents including Claude Code and Codex CLI. It can generate declarative YAML pipelines, continuous-integration workflows and Apache Airflow DAGs, then monitor managed runs without requiring the developer to keep jumping between an editor and the cloud console.

Its Orchestration Pipelines framework supports BigQuery, Managed Service for Apache Spark and Managed Service for Apache Airflow, along with Dataform and dbt. For a team already using those services, the immediate change is less hand-written orchestration boilerplate and a shorter path from describing a data workflow to producing deployable configuration.

There are firm limits. Open-source access to the kit doesn’t make the underlying cloud resources free. Developers still need suitable Google Cloud permissions, the relevant paid services and enough infrastructure knowledge to review what the agent generates. Google also cautions that results vary with the selected model, available context and token depth. Production pipelines still need human validation, particularly around data access, retries, costs and failure handling.

Google’s dramatic productivity example is a vendor demonstration, not an independent measurement across production teams. So I’d treat the kit as workflow compression, not autonomous data engineering. It could remove repetitive setup and make diagnosis more convenient, but it also deepens coupling to Google Cloud’s data stack. For builders already committed to that environment, it’s newly worth testing on a bounded pipeline. The useful result would be reviewed infrastructure produced faster, not generated YAML accepted simply because an agent wrote it.

You'll find the sources and full transcript at owenonthenet.com. Thanks for listening.

Sources

Reporting behind this episode.

  1. abc.net.au/news/2026-08-31/ai-could-boost-australias-economy-treasury-flag-slow-uptake/107099934
  2. openai.com/index/expanding-access-to-ai-with-chatgpt-ads
  3. nvidianews.nvidia.com/news/nvidia-and-mediatek-deepen-long-standing-partnership-to-build-ai-edge-to-cloud-computing-platforms
  4. investors.broadcom.com/news-releases/news-release-details/broadcom-introduces-vmware-private-ai-cloud-enabling-enterprises
  5. support.servicenow.com/kb
  6. securityweek.com/servicenow-patches-3-critical-code-injection-vulnerabilities
  7. github.blog/changelog/2026-08-31-github-copilot-in-vs-code-august-2026-releases
  8. deepmind.google/blog/piloting-the-worlds-first-double-blind-ai-evaluations
  9. cloud.google.com/blog/products/data-analytics/build-data-pipelines-in-less-time-with-data-agent-kit
  10. docs.cloud.google.com/data-agent-kit