The federal government's chief digital agency is defending its cloud and procurement settings as technology-neutral and resilient, as one of its key software suppliers warns the public service is drifting into deeper dependence on foreign tech companies and brittle legacy systems.
In a policy white paper, software company Red Hat has urged the government to take a more deliberate approach to open-source software across the public service. It said procurement habits and risk culture have steered agencies towards closed proprietary ecosystems dominated by US tech companies.
The paper said departments have routinely chosen cloud providers such as Amazon Web Services and Microsoft because of standard insurance and indemnity clauses, combined with high perceived risk around complex deployment leading to vendor lock-in.
Vendor lock-in occurs when an agency becomes trapped with a single provider and its ecosystem, making it too expensive or complex to switch to a rival.
Red Hat's Canberra-based public sector senior director, Brendan Hawke, said long-neglected legacy environments sat at the core of the problem.
"The cost associated with supporting a legacy system is usually a lot higher," Mr Hawke said. "You also have to ask whether you're comfortable with the vulnerabilities in that system, that's a really big one, and whether it's still fit for purpose for modern workloads."
At its core, the paper advocated an open-source model, where underlying software code is publicly accessible rather than hidden behind proprietary vendor licences, saying the approach would allow agencies to shift workloads between cloud providers without expensive re-engineering.
Red Hat said this portability would give local Australian information technology businesses a fairer shot at government work, cut long-term software costs and break down data silos across key portfolios like healthcare and energy.
The paper also framed open architecture as a national security hedge, citing longstanding warnings from security experts that foreign software dependencies left domestic infrastructure vulnerable to international trade disputes and privacy breaches.
Those fears turned into reality in June 2026, when the US Commerce Department abruptly imposed emergency export controls on artificial intelligence company Anthropic, forcing it to immediately cut off global access to its top-tier Fable 5 and Mythos 5 models.
Mr Hawke said rapid advances in AI would only magnify the risks in ageing systems.
"With agentic AI and the progression of technology at such a rapid rate, the instances of vulnerabilities ... is going to increase," he said. "It's not only your current systems that are going to be the problem; it's your legacy systems ... and how vulnerable they are going to become in the future."
Industry critics said that such unilateral disruptions left Australian institutions dangerously exposed whenever core government operations relied on proprietary stacks they could neither control nor easily exit.
However, the Digital Transformation Agency (DTA) rejected claims that its procurement settings favoured commercial vendors or excluded open-source providers.
DTA deputy chief executive officer Simon Quarrell said the agency maintained a strictly technology-neutral stance across government procurement.
"The DTA does not preference open-source or proprietary solutions," Mr Quarrell said. "Our marketplaces are designed to support agencies to choose the solution that best meets their needs and delivers value for money."
Mr Quarrell dismissed suggestions that contract guidelines structurally disadvantaged open-source vendors, and said insurance and indemnity rules were standard risk-management tools applied across all suppliers.
"The cost and types of insurances required may vary based on the risks of the product or service being supplied, not whether it is open source or proprietary," he said.
Addressing vendor lock-in concerns, Mr Quarrell said core principles from the 2011 open-source policy had already been absorbed into broader frameworks such as the Digital Service Standard, Digital and ICT Reuse Policy and Digital Sourcing Consider First Policy.
He said the DTA was incorporating stronger privacy, data portability, interoperability and exit requirements into the upcoming Digital Marketplace Panel 2 Software and Cloud module, alongside releasing new whole-of-government cloud computing guidance to support agency exit planning and legacy decommissioning.
Although the white paper urged systemic change, Mr Hawke said the industry was not asking for special treatment, backing the DTA's refusal to write a mandatory open-source preference into policy.
"Absolutely, and they should," he said of a technology-neutral stance. "I agree with that wholly."
Mr Hawke said open-source vendors had in the past run into difficulties with traditional insurance and indemnity settings.
The DTA was now "doing a really good job of accommodating open source software" and "leaning forward and understanding the benefits ... whilst maintaining a fair and equitable engagement around the whole of industry", Mr Hawke said.