Federated learning lets trusted partners train a shared AI on fraud, cyber, and disinformation without pooling raw data. A RAND analysis argues Australia should build that network at regional scale.
Fubon Financial Holdings' "Eagle Eye" fraud model reportedly stopped roughly NT$360 million (about A$17M or US$11M) from reaching scammers, with an 80% detection rate. The figures are Fubon's own and have not been independently audited. The model is built on federated learning, a way for trusted partners to train a shared AI without ever pooling their raw customer data. A July 2026 RAND commentary wants Australia to notice the technique, not just the headline number.
Federated learning, introduced by McMahan in a 2017 paper cited in the RAND piece, keeps data where it sits. Each partner trains a local model on its own records and only sends the learned patterns, the model updates, to a shared aggregator. No raw customer data, patient file, or intercept is pooled. The shared model improves as more participants contribute, and the partners retain control of their own information. Pilots in medical diagnostics and fraud detection have shown the approach can match the accuracy of centralized training.
Australia's December 2025 National AI Plan treats bilateral partnerships as the headline instrument for AI security cooperation, with the goal of making Australia a "partner of choice." Bird & Bird and White & Case both read the Plan as ambitious and operationally thin, and the CADE Project tracks the same gap. RAND's argument is that for the threats Australia cannot solve alone, the bilateral unit is the wrong one.
The threats are transnational by construction. Cyber intrusions, scam networks moving money across borders, deepfake-driven disinformation, and maritime domain awareness do not stop at a partnership line. A two-country pact sharpens cooperation inside its lane. It does not produce a shared model that recognizes a scam pattern seen in three other countries the previous week. Federated learning is the technique that lets a network of partners train that shared model while keeping their data local, and RAND positions Australia as a plausible first convener of a regional arrangement.
Australia already has the research base. Federated learning groups in Australian health and finance are publishing, so the techniques are not theoretical for those teams. What the Plan does not yet commit to is the connective tissue. Building a regional federated network means deciding who participates, what updates get exchanged, how disagreements are audited, and how a detection in one jurisdiction becomes a signal for the others. It also means investing in secure aggregation, differential privacy, and leakage testing on the model updates, plus a legal framework that lets a Singapore bank and an Australian telco share patterns without sharing customers.
The honest counterargument sits on the table. Federated learning for security cooperation is still early-pilot. The Fubon figure is vendor-reported. Broader claims about deepfake detection and cyber defense lean theoretical or narrow-pilot. Adopting the technique at regional scale would put Australia ahead of the threat set, and ahead of the evidence, at the same time.
The Plan is the natural place for that commitment. The current draft leaves it on the to-do list. Australia's first federated-learning test bed in finance or cyber will tell the rest of the story. Until then, bilateral pacts will keep signing while the actual signals slip across borders the agreements do not cover.