Legacy modernization just made front-page financial news, and it didn’t come from a bank. In late February 2026, IBM shares fell more than 13% in a single trading session, wiping out roughly USD 31.6 billion in market value. The trigger wasn’t a product recall or a lawsuit, it was one announcement: An AI coding tool had just shown it could understand decades-old COBOL code at scale – raising a bigger question for investors: how much of the mainframe-services business could AI eventually automate?
For any CIO, CTO or Head of Digital sitting in a boardroom in Melbourne or Sydney, that sentence should land harder than the stock chart did. Because the real story isn’t about IBM, it’s about every bank, insurer, utility and government agency still running core operations on code written before most of their current staff were born, and about how fast the old excuse, “modernizing is too risky,” is running out of road.
This is the story of why 2026 is the year legacy modernization stopped being a five-year roadmap line item in Australia and became a board-level risk conversation – and what an AI-native approach to fixing it actually looks like.

1. The Trillion-Dollar Case for Legacy Modernization in Australia
COBOL turns 67 this year. It was built for punch cards, in a world without cloud, APIs or real-time payments – and it is still, by widely cited industry estimates, processing something in the order of USD 3 trillion in financial transactions every day worldwide, with close to 95% of ATM transactions touching a COBOL program somewhere in the chain.
Australia is not an exception to that pattern. Insoftek puts the share of financial institutions globally still running core systems built more than 20 years ago at around 43%, and current Sydney and Melbourne job boards tell the same story at ground level: banks, insurers and government contractors are still actively recruiting COBOL, CICS and JCL specialists in 2026 just to keep three, four and five-decade-old systems alive.
That dependency carries a cost most balance sheets don’t show explicitly. Technical debt now accounts for close to 40% of the average enterprise IT budget – money spent keeping old systems breathing rather than building anything new. Meanwhile the supply of people who can do that work is shrinking fast: more than 85% of universities dropped COBOL from their curriculum after the 1990s, the average mainframe developer is now in their mid-50s, and recruiters report COBOL roles routinely take two to three times longer to fill than equivalent modern-stack positions.
That gap between shrinking talent and growing risk is exactly why legacy modernization has stopped being a purely technical debate and become a workforce-risk one as well.
Discover our data migration roadmap for legacy core systems: Data Migration Risks and Mitigation: What Enterprises Need to Know
2. Why APRA Just Turned “Later” into “Now”
For regulated Australian enterprises, this stopped being a purely technical decision on 1 July 2026, when APRA’s Prudential Standard CPS 230 came into full effect for banks, insurers and superannuation funds. CPS 230 requires every regulated entity to map its critical operations end to end – every system, process and third party a service depends on – and prove it can keep operating through a disruption, not just describe how it would in theory.
A core banking or claims platform running on unsupported, undocumented COBOL is exactly the kind of dependency CPS 230 was written to expose. It’s hard to evidence operational resilience for a system where the people who fully understand its failure modes have already left the building. Legacy modernization isn’t only an efficiency play in Australia in 2026 – it is quietly becoming a compliance one too, and that’s precisely the gap a well-planned legacy modernization program is designed to close before an auditor finds it first.
3. The Rip-and-replace Trap Australian Enterprises Already Learned The Hard Way
Given that pressure, the temptation is to greenlight a full replacement and be done with it. Australia has already run that experiment at scale: CBA’s original core banking transformation took about five years and cost more than AUD 1 billion. Contemporary reporting from iTnews explicitly described it as a “billion dollar, five-year” project, while another case study records the final expenditure at around AUD 1.1 billion.
The lesson from a decade of these projects isn’t “don’t modernize.” It’s “don’t rebuild everything from zero.” The organizations getting this right in 2026 aren’t necessarily replacing everything at once. They’re taking a sidecar or “hollow-the-core” approach: building new capabilities around the legacy core, keeping critical systems running while business logic is progressively modernized, and reducing the risk of a single big-bang cutover. This is also why COBOL modernization and legacy modernization are increasingly treated as separate workstreams – you can retire COBOL’s business logic gradually without ever attempting a single-cutover replacement of the whole core.
The AI-Native Path to Legacy Modernization in 2026

What makes this approach viable now, rather than five years ago, is AI’s new ability to do the part of legacy modernization that used to eat the most time and budget: understanding what the old code actually does. Historically, the majority of a modernization budget went into reverse-engineering decades of undocumented business logic – tax rules, compliance edge cases, exception handling nobody wrote down – before a single line of the new system could be trusted.
That’s the analysis layer AI coding tools proved out in early 2026 – and it’s why GEM approaches modernization as an AI-native technology transformation partner, not a traditional systems integrator running a rip-and-replace program. In practice, that means:
- AI-assisted code comprehension that maps legacy logic, dependencies and business rules before any migration decision is made – compressing a discovery phase that has historically eaten a third or more of project timelines
- Wrapping and exposing legacy systems through modern APIs, so new digital products, real-time payments and AI agents can be built on top without touching the legacy core on day one
- A phased, sidecar-style delivery model – pilot on a defined product or workflow, prove it, then scale – instead of a single high-risk cutover
- Hybrid-cloud architecture that meets APRA’s data sovereignty and resilience expectations while giving enterprises the elasticity of AWS-, Azure- or Databricks-based platforms
- Governance, monitoring and audit trails built in from day one, so the modernized estate is CPS 230-ready by design instead of retrofitted after a finding
See how GEM’s AI accelerators speed up your first modernization pilot: Top 24 AI Accelerators 2026 Powering Enterprise AI from Pilot to Production
GEM Corporation – Your AI-Native Legacy Modernization Partner

Across GEM Corporation’s enterprise modernization and AI transformation engagements, clients typically see cost reductions in the 20-45% range on the systems modernized, implementation timelines 40-70% faster than a traditional waterfall rebuild, and productivity gains of two to five times in the workflows the new AI-native layer touches – without the multi-year, nine-figure risk profile of a full core replacement.
In practice, that plays out in three phases rather than one leap. A 6-8 week AI-assisted discovery phase maps the legacy logic, dependencies and compliance edge cases, and quantifies the real risk before anything is committed to. A pilot – typically one product line, one workflow, or one customer-facing capability – is then built and proven on the new AI-native layer within a single quarter. Only once that pattern is validated does it extend workload by workload into a scale phase, with the legacy core decommissioned progressively as its business logic genuinely migrates across, not on a fixed calendar date. Each stage is a funded, reversible decision a board can sign off on independently, rather than one irreversible bet made upfront.
GEM works as an extension of the internal team throughout, not a black-box vendor: ISO 9001 and ISO 27001-certified delivery, CMMI Level 3 process maturity, and partnership-level experience with ServiceNow and Databricks give Melbourne and Sydney enterprises the audit trail regulators and boards now expect, alongside the delivery speed an AI-native approach to legacy modernization makes possible.
Conclusion
Every quarter an enterprise delays is another quarter of COBOL specialists retiring, another CPS 230 reporting cycle to explain away, and another cohort of AI-native competitors – fintechs and neobanks with no legacy core to protect – pulling further ahead on real-time payments and personalized digital experiences. The IBM story from February wasn’t really about IBM. It was a signal that the single biggest blocker to modernizing legacy code – understanding it, just got dramatically cheaper. The enterprises that move first will set the pace for everyone still deciding.
The maths only gets less forgiving from here. Every additional year of deferral compounds against three trends moving in the same direction at once: the talent pool keeps shrinking as a decade’s worth of mainframe specialists head toward retirement, APRA’s post-CPS 230 scrutiny of technology and third-party dependencies is unlikely to loosen, and the AI tooling that just made legacy code review dramatically cheaper is improving every quarter, not standing still. None of that is an argument for a rushed, high-risk rebuild. It’s an argument for starting the assessment now, on the enterprise’s own terms, rather than being forced into one later – under audit pressure, after an incident, or in the middle of a deal that a legacy core just complicated.
GEM’s legacy modernization assessment maps current-state dependencies, quantifies CPS 230 exposure, and scopes a phased, AI-native pathway tailored to the systems that actually carry the risk, with no obligation to commit to a full rebuild, and no rip-and-replace mandate baked in.
Talk to GEM about a legacy modernization assessment for your organization.
Why are Australian banks and insurers still running COBOL if it's this risky?
Mostly because the alternative has historically looked riskier. Commonwealth Bank's five-year, AUD 1 billion-plus core migration is the cautionary case study every Australian CIO knows, and industry data suggests roughly three-quarters of large-scale modernization projects globally run into serious cost or timeline trouble. Add a shrinking pool of COBOL specialists able to safely maintain the current systems, and many enterprises have simply kept deferring the decision.
How does APRA's CPS 230 standard change the calculus on legacy technology?
CPS 230 came into full effect on 1 July 2026 for banks, insurers and superannuation funds, requiring regulated entities to map every critical operation — including the systems and third parties behind it — and demonstrate they can maintain that operation through a disruption. A legacy core that only a handful of retiring specialists fully understand is difficult to evidence as resilient, which pushes legacy modernization from a discretionary IT project toward a prudential compliance priority for APRA-regulated organizations.
Is a full "rip and replace" ever the right approach?
Rarely, and almost never as a first move. The pattern proving out across global banking in 2026 - a "sidecar" or "hollow-the-core" model, used by an estimated 40% of banks per IDC projections - builds new capability on a modern engine alongside the legacy system, migrating workload by workload rather than betting the business on one cutover weekend. Full replacement can still make sense for a specific, well-bounded system, but it's a decision to make deliberately, not a default.
How does GEM's AI-native approach differ from a traditional systems integrator, and what results can we expect?
Traditional modernization programs spend most of their budget and timeline on manually reverse-engineering what the old code does before anything new can be built. GEM uses AI-assisted code comprehension to compress that discovery phase, then delivers through a phased, API-led, sidecar model with governance built in from day one. Across GEM's enterprise engagements, that typically translates to 20-45% cost reduction, 40-70% faster implementation, and 2–5x productivity gains in the modernized workflows - delivered under ISO 9001, ISO 27001 and CMMI Level 3-certified process discipline.

