That's a very small part of a lot of what we have to say, most of which is:
* we can't be compelled (under current laws) to install blanket monitoring on our users
* we can't be compelled to keep quiet about penetration that we notice
* there are always risks, including the risk that any random group knows unpublished security flaws in the systems that we use
We have written some things about techniques we use to reduce those risks (physically separate internal network rather than VLANS on a single router for example) - these help protect against both government AND non-government threats. But we can't make those risks go away entirely.
What we're saying is - the physical presence in the USA only changes one low-probability/high-visibility threat, which is direct tampering with our servers.
Regardless of the physical location of servers, we would still comply with legally valid requests made through the Australian Government.
It is our belief and hope that this process is difficult enough to mean that US agencies only ask for data when they have good cause rather than "fishing" - but still easier than taking our servers and shutting us down, with all the fallout that would cause.