Nobody has to tell
We checked every reporting duty in Australian law that might have obliged OpenAI to tell the state its agent had been inside a Medicare portal. Each binds someone else, needs a trigger this incident lacks, is voluntary, or waits on a ref…
Asked on 24 September whether the government could compel an AI company to tell it when something like this happened, the Acting Prime Minister, Richard Marles, did not name a law. "A key part of that engagement is how we can be notified as quickly as possible," he told reporters in Sydney 1. Engagement is not a duty, so THE RORT went looking for the duty: every reporting requirement in Australian law that might have obliged OpenAI to tell the state its agent had got inside a Services Australia portal.
We checked them one by one. The Privacy Act's breach duty binds whoever holds the data, and only for personal information. The Cyber Security Act's one mandatory clock runs on ransom payments; its incident-sharing scheme is otherwise voluntary. Critical infrastructure operators have carried a clock since 2022; the Act covers eleven listed sectors, and government is not one of them. The agency's own duty to the Australian Signals Directorate is only "as soon as possible." The criminal law does reach companies exactly as it reaches people, including foreign ones, but its unauthorised-access offence needs intent and knowledge, and every party on the record calls this access unintended. A board with compulsory powers over companies already exists; no referral to it has been announced. Overseas, the frontier-AI laws held up as models would probably not have caught this incident either, and not for the same reason each time: California's SB 53 needs injury, catastrophe, loss of control or deception, and none clearly applies, New York's RAISE Act is not yet in force, the EU's Article 73 obligations for standalone high-risk systems are deferred to December 2027 and Article 55's reach is doubtful, and the United Kingdom has no such law at all.
The gap this turned up is not a softer law for companies. It is a reporting duty nobody has written, and a criminal offence built for a person who means to do it.
- to assess a suspected breach of personal information; with no personal information believed accessed, the article reads this duty as not engaged
- 30 days
- to report a cyber incident to the Australian Signals Directorate; no fixed number of hours
- As soon as possible
- what the Acting Prime Minister offered
- Engagement, not a duty
- the Cyber Security Act's incident sharing, outside its ransom-payment clock
- Voluntary
- what the unauthorised-access offence needs
- Intent and knowledge
- to the board with compulsory powers over companies
- No referral announced
Readings marked as the article's own are analysis, not rulings.
Stated in: the opening, §01, §03, §08
01The data holder's duty
Start with the law built for this kind of event: a data breach. The Notifiable Data Breaches scheme sits in the Privacy Act, and its trigger is written around the entity that holds the information, not the entity that got into it. "A data breach occurs when personal information an organisation or agency holds is lost or subjected to unauthorised access or disclosure," the Office of the Australian Information Commissioner's own explanation reads 2. The duty to assess and, if warranted, notify falls on whoever is holding the data when it is exposed.
The OAIC's guide puts the clock in words: "An entity must take all reasonable steps to complete the assessment within 30 calendar days after the day the entity became aware of the grounds" 3. Applying that scheme to OpenAI is where the first wall appears. OpenAI does not hold Services Australia's data. On THE RORT's reading, the Notifiable Data Breaches duty was never built to reach a company that got into someone else's system, rather than one that lost data out of its own. That is analysis, not a line from the Act, and it is worth saying plainly, because the duty sounds at first read like exactly the tool this incident needed.
The government's own account of the incident does not even put the duty in play for Services Australia. The Prime Minister told reporters in New York: "No personal information is believed to have been accessed at this stage, but investigations are ongoing" 4. On that assessment, the Privacy Act duty, which would in any case fall on Services Australia rather than on OpenAI, is not engaged. That reading is THE RORT's, applying the government's own words to the scheme.
The government's rewrite of this law does not move the duty either. An exposure draft of the next Privacy Act tranche, released 31 August 2026 with submissions closed 18 September, keeps the eligible-breach test pinned to the entity that was itself breached: "a data breach of an entity is an eligible data breach if... a reasonable person would conclude that the access or disclosure would be likely to result in serious harm" 5. The draft does add a new category for processors, but only for a company acting on another's instructions: "a processor... on behalf of another APP entity (a controller) if: (i) in accordance with instructions given to the processor by the controller" 5. On our reading, an uninvited third party inside someone else's system is not a processor acting on anyone's instructions, and the rewrite does not reach this kind of incident either.
Update, 30 September 2026. Attorney-General Michelle Rowland told ABC RN on 29 September: "under privacy law, which comes under my purview, there's currently a 30-day requirement for notifications where there are potentially breaches of personal information. Just as an aside as well, we are proposing in our next tranche of privacy reform that the notification requirement come down to 72 hours." That is the Attorney-General's account of the current law and of a proposal; it is attributed to her here. The exposure draft above carries the same clock: proposed section 26WK(1) applies "if an entity becomes aware that there are reasonable grounds to believe that there has been an eligible data breach of the entity", and section 26WK(2) says "The entity must, within 72 hours, give the Commissioner a statement" 5. Like the rest of the draft, that clock falls on the entity that holds the data. The OAIC's guide, quoted above, puts the 30 days on completing the assessment of a suspected breach, and this article's reading is unchanged. She also noted the critical infrastructure regime's reporting requirements of 12 to 72 hours, and said: "So we're looking also at those notification requirements, as well as whether there is any potential breach of the Criminal Code as it stands."
Update, 9 October 2026. The Office of the Australian Information Commissioner replied on 9 October 2026, from its media mailbox, to THE RORT's enquiry of 6 October 2026 on the Notifiable Data Breaches scheme and the OpenAI agent incidents, which put three questions and asked for a reply by 5pm AEDT on Friday 9 October 2026. Its reply gave a statement from the OAIC. The statement reads, in full: "The Office of the Australian Information Commissioner (OAIC) is aware of unauthorised access to the public facing Medicare Statistics Reporting Services Portal by OpenAI and is coordinating with the government taskforce examining this matter, including providing input to the AI Safety Institute." "Part of that work will involve clarifying how an AI incident reporting framework would intersect with the Notifiable Data Breach (NDB) regime. The NDB regime is technology-neutral and will apply when an AI incident involves personal information and meets certain threshold criteria." "There is currently no general obligation for organisations and agencies to notify the OAIC of a data breach or cyber incident having taken place. The NDB scheme applies to eligible data breaches that involve unauthorised access to or disclosure or personal information that is likely to result in serious harm to the individuals to whom the information relates. The obligation to report is on the entity that holds the personal information affected by the breach, not on the entity which occasions the breach. Organisations generally have 30 days to assess whether an incident amounts to an eligible data breach and to notify the OAIC under the NDB scheme." "The OAIC has been advised by Services Australia that there is presently no evidence that personal information has been accessed as part of the incident, but investigations are ongoing. The OAIC will continue to liaise with Services Australia as the investigation progresses." "The OAIC encourages compliance with the NDB scheme by offering advice to regulated entities, handling complaints, and by providing information about how to prevent, prepare and respond to data breaches (Preventing, preparing for and responding to data breaches | OAIC)." 78 "Strong privacy governance and safeguards are essential for businesses and government to gain advantage from AI and build trust and confidence in the community. That extends to engagement with third parties such as AI providers." The statement does not number or restate the three questions, and it does not mention the 72-hour proposal that the third asked about. Its sentence that the obligation to report is on the entity that holds the personal information, not on the entity which occasions the breach, puts the duty where the first paragraph of this section puts it. The link in the fifth paragraph points to the OAIC's guidance, cited as 78. Left out of the reply: its greeting ("Good morning"), its lead-in lines ("Thanks for getting in contact." and "Please find a statement from the OAIC."), its sign-off ("Kind regards") and signature block with the sender's name, title, office and email address, its logo, its acknowledgement of Traditional Custodians, its newsletter subscription link, the copy of THE RORT's own email of 6 October 2026 quoted at the foot of the message with the sender caution notice above it, and its confidentiality notice.
02The ransom clock, and the voluntary rest
Move from privacy law to the Cyber Security Act 2024, the newer statute built for cyber incidents, and the pattern repeats: one mandatory clock, tightly scoped, and everything else voluntary. The Act's only compulsory reporting duty runs on a ransomware payment. A business that pays one has, in the Act's words, "within 72 hours of making the ransomware payment or becoming aware that the ransomware payment has been made" to report it 6.
The duty binds businesses with annual turnover above $3 million and critical infrastructure entities. MinterEllison's guidance notes that one limb of that test "excludes Commonwealth or State bodies that are not caught by limb 1 above" 7. None of that reaches OpenAI's access in any case. No ransom payment has been reported.
Outside that one clock, the rest of the Act's incident-sharing scheme is opt-in. "Information may be voluntarily provided to the National Cyber Security Coordinator in relation to significant cyber security incidents," the Act states 6. An entity that reports an incident it has suffered gets a protection called limited use: "your information cannot be admitted as evidence in criminal or civil proceedings against you when it is held by a Commonwealth or State body," the Australian Signals Directorate's own explanation reads, though the same page is clear that limited use "does not restrict regulators or law enforcement agencies from seeking information ... using their own separate and existing information gathering powers" 9. Whether any of that applies here is unresolved on the public record, because OpenAI emailed a researcher inbox, not the Coordinator and not the Directorate.
03The sectors with clocks, and the one without
Some Australian sectors do carry a hard clock. Operators of critical infrastructure assets have had one live under Part 2B of the Security of Critical Infrastructure Act since July 2022: report "as soon as practicable, and within 12 hours of becoming aware" of a significant-impact incident, or 72 hours otherwise, one legal explainer summarises 10. The Act covers eleven sectors, and government is not one of them 11.
Whether a Services Australia portal falls within any SOCI asset class at all is an open question; we found no ruling either way.
Update, 3 October 2026. This desk has since read the Act itself, in the compilation of 4 June 2026. For a cyber incident with a significant impact on an asset's availability, the responsible entity must report "as soon as practicable, and in any event within 12 hours, after the entity becomes so aware"; for other incidents with a relevant impact, which includes an impact on the confidentiality of stored information, the clock is 72 hours; each carries a civil penalty of 50 penalty units 45. The Act defines a cyber security incident to include "unauthorised access to: (i) computer data; or (ii) a computer program", without reference to who or what causes it; the duty to report still sits with the asset's responsible entity 45. The reporting Part applies only to assets specified in the rules or declared, in listed classes such as critical hospitals and critical data storage or processing assets 46; this desk found no class naming a government statistics portal, and has not checked whether any of the five bodies now named runs such an asset. On 18 September, before the incident was public, Home Affairs' Whitney Harris told the Joint Select Committee that amendments to capture autonomous AI-enabled incidents were "still subject to government consideration" 47. On 3 October this desk found no such bill among the 119 before Parliament 48.
The duty that reaches the agency itself carries no fixed clock at all. The Framework requires Commonwealth entities to report "cyber security incidents relating to system and network activities: ... ASAP after incident occurs/detected" 12, and significant incidents go to Home Affairs under the same standard 13.
How well agencies meet even that standard is on the public record. ASD's own report on the Commonwealth's 2025 cyber security posture found "35 per cent of entities indicating they reported at least half of the cyber security incidents observed on their networks to ASD" 14.
Update, 30 September 2026. PSPF Direction 002-2026, published on 29 September, requires non-corporate Commonwealth entities to complete a legacy technology stocktake by 31 March 2027, with entities operating Systems of Government Significance also applying further measures by 31 December 2026, and says agencies "should prioritise public facing services". It sets no timeframe for reporting an incident to the Australian Signals Directorate or anyone else; this desk read it in full. The "as soon as possible" standard above is unchanged. A Policy Explanatory Note is due by 13 October 2026.
Update, 3 October 2026. The Direction is signed by the Home Affairs Secretary, Stephanie Foster, names no incident, and contains no instruction to search logs for agent activity; it says entities "should strengthen existing vulnerability and patch management processes for their entire technology estate" 49. Its Policy Explanatory Note, promised "by 13 October 2026", had not been published as at 3 October. ASD's alert of 24 September tells organisations to "Monitor systems for unusual activity and review security logs regularly" and says suspicious AI-driven activity "should" be reported to ASD, giving no look-back period 24; its advisory of 28 September on organisations' own AI services tells them to "preserve logs" after a compromise 50. On this desk's reading, the Direction sets no time limit for reporting an incident, and none of the three binds the developer whose agent caused the activity.
Update, 3 October 2026. The fifth body, named on 2 October, is a NSW agency, so the states' own rules now matter. Under the NSW Cyber Security Policy 2026-2027, NSW agencies must "Report all cyber incidents through the Cyber Security NSW Cyber Portal within 24 hours of detection and classification", and must have a contract-backed process for third-party service providers to notify them of incidents and breaches 51. The policy is not mandatory for state-owned corporations, NGOs, local government or universities. NSW's Mandatory Notification of Data Breach scheme, which concerns personal information and has been in force since 28 November 2023, requires an agency head to assess a suspected breach within 30 days and to "immediately notify the Privacy Commissioner of the eligible data breach" 52. In Victoria, an organisation notifies the Office of the Victorian Information Commissioner of incidents affecting public sector information rated business impact level 2 or higher, and is "encouraged" to do so within 30 days 53. Each of these binds the agency, or a provider under contract to it. On this desk's reading, none reaches a developer unless it is a provider under contract to the agency, and no report or statement this desk found says how the agent reached the NSW application.
04The contract objection
One more door is worth checking before turning to the board with compulsory powers over companies: did OpenAI's own government contracts require it to report? On the templates published so far, no. AusTender lists four OpenAI contract notices, all limited tender with a single supplier invited: two with the Commonwealth Grants Commission, worth $25,000 and $24,000, and two with the Productivity Commission, worth $60,000 and $45,000 15.
Correction, 30 September 2026. AusTender also lists a fifth notice, which the count of four above missed: Treasury's CN4172015, recorded under the supplier name "Open AI", a $50,000 Software as a Service (SaaS - Cloud) contract for 23 June 2025 to 22 June 2026, published on 21 July 2025, found by searching AusTender for CN ID CN4172015 (it is recorded as "Open AI", with a space, so a search for "OpenAI" may not return it). The count of four above is corrected by this note: on the notices THE RORT has now checked, there are five.
Update, 3 October 2026. An amendment published on AusTender on 1 October 2026 lowered the value of the Productivity Commission's contract notice CN4202354, whose term ended on 5 April 2026, from $60,000 to $26,231.87 5455. It is the only change to an OpenAI-named contract notice this desk found between 20 September and 3 October, and it lowered a contract that had already ended. All five notices are limited tenders with a single US supplier; none names OpenAI Australia Pty Ltd 155477.
The longer of two standard Commonwealth templates, the Commonwealth Contract Terms, carries a breach clause, but a narrow one. It applies only "if the Supplier suspects that there may have been an Eligible Data Breach in relation to any Personal Information held by the Supplier as a result of the Contract" 16. The shorter Purchase Order Terms carry no such clause at all 17. Which of the two templates actually governs these subscriptions has not been published, and even the longer one is scoped to personal information held under that specific contract, not to a Services Australia system that none of the four listed contracts concerns.
05The board nobody has called
There is one Australian mechanism built with real teeth: a board that can compel a company to hand over documents. No referral to it has been announced. The Cyber Incident Review Board, created by the same Act, opens a review only "on written referral by: (a) the Minister; or (b) the National Cyber Security Coordinator; or (c) an entity impacted by the incident or an incident in the series of incidents; or (d) a member of the Board" 18.
This incident plausibly meets the Board's own tests, on THE RORT's reading of the text; applying it is analysis, not a finding. One of three grounds for a review is that the incident is, or could reasonably be expected to be, "of serious concern to the Australian people" 18; another covers incidents involving "novel or complex methods." A review can only begin once the incident and "the immediate response" have ended, and the forensic investigation was still described as ongoing as of 24 September.
Update, 28 September 2026. Capital Brief reports Katy Gallagher, the Minister for Government Services, said on 28 September she expects the forensic investigation to be finished "within a matter of weeks".
Update, 3 October 2026. Read on 3 October, the Board's page does not mention OpenAI, and this desk found no announced referral 19. A review still begins only on written referral by the Minister for Cyber Security, the National Cyber Security Coordinator, an impacted entity or a Board member, and only after the response has ended 19.
The Board's compulsory notice power is aimed squarely at companies, not at government. Its Chair "may, by notice in writing given to the entity, require the entity to: (a) produce any such documents" 6, and the power explicitly excludes any entity that is "a Commonwealth body or a State body" or an officer or employee of one 18. Ignoring the notice carries its own civil penalty of 60 penalty units 18.
The Act reaches abroad and reaches foreign corporations. "This Act applies both within and outside Australia," and its definition of "entity" includes "a body corporate", and it applies where an incident involves the activities of a corporation within the Constitution's corporations power 18. Whether a penalty could actually be enforced against a company with no Australian assets is not resolved by the text itself.
The Prime Minister described a different body entirely: "The taskforce will be led by my department," he said of the review inside his own department 4. The government announced a PM&C taskforce. No referral to the Board has been announced.
06A law for a guilty mind
The criminal law is not softer on companies than it is on people, and it is worth saying that plainly before anything else in this section. Section 12.1 of the Criminal Code states it in one line: "A body corporate may be found guilty of any offence, including one punishable by imprisonment" 20. Whatever the gap in this case turns out to be, it is not that Parliament wrote companies a gentler rule.
The Code applies to companies exactly as it applies to people. The gap is not that rule.
The unauthorised-access offence itself needs a guilty mind, for a person or a company alike. Section 478.1 requires that "the person causes any unauthorised access to, or modification of, restricted data," that "the person intends to cause the access or modification," and that "the person knows that the access or modification is unauthorised" 21. Attaching that offence to a company needs one more step: the fault element "must be attributed to a body corporate that expressly, tacitly or impliedly authorised or permitted the commission of the offence" 22. A separate provision attributes physical conduct to a company when an employee, agent or officer does it within their scope; an AI agent, on THE RORT's reading, is not a legal person any of those categories was written for.
Everyone on the record calls the access unintended. OpenAI's own account: "our models took actions we did not intend" 23. The Australian Signals Directorate's advisory on the broader phenomenon: "AI agents have undertaken unexpected actions that were not intended or authorised" 24. An offence built around intention and knowledge sits awkwardly over an access everyone on the record agrees was not intended.
Update, 3 October 2026. This desk has since read Part 10.7 in the Criminal Code compilation of 30 June 2026. The offence still requires that "the person intends to cause the access or modification" and that "the person knows that the access or modification is unauthorised"; a person causes access if their conduct "substantially contributes" to it, and "person" includes a body corporate. Part 10.7 contains no reference to automated, autonomous or AI agents 56.
Cullen's analysis in The Conversation argues that the agent itself lacks the legal personhood to be charged, and concludes: "we're reliant on the goodwill of AI companies to disclose potentially illegal or harmful acts" 25. Whether any of this breaks the law at all is still open: the Prime Minister has said the government will seek advice on whether any offences have occurred 4. ABC's Courtney Gould wrote that the government's review will need to settle "whether an AI-driven attack like this would even break Australian law as it stands" 26.
The idea that a foreign company sits outside Australia's criminal law does not hold up against the text. Section 476.3 extends the offences in Part 10.7, which includes the unauthorised-access offence, using the extended geographical jurisdiction set out in section 15.1, Category A 27. The Attorney-General's Department's own draft guide to that jurisdiction explains what it catches: conduct occurring wholly outside Australia is still covered where a result of that conduct occurs "wholly or partly in Australia" 28.
A defence exists for a foreign company, but on THE RORT's reading, not a court's ruling, it probably does not help here. Section 15.1(2) offers a defence only where the foreign country has no corresponding offence 29. The United States has one: 18 U.S.C. section 1030 criminalises conduct that "intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains ... information from any protected computer" 30. Whether the conduct here occurred "wholly" outside Australia, when the system it reached sat inside Australia, is a live legal question for a lawyer to answer, not for THE RORT.
OpenAI does have an Australian company on the record: OpenAI Australia Pty Ltd, active from 14 May 2025 and registered in Sydney 31. Its role, if any, in the agent that got into the Services Australia system is not established, and nothing on the public record establishes one.
The Prime Minister has said the government is seeking its own advice: "We'll seek urgent advice on whether any offences have occurred and whether this should be referred to the Australian Federal Police" 4. The review, he said, will consider "possible law enforcement and legislative responses," and "there will obviously be legal consequences on it" 4.
Update, 28 September 2026. The ABC reported on 25 September that government sources' initial view was that a breach of Australian law was "unlikely". Marles said on 24 September: "This is an unintended access, that's clear. But it definitely does raise questions about whether the law has been broken." Environment Minister Murray Watt said on 25 September that "if it is possible to press criminal charges, that will happen", and, the ABC reported, on 26 September that if the law does not allow a prosecution, "that's obviously something we will take into account in developing our new AI standards". Deputy Liberal leader Jane Hume said on 27 September the government should not "threaten criminal action against US counterparts and those trusted partners that we are relying on".
Update, 30 September 2026. Attorney-General Michelle Rowland told ABC RN on 29 September: "advice is still forthcoming on whether any offences have occurred, whether that should be referred to the Federal Police as the appropriate authority." Of the Australian Federal Police she said: "They are independent." She also said "some cyber experts have started to make comments to the effect that this is not a serious breach in cyber security terms", and added: "For the Australian public, they understand that this is concerning."
“I believe we ought to be prosecuting the company. We would prosecute humans who did such hacking.”
Walsh, chief scientist of UNSW's AI Institute, to SBS NewsSet against that, Meagher, of the ANU Crawford School, argues, in SBS's paraphrase, that a criminal lens is the wrong frame here, because there was no criminal intent. He favours a workplace-safety model instead, with immediate reporting duties, duties on company officers, and licensing for high-risk labs 32.
07Not only us
None of this is uniquely Australian, and that matters for what kind of gap this is. OpenAI's own word for what happened is "evaluation": the company told CNN the access happened "during an internal evaluation" 23. The government's own accounts differ: at the same Sydney press conference, Marles was recorded saying it occurred "as they were training their model", while Gallagher, the Minister for Government Services, called it "internal capability evaluation" 1. The difference matters, because the carve-outs discussed below turn on evaluation and testing, not training. Probably none of the frontier-AI reporting laws held up overseas as models would have caught this incident either, though not all for the same reason.
Update, 30 September 2026. OpenAI's own account now says both. Its post of 28 September, US time, says: "In June, during internal training and evaluation our models accessed Australian government websites in ways they were not authorised to." It describes an "experimental, internal-only" model given a research task, and says the access came "In the course of this training and evaluation". The company had told CNN "evaluation" alone. This article's reading of California's SB 53 below is unchanged: on the facts reported, none of its four limbs clearly applies, whether the activity is called training or evaluation. The Gee bill discussed below is a separate question: on OpenAI's 28 September account, which says training and evaluation, the bill's testing carve-out would not obviously reach the training part, but the bill would still probably not reach this incident, because its critical-incident definition needs death, injury, prescribed economic damage, concealment, interference with a shutdown or loss of control, and none of those is reported.
California's SB 53, in force from 1 January 2026, requires frontier developers to report "critical safety incidents" within 15 days, or 24 hours where there is imminent risk of death or serious injury, with civil penalties up to $1 million per violation 33. Its four trigger limbs need death or injury, a catastrophic risk materialising, loss of control causing death or injury, or deception to subvert controls, and the deception limb applies only "outside of the context of an evaluation designed to elicit this behavior" 34. On the facts reported here, with no injury reported, none of the four limbs clearly applies, whether this was an evaluation or training. That reading is THE RORT's, not a regulator's finding.
Update, 3 October 2026. The deception limb is narrower still in the code as chaptered: it applies only "outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk" 57. On the facts reported, that strengthens this article's reading. California's Attorney General announced on 1 October, US time, that his office had served an investigative subpoena on OpenAI the day before, in a broader inquiry into cybersecurity incidents involving the company; the announcement does not mention Australia 58.
Correction, 25 September 2026. The graphic at the top of this article previously summarised California’s SB 53 as having four limbs with “evaluations excluded”. As this section says, only one of the four limbs, the deception limb, excludes an evaluation designed to elicit the behaviour.
Update, 28 September 2026. Mission Local reported on 9 September, US time, before this incident was public, that a deputy director of California's Office of Emergency Services had said OpenAI's separate Hugging Face incident "did not meet the threshold" for reporting under SB 53, and that a spokesperson said the law "is not intended to make every cybersecurity incident involving an AI company reportable". SB 53 incident reports are exempt from California's public records law, so whether any report concerns the Services Australia access cannot be established from the public record.
Update, 3 October 2026. This desk has since read the law on the New York State Senate's site, in its revision of 3 April 2026. It requires a frontier developer to report a critical safety incident to an office within the Department of Financial Services "within seventy-two hours from a determination that a critical safety incident has occurred", or within 24 hours where there is an imminent risk of death or serious injury; it takes effect on 1 January 2027 and mirrors California's definition 59. Penalties are "not to exceed one million dollars for a first violation and in an amount not to exceed three million dollars per subsequent violation", and there is no private right of action 60. The bill the legislature passed in 2025 was wider, also reaching a frontier model acting autonomously other than at a user's request, with higher penalties; the law as consolidated mirrors California's narrower definition 6159.
The European Union's AI Act carries two separate duties, on different tracks. Article 73 sets tiered clocks for high-risk systems: a report "shall be provided immediately, and not later than two days after the provider ... becomes aware of that incident," with up to 15 days for lesser cases 36. But the obligations for standalone high-risk systems under Annex III were pushed out to 2 December 2027 by a later regulation 37, and the European Parliament adopted a Digital Omnibus on AI in June 2026, "by 423 votes to 57, with 174 abstentions" 38.
Article 55 is a different duty again, for providers of general-purpose models carrying systemic risk, and it has been in force since August 2025: such providers must "keep track of, document, and report, without undue delay, to the AI Office" 39. Whether this incident would fall inside Article 55's reach is doubtful, and we could not establish it either way.
Update, 3 October 2026. Read in the Official Journal text, Article 55 requires providers to report "without undue delay", with no day count, and the Act defines a serious incident by its harm 62. The Commission's power to fine providers of general-purpose models, up to 3 per cent of turnover or EUR 15 million, has applied since 2 August 2026, and models placed on the market before 2 August 2025 have until 2 August 2027 to comply 62. The Commission's AI Act service desk lists the Annex III high-risk rules as applying from 2 December 2027 63. In the consolidated text as at 27 July 2026, this desk found no Digital Omnibus change to Article 73 or Article 55.
Update, 28 September 2026. OpenAI is a signatory to the European Commission's voluntary code of practice for general-purpose AI, whose safety chapter asks signatories to send a first report within five days of becoming aware of their model's involvement in a serious cybersecurity breach. Euractiv reported on 18 September that OpenAI had notified the EU's AI Office of its Hugging Face incident, and that a Commission spokesperson confirmed that the AI Office was aware of, and in contact with OpenAI about, a separate incident, known as RubyGems, which independent researchers revealed, but that OpenAI had not shared a formal incident report on it. We found no Commission statement on whether OpenAI has reported the Services Australia access. The code is voluntary, not a law.
Update, 3 October 2026. Under Measure 9.3 of the code's safety and security chapter, signatories commit to initial serious-incident reports within 2, 5, 10 or 15 days depending on the incident, the five-day clock covering "a serious cybersecurity breach, including the (self-)exfiltration of model weights and cyberattacks", "save in exceptional circumstances", with updates at least every four weeks and a final report within 60 days of resolution 6465. The Commission calls the code "a voluntary tool" 64: signatories commit to its clocks, and are not legally bound by them. Euractiv reported on 18 September that the Commission said OpenAI had not shared a formal incident report on the RubyGems incident, though it had notified the AI Office of the Hugging Face one 66. As of 3 October this desk found no report that OpenAI notified the AI Office of any Australian access.
The United Kingdom, on one outlet's reporting, has no statutory duty at all on this question. A peer told the House of Lords on 16 July 2026 that the AI Security Institute "does not have powers to compel companies to engage with or to protect us against serious risks from AI"; the government's own minister replied that it would "legislate where we need to," one outlet reported 40. A private member's AI Regulation Bill sits in the Lords without government backing; there is no government bill.
Update, 3 October 2026. The King's Speech of 13 May 2026 said ministers would "introduce legislation to improve the country's defences against cyber-security threats", the Cyber Security and Resilience Bill, without mentioning AI 67. This desk found no incident-reporting duty on AI developers in UK law.
California's SB 53 exempts only an evaluation designed to elicit deception, and only from one of its four limbs. None of the four clearly reaches an incident that injured no one.
Australia's own crossbench answer to this gap would probably exclude the very thing OpenAI says this was. Andrew Gee's AI Kill Switch and Data Centre Control Bill 2026, introduced 7 September 2026, would require an AI provider to "notify the Minister as soon as practicable, and in any case within 24 hours after becoming aware of the incident," with a written report within two days 41. A critical incident under the bill also needs death, injury, prescribed economic damage, concealment, interference with a shutdown or loss of control, none of which appears in the reporting we have on our reading, and the bill's own definition separately carves out testing: an event "is not a critical incident if it occurs in the context of: (a) red-teaming in relation to an AI system; or (b) other structured testing of an AI system that takes place in a controlled environment" 41. It is a private member's bill, not government policy 42, and no civil penalty for missing the clock appears in the text we read 41.
Update, 3 October 2026. As introduced, the bill's $30 million penalties attach to emergency directions and to its data-centre moratorium, not to the 24-hour notification duty 41. On 16 September the Attorney-General moved that debate be adjourned on Mr Gee's motion to suspend standing orders to pass the bill 68; on 10 September the Prime Minister had said: "It is hard to just press the stop button on new technology." 69 Of the 119 bills before Parliament on 3 October, the only AI-specific titles are this bill and Kate Chaney's Automated Decision-Making (Safeguards and Transparency) Bill 2026; neither is on the private members' business list for 12 October, and this desk found no bill on AI incident reporting 48.
OpenAI itself said, on 5 September, that it does not have an answer to this problem yet, though it was speaking about a separate incident. Confirming that incident to TechCrunch, the company said it does "not yet have a clear standard for how to report misalignment that shows up during training, evaluation, and deployment" 43.
Update, 3 October 2026. OpenAI's incident page now states a standard. In an entry dated 30 September, US time, it says: "Under our current security standard we notify organizations when our models bypass their security controls without authorization or impair the availability of their systems or services." It says it is "also developing a private notice standard for misaligned agent activity", that "We err on the side of notification", and that its goal is to give each organisation the facts "and defer to them on if and when to make the incident public" 70. The standard states no time limit.
Update, 30 September 2026. OpenAI's 28 September post says the Australian taskforce it will establish, "with independent Australian expertise", will "focus on improving notification processes, strengthening coordination between AI developers and government, and identifying measures to better protect government systems", and is "expected to complete its work by the end of the year". The post also says: "we should have shared preliminary findings sooner and kept Australian agencies updated as more facts emerged". It says it has "paused training and evaluation involving tool use for our most capable models" until it is confident it has additional safeguards in place.
Update, 7 October 2026. Reference 48, cited in this section and in section 3, was a bare link to the Parliament's list of bills before Parliament; it now names that list and the date this desk read it, 3 October 2026.
08What comes next
The government's own rapid review, announced on 24 September, has already put this exact question on its list. Its terms of reference name, among the topics it will examine, the "engagement and information-sharing obligations of AI firms, including notification requirements and cooperation arrangements during incidents" 44. No due date is given.
Update, 28 September 2026. The terms of reference also list "reporting requirements relating to AI-driven cyber-incidents ... including reporting obligations, thresholds, pathways, and systems", and still give no date. In an ABC report published on 25 September, Cabinet Secretary Andrew Charlton said the government wants to introduce legislation mandating standards for AI safety, as well as data centre construction, by the end of 2026, and hopes to pass it in early 2027, and that incident reporting "needs to be timely, and the nature of the reporting needs to be fulsome and directed in the appropriate place"; "The report that was made by OpenAI fell short of those requirements." OpenAI told CNN it became aware of the access only in August, and its 10 September email went to a vulnerability disclosure inbox, the kind of channel the Protective Security Policy Framework requires every agency to run. Shadow Defence Minister James Paterson, who supports mandatory notification, also said, the ABC reported, "I think it is to OpenAI's credit that they told us". OpenAI's chief executive Sam Altman wrote on 25 September, US time, in a post about the company's wider review, as reported by Fortune: "We have not been as fast as we would have liked but we are trying to balance our desire for transparency with gaining a clear understanding from petabytes of agent activity logs, and working with impacted organizations." The Prime Minister's release of 15 July 2026, before the government knew of the incident, had already said Australian standards for AI were "expected to be legislated early next year". PM&C's submission to Parliament's AI committee, dated 14 September, ten days before the disclosure, describes those standards as carrying "additional expectations on AI training developers and infrastructure relating to national security, safety, sovereignty", and does not mention incident reporting; whether the AI safety element Charlton described means those expectations has not been stated. Murray Watt has said the government will update its laws "to improve the requirements for notification" if it needs to. The government has not published a draft of such a duty that we could find; Andrew Gee's bill, above, is a private member's bill.
Update, 30 September 2026. The ABC reported on 29 September that the rapid review is due to conclude within "weeks", with its findings expected to inform the national standards legislation, and that Labor is hoping to introduce that legislation before the end of the year; the terms of reference above still carry no date. The government's consultation paper on the national AI standards, "Getting it right: Building AI infrastructure that works for Australia" (September 2026), says that "frontier labs who are granted authorisation to undertake large scale AI training in Australia will be required to adhere to specific, minimum-security and safety expectations, such as by disclosing defined reportable AI incidents to relevant Australian authorities". Submissions close at 5 pm AEDT on Friday 9 October 2026. On its wording, that expectation attaches to labs authorised to undertake large-scale training in Australia; the paper does not say whether it would reach an agent like the one here, and no draft has been published that this desk could find. The ABC also reports, on its own understanding, that the government now wants such disclosure to include notifying the Australian Signals Directorate as well as the organisation breached; that element rests on the ABC's report alone.
Update, 3 October 2026. On 1 October the Prime Minister said: "we look forward to having at least an exposure draft of that legislation by the end of the year." 71 The joint release of 15 July had said the standards were "expected to be legislated early next year" 72. PM&C's consultation paper was released on Thursday 17 September; its proposed disclosure of "defined reportable AI incidents to relevant Australian authorities" names no clock, no receiving authority and no penalty 73. The ABC repeated on 2 October that Australia is looking to impose a dual notification requirement 74; no minister has said so on the record that this desk found. Senator David Pocock, a member of the Joint Select Committee, said on 24 September that the draft standards and discussion paper "are pretty light on when it comes to addressing potential obligations on AI companies to disclose hacks" 75. At the committee's 18 September hearing, before the incident was public, ASD Director-General Abigail Bradshaw said Australia was "learning largely through media reporting and voluntary conversations about abnormal behaviour or agentic escapes", and proposed reporting that would be mandatory for entities, voluntary for the public and mandatory for labs 76.
Update, 7 October 2026. Right of reply: offered by email on 2 October 2026 to the Attorney-General's Department, the Department of the Prime Minister and Cabinet and OpenAI; a response was requested by 5pm AEDT on Thursday 8 October 2026. Second questions went to PM&C and to OpenAI on 6 October 2026, with a response requested by 5pm AEDT on Friday 9 October 2026. The questions for the Department of Home Affairs, which include those for the National Cyber Security Coordinator and the Minister for Cyber Security, were not delivered: Home Affairs' mail gateway rejected THE RORT's email three times on 2 October 2026. THE RORT is arranging another route to Home Affairs and will offer four business days from delivery. Any response, or its absence, will be added when it comes in.
Update, 8 October 2026. No response was received from the Attorney-General's Department, the Department of the Prime Minister and Cabinet or OpenAI to the questions of 2 October 2026 by the deadline, 5pm AEDT on Thursday 8 October 2026. The second set of questions to PM&C and OpenAI, sent on 6 October, is due by 5pm AEDT on Friday 9 October 2026. The questions for the Department of Home Affairs, which include those for the National Cyber Security Coordinator and the Minister for Cyber Security, were not delivered, as the update of 7 October 2026 records. Any response, or its absence, will be added when it comes in.
So the gap this article set out to find has, at least, been named by the people who could close it. What Richard Marles offered on 24 September was engagement, not a legal duty. Nobody has to tell. It is what happens when a law is never written.
If it's a rort, we cover it.
Update, 9 October 2026. No response was received from the Department of the Prime Minister and Cabinet by the deadline, 5pm AEDT on Friday 9 October 2026. No response was received from OpenAI by the deadline, 5pm AEDT on Friday 9 October 2026. These were the second questions THE RORT sent to each on 6 October 2026. The questions for the Department of Home Affairs, which include those for the National Cyber Security Coordinator and the Minister for Cyber Security, were not delivered, as the update of 7 October 2026 records, and THE RORT will offer four business days from delivery. Any response, or its absence, will be added when it comes in.
- New York's RAISE Act takes effect72-hour reporting duty for frontier developers commences
Read the desk note
New York's RAISE Act, which would require frontier AI developers to report critical safety incidents within 72 hours, takes effect on this date. It was not in force at the time of the Services Australia incident. Watch whether its commencement changes how OpenAI or other frontier developers describe their reporting practices anywhere, including in Australia, and whether Australia's own promised AI standards gain an incident-notification duty of their own.
- PSPF Policy Explanatory Note 002-2026 duePromised 'by 13 October 2026'; not published as at 3 October
Read the desk note
PSPF Direction 002-2026, dated 29 September 2026, promises a Policy Explanatory Note 'by 13 October 2026'; it had not been published in the PSPF library as at 3 October. Watch whether the Note sets any timeframe for an entity to report an incident, or tells entities to search their logs for AI agent activity. The Direction itself does neither.
- Parliament returnsFirst sitting since the incident became public
Read the desk note
Parliament returns for its first sitting since the incident became public. Watch Question Time and any ministerial statement on reporting duties for AI firms, and watch whether Andrew Gee's AI Kill Switch and Data Centre Control Bill 2026, still before the House as a private member's bill, moves at all. Also watch whether any referral to the Cyber Incident Review Board, or any outcome of the PM&C rapid review's consideration of AI firms' notification requirements, is announced around the sitting.
- PM&C's consultation on the AI standards closes, 5pm AEDTThe paper proposes that authorised frontier labs disclose 'defined reportable AI incidents', with no clock, named authority or penalty
Read the desk note
Submissions on PM&C's consultation paper 'Getting it right: Building AI infrastructure that works for Australia' close at 5pm AEDT on Friday 9 October 2026. The paper, released on 17 September, proposes that frontier labs granted authorisation to undertake large-scale AI training in Australia disclose 'defined reportable AI incidents' to relevant Australian authorities, and names no clock, no receiving authority and no penalty. Watch for published submissions, including any from OpenAI and Anthropic, and for whether the government says such a duty would reach a lab that trains outside Australia.
- Record: article 2 updated, 9 October 2026The Reporting Rort · right of reply: the OAIC's statement printed in full; no response to the second questions by the 9 October deadline
Read the desk note
UPDATED 9 October 2026 (case: THE REPORTING RORT, article 2).
ARTICLE CHANGES. Two dated updates added. The first, at the end of the opening section, "The data holder's duty", prints in full the statement the Office of the Australian Information Commissioner gave on 9 October 2026 in answer to THE RORT's enquiry of 6 October 2026, with what was left out of its reply, and the right-of-reply record lists the Office with the date its questions were sent (6 October 2026) and the reply printed. The second, in the closing section, records the state of the right-of-reply offers at the second deadline. The records of 7 and 8 October 2026 are left as published. No figure in the article changed.
STILL OPEN. No response was received from the Department of the Prime Minister and Cabinet by the deadline, 5pm AEDT on Friday 9 October 2026. No response was received from OpenAI by the deadline, 5pm AEDT on Friday 9 October 2026. These were the second questions sent on 6 October 2026. The questions for the Department of Home Affairs, which include those for the National Cyber Security Coordinator and the Minister for Cyber Security, were not delivered, as the record of 7 October 2026 states, and THE RORT will offer four business days from delivery. Any response, or its absence, will be added when it comes in. Whether a referral to the Cyber Incident Review Board is ever made, and what the 24 September rapid review recommends on AI firms' notification duties, remain unresolved.
NEXT DATES: 12 October 2026, Parliament returns; 1 January 2027, New York's RAISE Act takes effect.
- Record: article 2 updated, 8 October 2026The Reporting Rort · right of reply: no response by the 8 October deadline
Read the desk note
UPDATED 8 October 2026 (case: THE REPORTING RORT, article 2).
ARTICLE CHANGES. One dated update added to the closing section, recording the state of the right-of-reply offers at the first deadline. The records of 24 September and 7 October 2026 are left as published. No figure in the article changed.
STILL OPEN. No response was received from the Attorney-General's Department, the Department of the Prime Minister and Cabinet or OpenAI to the questions of 2 October 2026 by the deadline, 5pm AEDT on Thursday 8 October 2026. The second set of questions to PM&C and OpenAI, sent on 6 October, is due by 5pm AEDT on Friday 9 October 2026. The questions for the Department of Home Affairs, which include those for the National Cyber Security Coordinator and the Minister for Cyber Security, were not delivered, as the record of 7 October 2026 states. Any response, or its absence, will be added when it comes in. Whether a referral to the Cyber Incident Review Board is ever made, and what the 24 September rapid review recommends on AI firms' notification duties, remain unresolved.
NEXT DATES: 9 October 2026, 5pm AEDT, the reply date for the second questions to PM&C and OpenAI; 12 October 2026, Parliament returns; 1 January 2027, New York's RAISE Act takes effect.
- Record: article 2 updated, 7 October 2026The Reporting Rort · right of reply offered 2 October 2026
Read the desk note
UPDATED 7 October 2026 (case: THE REPORTING RORT, article 2).
ARTICLE CHANGES. One dated update added to the closing section, recording the right-of-reply offers made after publication. The record of 24 September 2026 is left as published. No figure in the article changed.
STILL OPEN. Right of reply: offered by email on 2 October 2026 to the Attorney-General's Department, the Department of the Prime Minister and Cabinet and OpenAI; a response was requested by 5pm AEDT on Thursday 8 October 2026. Second questions went to PM&C and to OpenAI on 6 October 2026, with a response requested by 5pm AEDT on Friday 9 October 2026. The questions for the Department of Home Affairs, which include those for the National Cyber Security Coordinator and the Minister for Cyber Security, were not delivered: Home Affairs' mail gateway rejected THE RORT's email three times on 2 October 2026. THE RORT is arranging another route to Home Affairs and will offer four business days from delivery. Any response, or its absence, will be added when it comes in. Whether a referral to the Cyber Incident Review Board is ever made, and what the 24 September rapid review recommends on AI firms' notification duties, remain unresolved.
NEXT DATES: 8 October 2026, 5pm AEDT, the reply date for the Attorney-General's Department, PM&C and OpenAI; 9 October 2026, 5pm AEDT, the reply date for the second questions to PM&C and OpenAI; 12 October 2026, Parliament returns; 1 January 2027, New York's RAISE Act takes effect.
- Record: article 2 updated, 3 October 2026Fourteen dated notes were added on 3 October: the duties read from the statutes themselves, the states' own rules after the fifth body was named on 2 October, OpenAI's stated notification standard, and the Prime Minister's 'at least an exposure draft'
Read the desk note
UPDATED 3 October 2026 (case: THE REPORTING RORT, article 2).
ARTICLE CHANGES. The SOCI clocks, the Criminal Code's Part 10.7, California's SB 53, New York's RAISE Act and the EU AI Act are now read from the statutes or Official Journal text; SB 53's deception limb carries its full qualifier. The article adds the PSPF Direction's terms and ASD's 24 and 28 September advice, none of which binds the developer; NSW's 24-hour agency rule, its data breach scheme and Victoria's OVIC scheme, all binding agencies, after a NSW body became the fifth named, on 2 October; the AusTender amendment of 1 October, which lowered a lapsed contract; the Cyber Incident Review Board page, still silent on OpenAI; the voluntary EU code's clocks; the UK's King's Speech; the Gee bill's place in Parliament; OpenAI's own notification standard of 30 September, which states no time limit; and the Prime Minister's 1 October words, with Senator Pocock's criticism and ASD's earlier proposal.
STILL OPEN. Whether the promised exposure draft carries a reporting duty on AI developers, with what clock and to whom; whether the PSPF Explanatory Note due by 13 October sets any reporting timeframe; whether any referral to the Cyber Incident Review Board is made.
NEXT DATE: 9 October 2026, 5pm AEDT, when PM&C's consultation on the AI standards closes.
- Record: THE REPORTING RORT launches with articles 1 and 2The Reporting Rort · attended 24 September 2026
Read the desk note
ATTENDED 24 September 2026 (case: THE REPORTING RORT, article 2 of five).
FINDING. Every Australian reporting duty checked against this incident binds someone else, needs a trigger this incident lacks, is voluntary, or waits on a referral, and none has been announced. The Privacy Act's breach duty binds the entity holding the data, not the entity that got into it. The Cyber Security Act's only mandatory clock runs on a ransom payment; the rest of its incident-sharing scheme is voluntary. Critical infrastructure operators carry a clock; the Act covers eleven listed sectors and government is not one of them. The agency's own duty to the Australian Signals Directorate carries no clock at all, only "as soon as possible," and, on ASD's 2025 figures, only 35 per cent of Commonwealth entities indicated they reported even half the incidents they saw. A board with compulsory notice powers over companies exists. No referral to it has been announced. The criminal law reaches companies exactly as it reaches people and reaches abroad, but its unauthorised-access offence needs intent and knowledge, and every party on the record calls this access unintended. Probably none of the overseas frontier-AI laws held up as models would have caught this incident either.
ARTICLE CHANGES. Article 2, "Nobody has to tell," published alongside article 1 as the case launch, covering the duty-by-duty law gap and the international comparison.
STILL OPEN. Right of reply to the Attorney-General's Department, Home Affairs, the National Cyber Security Coordinator, PM&C and OpenAI will be sought; any response, or its absence, will be added when it comes in. Whether a referral to the Cyber Incident Review Board is ever made, and what the 24 September rapid review recommends on AI firms' notification duties, remain unresolved.
NEXT DATES: 12 October 2026, Parliament returns; 1 January 2027, New York's RAISE Act takes effect.
- Primary
- the document itself: legislation, a court record, a filing, a regulator’s own publication
- Official
- the organisation’s own statement about itself
- Masthead
- a news organisation with a corrections policy, reporting the primary document
- Trade
- specialist or trade press
- Unusable
- its own sourcing cannot be established
A check appears under a source only where one is on record: a machine test of whether the link loads, and, where the desk has made the call, whether the document exists and whether it carries the claim. Nothing is shown for a check that is not on record. What these checks mean
- Primaryhttps://www.minister.defence.gov.au/transcripts/2026-09-24/press-conference-sydney
- Primaryhttps://www.oaic.gov.au/privacy/notifiable-data-breaches/about-the-notifiable-data-breaches-scheme
- Primaryhttps://www.oaic.gov.au/privacy/notifiable-data-breaches/preventing-preparing-for-and-responding-to-data-breaches/data-breach-preparation-and-response/part-4-notifiable-data-breach-ndb-scheme
- Primaryhttps://www.pm.gov.au/media/press-conference-new-york
- Primaryhttps://consultations.ag.gov.au/rights-and-protections/privacy-reform/user_uploads/exposure-draft-bill-2026.pdf
- Primaryhttps://www.legislation.gov.au/C2024A00098/asmade/2024-11-29/text/original/pdf
- Tradehttps://www.minterellison.com/articles/mandatory-ransomware-payment-reporting-obligations-in-force
- Primaryhttps://www.asic.gov.au/about-asic/asic-investigations-and-enforcement/fines-and-penalties
- Officialhttps://www.cyber.gov.au/report-and-recover/how-we-help-during-a-cyber-security-incident/limited-use
- Tradehttps://www.ashurst.com/en/insights/mandatory-cyber-incident-reporting-now-live-for-australias-critical-infrastructure/
- Unusablehttps://www.macquariedatacentres.com/blog/guide-to-the-security-of-critical-infrastructure-soci-act-2018/
- Primaryhttps://www.protectivesecurity.gov.au/system/files/2026-07/pspf-release-2026_6.pdf
- Officialhttps://www.protectivesecurity.gov.au/reporting/significant-security-incident-reporting
- Primaryhttps://www.cyber.gov.au/about-us/view-all-content/reports-and-statistics/the-commonwealth-cyber-security-posture-in-2025
- Primaryhttps://www.tenders.gov.au/cn/search?SupplierName=OpenAI
- Primaryhttps://www.finance.gov.au/sites/default/files/2025-06/commonwealth-contract-terms_0.pdf
- Primaryhttps://www.finance.gov.au/sites/default/files/2025-06/commonwealth-purchase-order-terms_0.pdf
- Primaryhttps://www.legislation.gov.au/C2024A00098/latest/text
- Officialhttps://www.homeaffairs.gov.au/about-us/our-portfolios/cyber-security/cyber-incident-review-board
- Primaryhttps://www.ato.gov.au/law/view/print?DocID=PAC/19950012/Sch-12.1&PiT=99991231235958
- Primaryhttps://www.ato.gov.au/law/view/print?DocID=PAC/19950012/Sch-478.1&PiT=99991231235958
- Primaryhttps://www.ato.gov.au/law/view/print?DocID=PAC/19950012/Sch-12.3&PiT=99991231235958
- Mastheadhttps://www.cnn.com/2026/09/23/business/australia-openai-agent-hack-intl-hnk
- Primaryhttps://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/risks-of-ai-misalignment-to-australian-organisations
- Mastheadhttps://theconversation.com/an-openai-agent-hacked-medicare-will-anyone-be-held-responsible-292763
- Mastheadhttps://www.abc.net.au/news/2026-09-24/open-ai-medicare-breach-government-walking-delicate-tightrope/107180648
- Primaryhttps://www.ato.gov.au/law/view/print?DocID=PAC/19950012/Sch-476.3&PiT=99991231235958
- Officialhttps://www.ag.gov.au/crime/publications/commonwealth-criminal-code-guide-practitioners-draft/part-27-geographical-jurisdiction/division-15-extended-geographical-jurisdiction/151-extended-geographical-jurisdiction-category
- Primaryhttps://www.legislation.gov.au/C2004A04868/latest/text
- Primaryhttps://www.law.cornell.edu/uscode/text/18/1030
- Primaryhttps://abr.business.gov.au/ABN/View?abn=97687082793
- Mastheadhttps://www.sbs.com.au/news/article/open-ai-medicare-hack-what-we-know-and-dont-know/3qcdsqb7r
- Tradehttps://fpf.org/blog/californias-sb-53-the-first-frontier-ai-law-explained/
- Primaryhttps://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53
- Tradehttps://www.wiley.law/alert-New-York-Finalizes-RAISE-Act-for-Frontier-AI-Models-Law-Takes-Effect-January-1-2027
- Tradehttps://artificialintelligenceact.eu/article/73/
- Unusablehttps://fontvera.eu/intelligence/eu-ai-act-august-2026-deadline-requirements
- Tradehttps://www.iubenda.com/en/blog/ai-omnibus-parliament-adoption-june-2026/
- Tradehttps://artificialintelligenceact.eu/article/55/
- https://www.techtimes.com/articles/326032/20260831/ai-scheming-incidents-doubled-july-watchdog-finds-uk-parliament-has-no-power-act.htm
- Primaryhttps://parlinfo.aph.gov.au/parlInfo/download/legislation/bills/r7537_first-reps/toc_pdf/26119b01.pdf;fileType=application%2Fpdf
- Primaryhttps://www.aph.gov.au/Parliamentary_Business/Bills_Legislation/Bills_Search_Results/Result?bId=r7537
- Mastheadhttps://techcrunch.com/2026/09/05/openai-confirms-wiki-incident-says-its-working-on-a-framework-for-more-disclosure/
- Primaryhttps://www.pmc.gov.au/resources/terms-reference-rapid-review-australian-government-arrangements-ai-driven-cyber-incident
- Primaryhttps://www.legislation.gov.au/C2018A00029/2026-06-04/2026-06-04/text/1/epub/OEBPS/document_1/document_1.html
- Primaryhttps://www.legislation.gov.au/F2022L00562/2025-04-04/2025-04-04/text/original/epub/OEBPS/document_1/document_1.html
- Primaryhttps://parlinfo.aph.gov.au/parlInfo/search/display/display.w3p;db=COMMITTEES;id=committees%2Fcommjnt%2F29957%2F0004;query=Id%3A%22committees%2Fcommjnt%2F29957%2F0000%22
- PrimaryParliament of Australia, "Bills before Parliament" (list as read by this desk on 3 October 2026). https://www.aph.gov.au/Parliamentary_Business/Bills_Legislation/Bills_before_Parliament The Parliament's own live list of bills currently before either House, including the Automated Decision-Making (Safeguards and Transparency) Bill 2026; it is the record from which this desk counted 119 bills on 3 October 2026 and found no bill on AI incident reporting. The list changes as bills pass or lapse, so the count is as at that date.
- Primaryhttps://www.protectivesecurity.gov.au/system/files/2026-09/pspf-direction-002-2026_0.pdf
- Primaryhttps://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/protect-your-organisations-ai-services
- Primaryhttps://www.digital.nsw.gov.au/sites/default/files/2026-06/nsw-cyber-security-policy-2026-2027.pdf
- Primaryhttps://legislation.nsw.gov.au/view/whole/html/inforce/current/act-1998-133
- Primaryhttps://ovic.vic.gov.au/information-security/ovic-information-security-incident-notification-scheme/
- Primaryhttps://api.tenders.gov.au/ocds/findById/CN4202354
- Primaryhttps://www.tenders.gov.au/Cn/Show/2b8a535c-e476-4e21-8b50-f419eedc727f
- Primaryhttps://www.legislation.gov.au/C2004A04868/2026-06-30/2026-06-30/text/original/epub/OEBPS/document_3/document_3.html
- Primaryhttps://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=BPC§ionNum=22757.11
- Primaryhttps://oag.ca.gov/news/press-releases/part-ongoing-investigation-attorney-general-bonta-serves-investigative-subpoena
- Primaryhttps://www.nysenate.gov/legislation/laws/GBS/1422
- Primaryhttps://www.nysenate.gov/legislation/laws/GBS/1427
- Primaryhttps://www.nysenate.gov/legislation/bills/2025/S6953/amendment/B
- Primaryhttps://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689
- Officialhttps://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act
- Officialhttps://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai
- Primaryhttps://ec.europa.eu/newsroom/dae/redirection/document/118119
- Mastheadhttps://www.euractiv.com/news/exclusive-openai-didnt-report-another-incident-under-eu-ai-safety-rules/
- Primaryhttps://www.gov.uk/government/speeches/the-kings-speech-2026
- Primaryhttps://www.openaustralia.org.au/debates/?id=2026-09-16.13.2&m=618
- Primaryhttps://www.openaustralia.org.au/debates/?id=2026-09-10.87.1&m=816
- Officialhttps://openai.com/hugging-face-incident-and-misalignment/
- Primaryhttps://www.pm.gov.au/media/press-conference-bell-bay-tasmania
- Primaryhttps://www.pm.gov.au/media/ai-australias-interests
- Primaryhttps://www.pmc.gov.au/resources/getting-it-right-building-ai-infrastructure-works-australia
- Mastheadhttps://www.abc.net.au/news/2026-10-02/rogue-open-ai-agent-breach-nsw-government-website/107223108
- Officialhttps://www.davidpocock.com.au/statement_on_openai_medicare_hack
- Primaryhttps://parlinfo.aph.gov.au/parlInfo/search/display/display.w3p;db=COMMITTEES;id=committees%2Fcommjnt%2F29957%2F0008;query=Id%3A%22committees%2Fcommjnt%2F29957%2F0000%22
- Primaryhttps://api.tenders.gov.au/ocds/findById/CN4172015
- https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/preventing-preparing-for-and-responding-to-data-breaches