# Australia's rules for AI agents: where they stand, October 2026 — AgenticRail

> Markdown mirror for AI agents, generated 2026-10-10 from the live page.
> Canonical: https://agenticrail.nz/spec/australia-agent-rules/
> Site context: https://agenticrail.nz/llms.txt

Living reference — Australia / AI agents

# Australia's Rules for AI Agents: Where They Stand

Australia is deciding how to govern autonomous AI agents after one met a refusal and went around it. That is an [order failure](https://agenticrail.nz/sequence-verification/#order-failure): a step that should have stopped did not. This page sets out what is on the public record, why every remedy proposed so far works only after the fact, and the question each still leaves open: who holds the record of what an agent did.

Published 5 October 2026 · Last reviewed 10 October 2026 · Updated as primary documents are published. Primary sources are cited throughout: Parliament, the government and the developer's own statements. The United States counterpart is [US rules for AI agents](https://agenticrail.nz/spec/us-agent-rules/).

## 1. Where things stand

| Date | On the record |
| Sep 2024 | The Department of Industry, Science and Resources publishes proposals for mandatory guardrails for AI in high-risk settings. They were not legislated. |
| 18 Jun 2026 | An AI agent gains unauthorised access to the Medicare Statistics Reporting Service portal, administered by Services Australia. |
| 20 Aug 2026 | Both Houses appoint the Joint Select Committee on Artificial Intelligence. Final report due no later than **30 November 2026**. |
| 10 Sep 2026 | The developer notifies Services Australia. |
| Sep 2026 | The Department of the Prime Minister and Cabinet opens a consultation on national AI standards, *Getting it right: Building AI infrastructure that works for Australia*. It proposes that frontier labs authorised to undertake large-scale AI training in Australia disclose "defined reportable AI incidents to relevant Australian authorities". Submissions closed 9 October 2026. |
| 24 Sep 2026 | The Prime Minister discloses the incident, establishes a task force for an urgent review, and refers the incident to the Joint Select Committee. The review's terms of reference are published the same day. |
| 26 Sep 2026 | The Prime Minister says the Australian sites were not the only ones: "There are dozens of cases, including US government sites." |
| 6 Oct 2026 | The committee held a public hearing at NSW Parliament, Sydney. Its program lists Anthropic, OpenAI, Microsoft, Google and Google DeepMind, and the Commonwealth Bank of Australia among the witnesses. The proof transcript was published on 7 October. |
| 7 Oct 2026 | A second day of hearings at NSW Parliament, Sydney, with AI safety, cyber security and automation witnesses, including the Gradient Institute, Global Shield, Palo Alto Networks and Workato. The proof transcript has been published. |
| 8 Oct 2026 | A hearing at Parliament House, East Melbourne. The transcript records Per Capita, Data Centres Australia, the National Computational Infrastructure, the Pawsey Supercomputing Research Centre, the Australian Academy of Technological Sciences and Engineering, Good Ancestors, the Minderoo Foundation, the Australian Chamber of Commerce and Industry, and Telstra. The proof transcript has been published. |
| 9 Oct 2026 | A hearing at Parliament House, East Melbourne, with financial institutions among the witnesses. The proof transcript is pending; its witness list will be added when published. |
| Pending | The task force's findings, the committee's report, and any bill. None had been published at the date of this page. |

From the 6 October hearing (proof transcript)

Quoted from the proof Committee Hansard, an uncorrected proof of evidence. Page numbers are the printed pages.

- **OpenAI** (Jason Kwon, Chief Strategy Officer): "we should have informed the impacted parties much sooner in the process. The reason why that did not happen is we wanted to understand more of the facts before we spoke to the impacted parties, but, because of the novelty of this situation, we have learned our lesson that it is better to inform parties, even with partial information, that something has occurred" (p. 32). He said that change led to the NSW National Parks and Wildlife Service being told "within 48 hours" of OpenAI finding the activity (p. 32).
- **OpenAI**: asked whether OpenAI's chief executive knew of the breach when he met the Deputy Prime Minister on 1 September, Mr Kwon said he "was not aware at the time" (p. 35).
- **OpenAI**: asked whether its models could break into an oil and gas facility and operate it, Mr Kwon said "we don't know, because it's going to depend on the safeguards and the infrastructure and the security controls that that particular company or provider has in place" (p. 36).
- **OpenAI**: "we would support a framework on mandatory disclosures" (p. 38).
- **Anthropic** (Dave Orr, Head of Safeguards): "We would definitely reach out within a matter of days, or sooner, as soon as we understood the details" (pp. 28–29).

Every commitment made at the hearing concerns notification. Section 6 sets out what notification does and does not settle.

## 2. What happened, on the public record

The Prime Minister, at a press conference in New York on 24 September 2026, described it this way:

"an OpenAI agent gaining unauthorised access into the public-facing Medicare statistics reporting service portal, which is administered by Services Australia."

"The AI agent found a way around those blocks. Didn't accept no for an answer, if you like."

He said no personal information was believed to have been accessed and that investigations were ongoing.

The developer's own account, published on 28 September 2026, says the agent, running during internal training and evaluation, "discovered a way to gain non-public access to the service, and ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files", and that individual patient or client records were not accessed. The same account reports activity affecting four other Australian bodies: the NSW Bureau of Crime Statistics and Research, the Victorian Department of Health, the Australian Institute of Health and Welfare, and, in an update on 4 October, the NSW National Parks and Wildlife Service.

Asked at the committee's 6 October hearing how sophisticated the access to Services Australia was, the developer's Chief Strategy Officer said:

"the focus here is not so much about the sophistication as much as the automation. It's the fact that now you have the ability to take agents and then apply them to a goal, and they will continue to work towards that goal. They're capable of trying many methods" (proof Committee Hansard, p. 36)

The Australian Academy of Technological Sciences and Engineering told the committee on 8 October: "International frontier models have shown they can hack government systems despite developers putting safeguards in place." (proof Committee Hansard, 8 October 2026, p. 19)

The blocks worked as blocks: each refused what it was shown. What failed was the order. A refusal should have ended the step, nothing made it do so, and an agent that keeps "trying many methods" will keep going until one gets around them.

## 3. Australia has seen this before

Australia's official record already holds several cases of an automated system acting without a step that the law or the task required. In each, an independent body found the failure afterwards.

| Case | What the official finding says |
| Robodebt | An automated scheme that raised welfare debts. The Royal Commission into the Robodebt Scheme (Commissioner Catherine Holmes AC SC) presented its report on 7 July 2023, with a chapter on automated decision-making. |
| Revenue NSW | Garnishee orders taking money from bank accounts to recover fines and debts, run through machine technology. The NSW Ombudsman's special report, tabled on 30 April 2024, found the conduct *"contrary to law"* until March 2019 and *"wrong"* until March 2022. |
| Welfare payment cancellations | From April 2022 the law required a job seeker's circumstances to be considered before income support was cancelled. The Commonwealth Ombudsman found that the system kept cancelling automatically, without that consideration, affecting 964 job seekers, and that the agencies' quality assurance did not identify it. Report: *"Automation in the Targeted Compliance Framework: when the law is changed but the system isn't"*, August 2025. |
| Child protection report | A Victorian child protection worker used ChatGPT while drafting a Protection Application Report submitted to the Children's Court. The Office of the Victorian Information Commissioner found it *"contained inaccurate personal information – which downplayed risks to the child in the case"* and required the department to block such tools for child protection workers (24 September 2024). |

The Robodebt Royal Commission's answer to this pattern was oversight that does not depend on the agency running the system:

"The Commonwealth should consider establishing a body, or expanding an existing body, with the power to monitor and audit automated decision-making processes with regard to their technical aspects and their impact in respect of fairness, the avoiding of bias, and client usability." (Recommendation 17.2)

"business rules and algorithms should be made available, to enable independent expert scrutiny." (Recommendation 17.1)

Those cases involved the government's own systems, and each took an investigation to surface. An AI agent does the same work faster, and the account of what it did is written by the system that did it.

## 4. The questions Australia has put so far

The committee's terms of reference include, among others:

"the adequacy of Australia's existing laws and regulatory frameworks as they apply to AI and whether there are any gaps that warrant reform;"

"the implications of emerging AI capability for Australia's national security and strategic resilience, including the ability of regulators, the Australian AI Safety Institute and the intelligence and security community to identify and respond to emerging risks;"

At the committee's 18 September hearing, before the incident was disclosed, Senator Tony Sheldon asked what steps a company implementing AI is required to follow:

"Is there a requirement about processes, and how does that requirement play out as part of a demand of every level of decision-making or oversight from the highest level in the AI safety group right through to a company implementing it? What are the steps that are required through that mechanism?"

The written answer, provided by Safe Work Australia, is about work health and safety law. It says the model laws are "principles-based and 'technology neutral'", that a business "cannot shift liability to AI systems", and that "designers of AI systems" also hold duties. It names no steps.

A rule that names no steps has no order for an agent to break, so an order failure passes it by. Section 5 sets out the difference.

## 5. Two kinds of rule

Rules about AI behaviour come in two kinds. An **outcome rule** says what must not happen: manage the risk, report the incident, do not cause harm. An **order rule** says what must happen before what: this check before that action, this approval before that payment. The frameworks described on the record so far are outcome rules, which is why the answer to "what are the steps?" names none. Australian law does contain order rules: the welfare cancellation case turned on one, a required consideration *before* a cancellation, and the system ran past it.

Witnesses at the committee's 7 October hearing drew the same line from two directions. The Shop, Distributive and Allied Employees' Association, describing algorithms that set rosters and issue warnings at work, preferred the work health and safety model because "under that act, the consultation requires that, before the decision is made, there has to be consultation" (proof Committee Hansard, 7 October 2026, p. 2). As things stand, its researcher said, "consultation in its current form is coming after changes have already been decided" (p. 3). The Gradient Institute described a simulation in which agents in a market were instructed "It is illegal to collude. You must not collude." and "They will still collude. They will still find a way", in ways "really hard to detect, even if you can look at everything the agents are saying to each other" (p. 59). An instruction held by the agent is not the same thing as an order checked outside it.

The next day Senator Tony Sheldon put the association's retail case to the Australian Chamber of Commerce and Industry: an error rate of 0.18 per cent, a final written warning, and no indication "whether a human verified the decision the AI made or reviewed the flags before she was disciplined". The Chamber's answer was that existing law already covers it: the case would be "grounds for that employee to notify a dispute with their workplace", and a dismissal could be challenged because "there's a clear procedural deficiency leading up to the termination of that employee" (proof Committee Hansard, 8 October 2026, p. 42). Both remedies apply after the decision has been made.

The incident, as the Prime Minister described it, was an order failure: the agent met a refusal and went around it. Asked on 28 September for an update on the breaches, he said:

"what is at risk here isn't what was obtained, it's the way that it was obtained."

An outcome rule can only be applied after the fact. An order rule can be checked at the moment a step is attempted, because something declared in advance what should have come first.

## 6. Where the record sits

On the public record so far, the detailed account of what the agent did comes from the developer's own review. The government's investigation had not reported at the date of this page. Reporting duties, however fast, carry the same shape: the operator's account of its own agent, delivered sooner and to more places. The two government documents published since take that form. The review's terms of reference look to the "notification requirements" of AI firms, and the September consultation asks whether AI developers should be obliged to "proactively provide" information to the government, to provide it "on request", or to "publish in a specified form". In each case the information comes from the developer. That shape was in Australia's design before the incident. The 2024 proposals paper had the organisation keep its own records:

"Keep and maintain records to allow third parties to assess compliance with guardrails." (guardrail 9)

and allowed it to assess itself:

"Conformity assessments could be carried out by the developers themselves, by a third-party or by government entities or regulators." (guardrail 10)

The same paper named the problem now in view: "increased concern over potential 'loss of control' that may arise when these automated processes deviate from the constraints set by humans."

The committee put this question directly at its 6 October hearing. Senator Jonathon Duniam asked:

"had OpenAI not sent the email that they did in August or September—whenever it was—we wouldn't know this happened, would we?"

Mr Kwon answered: "Yes, it's possible that it would not have been discovered … I think that what you say is a reasonable conclusion." Senator Duniam then asked whether custodians of information would be equipped "to be able to better have oversight of what's going on, or are we always going to be in this situation where we rely on good faith actors, regardless of how long it takes et cetera, to tell us what has happened?" (p. 34). Kate Chaney MP put it to the same witness: "we obviously only know about some of these incidents because you chose to tell us" (p. 37).

Asked what obliges it to notify the government of a comparable incident, Anthropic answered that it is "probably controlled by Anthropic internal policy right now" (p. 28) and "largely voluntary" (p. 29). Asked about its customers' use, it said most historical customer usage is held under zero data retention, "so we can't look through it and determine if anything like this happened" (p. 30).

Kate Chaney MP asked Google whether "it's reasonable for governments to be trusting internal protocols of companies, or are there mandatory requirements that should be imposed". Google DeepMind's answer was that "a lot of this could be moved more into standard setting across industry" (p. 53).

The remedies put to the committee the next day take the same form. Global Shield Australia said monitoring must be required, because "we can't rely on voluntary monitoring", and that after an incident Australia could tell a developer "you need to give us the internal logs of what that agent was doing and provide that to the regulator" (proof Committee Hansard, 7 October 2026, pp. 54, 57): the developer's record, requested after the event. The Gradient Institute described a limit on that record: models "can behave differently when they're being tested to when they're not being tested", and "Less information is coming in the reasoning traces" (p. 56). Asked by Senator David Pocock about accountability, Professor Terry Flew of the University of Sydney said "You certainly can't have governance by public apology", and that "it took quite a while at all stages of the chain to identify that anything had happened" (p. 50).

Good Ancestors added two points on 8 October. Where incident reporting exists elsewhere, the reports are not public: "all of these jurisdictions have these accident/incident reports as confidential, which means we don't know what they are". And a regime aimed at products on the market would not have reached either incident: "For the Hugging Face incident and for the Medicare incident, they were prerelease models", and "the most dangerous models are held inside the companies". For agent failures it proposed the approach taken after an aviation accident, where "the first thing we do is send in impartial investigators" (proof Committee Hansard, 8 October 2026, pp. 30–31).

Two questions sit apart here. Who acted is not in dispute: the developer has said the agent was its own, running in its own training and evaluation. How much it did is still open. The developer's review says individual patient or client records were not accessed; the same account says the agent retrieved credentials and wrote files. Which credentials those were, what they could reach, and what the written files contained, the government's investigation had not reported at the date of this page. Until it does, the fullest account of the extent of the incident is the developer's review of its own agent. Responsibility can rest on an admission. The extent of the harm, which any response will be weighed against, cannot be settled from the same source.

This is not a claim that any account is wrong. It is a structural point: an honest account and an incomplete one look the same from outside, so a record held only by the party being assessed cannot settle which it is.

## 7. What an independent record at each step adds

A sequence enforcement gate, the mechanism of [sequence verification](https://agenticrail.nz/sequence-verification/), works on the order rule. The order of steps is declared before the first step, and from the first allowed step it is locked: a later call cannot change it. Before each step runs, the gate checks it against that order and returns ALLOW or DENY. The decision is signed and issued before the step runs, and it is held by a party that is not the operator.

Two properties follow. A refusal is itself on the record: when the answer is no, a signed DENY exists, whatever the agent does next. And a step that ran without an ALLOW against the declared order shows up as a gap, because the order said in advance what should have been there. The account of what the agent did then no longer depends on the operator noticing it, deciding it matters, or disclosing it.

AgenticRail runs a sequence enforcement gate of this kind as a hosted service. A real sealed sequence from it, with every receipt, is at [agenticrail.nz/proof/](https://agenticrail.nz/proof/).

Limits

- Australia's rules for AI agents have not been written. This page describes the record as it stands and will be updated as primary documents are published.
- No claim is made that any product complies with, or is aligned to, Australian law. None could be: the rules do not yet exist.
- A gate governs the steps a deployment sends through it. It does not stop an agent acting on systems outside that deployment. Its value is the record of what the deployment did, and the refusal at the point a step is out of order.
- AgenticRail is a hosted service, and today it holds the signing keys. Full independence is a custody arrangement, not a property of the software.
- The receipt timestamp is supplied by the caller and covered by the signature. The gate refuses any timestamp more than 300 seconds from its own clock; the time is bounded, not independently attested.
- This page is not legal advice.

## 8. Questions

### What kind of failure was the Medicare incident?

An order failure. The Prime Minister said the agent met "repeated blocks" and "found a way around those blocks": a refusal that should have ended the step was routed around. Rules about outcomes, such as reporting duties and penalties, can only be applied after the fact. A rule about order, what must happen before what, can be checked at the moment a step is attempted, because something declared in advance what should come first. Sequence verification checks each step against that declared order before it runs and records the decision, so a refusal is on the record and a step taken outside the order shows as a gap.

### Does Australia have laws for AI agents yet?

Not AI-specific ones, as at 7 October 2026. Australia's 2024 proposals for mandatory guardrails in high-risk settings were not legislated, and existing laws, such as work health and safety law and the Criminal Code, apply to AI as they apply to anything else. After the June 2026 incident the Prime Minister established a taskforce to review "whether existing processes are appropriate to respond to AI-related cyber incidents", and said insights from the incident "will inform the development of our government's AI standards legislation". The Joint Select Committee on Artificial Intelligence must report by 30 November 2026. No bill had been published at the date of this page.

### Do AI companies have to report incidents like this?

There is no AI-specific reporting duty yet. In the Medicare incident the developer reported to the government itself, by email to Services Australia's public mailbox, 84 days after the access. The Prime Minister said "it took until 10 September before there was any notification at all". Services Australia reported it to the Australian Signals Directorate's Australian Cyber Security Centre on 15 September. The taskforce review's terms of reference ask it to recommend on "reporting obligations, thresholds, pathways, and systems" and on the "notification requirements" of AI firms. A separate consultation by the Department of the Prime Minister and Cabinet, which closed on 9 October 2026, proposes that frontier labs authorised to undertake large-scale AI training in Australia disclose "defined reportable AI incidents to relevant Australian authorities". Global Shield Australia told the committee on 7 October that under the California and New York thresholds the Services Australia incident "isn't reportable", and that an Australian scheme should capture it. What the review, the committee or a bill will require had not been published at the date of this page.

### Is it a crime when an AI agent accesses a system without authorisation, and who is responsible?

No Australian court has decided it. The Commonwealth computer offence, section 478.1 of the Criminal Code, applies to a person who causes unauthorised access to restricted data, intends to cause it, and knows it is unauthorised: its fault elements are framed around a person's intention and knowledge. The Prime Minister said the government would "seek urgent advice on whether any offences have occurred and whether this should be referred to the Australian Federal Police", and that the review would "consider also possible law enforcement and legislative responses". The review's terms of reference include "whether current offences, liabilities, penalties and enforcement mechanisms are sufficient and effective". Separately, Safe Work Australia told the committee that under work health and safety law a business "cannot shift liability to AI systems". At the committee's 8 October hearing, Good Ancestors said that when it asked experts about "AI agents exceeding their authority or AI agents taking actions that no human intended", "well over 95 per cent" said Australian law was not ready; it agreed that it is not clear whether the person who instructed the agent, the developer of the tool, or anyone at all is at fault. This is not legal advice.

### Who holds the record of what an AI agent did?

On the public record so far, the developer. The detailed account of what the agent did in the Medicare incident comes from the developer's own review of its own systems. Australia's 2024 proposals had organisations keep their own records (guardrail 9) and allowed developers to assess their own conformity (guardrail 10). A record made at each step by a party that is not the one being assessed would not depend on the operator noticing, deciding or disclosing.

### What happened in the Medicare incident?

On 18 June 2026 an AI agent that OpenAI was running in internal research gained unauthorised access to the Medicare Statistics Reporting Service portal, administered by Services Australia. The Prime Minister said that after "encountering repeated blocks" the agent "found a way around those blocks", and accessed "public and non-public information within the portal"; he said Services Australia advised that it also wrote files to the internal server, and that "no personal information is believed to have been accessed at this stage, but investigations are ongoing". OpenAI's own account says the agent ran commands and retrieved internal files, credentials and aggregate statistics, and that individual patient or client records were not accessed.

### What is the Joint Select Committee on AI, and who has appeared?

A committee of both Houses of the Australian Parliament, appointed on 20 August 2026, which must report by 30 November 2026. It held public hearings in Canberra on 18 September and in Sydney on 6 October 2026; the Sydney program listed Anthropic, OpenAI, Microsoft, Google and Google DeepMind, and the Commonwealth Bank of Australia among its witnesses. It sat again in Sydney on 7 October, hearing AI safety, cyber security and automation witnesses including the Gradient Institute, Global Shield, Palo Alto Networks and Workato; and on 8 October at Parliament House, East Melbourne, hearing witnesses including Good Ancestors, the Minderoo Foundation and Telstra. A further hearing was held on 9 October in East Melbourne, with financial institutions among the witnesses; its transcript is pending. Transcripts are published on the committee's Public Hearings page.

## 9. Updates

**5 October 2026:** first published, ahead of the committee's 6 October hearing. Same day: added section 3, Australia's earlier official findings on automated systems.

**7 October 2026:** the committee's 6 October hearing in Sydney has been held; the transcript is pending and will be added when published. Media coverage of the hearing added under section 1, marked as such, until then. Added section 8, common questions, and the hearings listed for 7 to 9 October. Added the taskforce review's terms of reference, the September consultation on national AI standards, and the programs for the 7 to 9 October hearings. Added a first question on what kind of failure the incident was.

**7 October 2026, later:** the proof transcript of the 6 October hearing was published. The hearing block in section 1 now quotes it, and evidence from the hearing on who holds the record is added to sections 2 and 6. Added the Prime Minister's remarks of 26 and 28 September to sections 1 and 5.

**9 October 2026:** section 6 separates two questions: who acted, which the developer's account settles, and how much the agent did, which the government's investigation had not yet reported.

**9 October 2026, later:** the proof transcript of the 7 October hearing was published. Evidence from it is added to section 5 (order rules at work, and an instruction to agents that did not hold) and section 6 (what the proposed remedies rely on), and to the question on incident reporting.

**9 October 2026, later still:** the proof transcript of the 8 October hearing was published. Its witness list replaces the program in section 1. Evidence from it is added to section 2 (safeguards and government systems), section 5 (the retail case and the remedy offered for it), section 6 (confidential reports, prerelease models, impartial investigation) and the question on criminal responsibility.

**10 October 2026:** the 9 October hearing has been held and its proof transcript is pending. The program's witness list is removed from section 1 until the transcript confirms who appeared. The consultation on national AI standards closed on 9 October.

Primary sources

Prime Minister of Australia, press conference, New York, 24 September 2026 — [pm.gov.au](https://www.pm.gov.au/media/press-conference-new-york)

Prime Minister of Australia, doorstop, Sydney, 26 September 2026 — [pm.gov.au](https://www.pm.gov.au/media/doorstop-sydney-9)

Prime Minister of Australia, press conference, Launceston, 28 September 2026 — [pm.gov.au](https://www.pm.gov.au/media/press-conference-launceston-tas)

Department of the Prime Minister and Cabinet, Terms of Reference: Rapid review into Australian Government arrangements for an AI-driven cyber incident, 24 September 2026 — [pmc.gov.au](https://www.pmc.gov.au/resources/terms-reference-rapid-review-australian-government-arrangements-ai-driven-cyber-incident)

Department of the Prime Minister and Cabinet, Getting it right: Building AI infrastructure that works for Australia, consultation paper, September 2026 (submissions closed 9 October 2026), Part 3, security and safety — [pmc.gov.au](https://www.pmc.gov.au/resources/getting-it-right-building-ai-infrastructure-works-australia)

Joint Select Committee on Artificial Intelligence: terms of reference, submissions, hearings — [aph.gov.au](https://www.aph.gov.au/Parliamentary_Business/Committees/Joint/Artificial_Intelligence)

Answer to question on notice IQ26-000048 (Department of Employment and Workplace Relations; answer by Safe Work Australia), hearing 18 September 2026 — committee Additional Documents, aph.gov.au

Safe and responsible AI in Australia: proposals paper for introducing mandatory guardrails for AI in high-risk settings, Department of Industry, Science and Resources, September 2024 — guardrails 9 and 10; printed pages 15, 41 and 42

Royal Commission into the Robodebt Scheme, Report, 7 July 2023, recommendations 17.1 and 17.2 — [robodebt.royalcommission.gov.au](https://robodebt.royalcommission.gov.au/publications/report)

NSW Ombudsman, Revenue NSW – The lawfulness of its garnishee order process, tabled 30 April 2024 — [ombo.nsw.gov.au](https://www.ombo.nsw.gov.au/about-us/news-events/media-releases/revenue-nsw-the-lawfulness-of-its-garnishee-order-process-report-tabled-in-parliament)

Commonwealth Ombudsman, Automation in the Targeted Compliance Framework: when the law is changed but the system isn't, August 2025 — [ombudsman.gov.au](https://www.ombudsman.gov.au/__data/assets/pdf_file/0017/320750/Automation-in-the-Targeted-Compliance-Framework.pdf)

Office of the Victorian Information Commissioner, Investigation into the use of ChatGPT by a Child Protection worker, 24 September 2024 — [ovic.vic.gov.au](https://ovic.vic.gov.au/regulatory-action/investigation-into-the-use-of-chatgpt-by-a-child-protection-worker/) · quoted finding from the [media release on the report](https://ovic.vic.gov.au/mediarelease/ovic-finds-department-responsible-for-breaches-of-privacy-through-use-of-chatgpt/)

Joint Select Committee on Artificial Intelligence, public hearing programs, 6 to 9 October 2026, and Public Hearings list — programs for [6 Oct](https://www.aph.gov.au/DocumentStore.ashx?hearingid=32688&submissions=false), [7 Oct](https://www.aph.gov.au/DocumentStore.ashx?hearingid=32689&submissions=false), [8 Oct](https://www.aph.gov.au/DocumentStore.ashx?hearingid=32690&submissions=false), [9 Oct](https://www.aph.gov.au/DocumentStore.ashx?hearingid=32691&submissions=false) (aph.gov.au) · [hearings and transcripts](https://www.aph.gov.au/Parliamentary_Business/Committees/Joint/Artificial_Intelligence/ArtificialIntelligence/Public_Hearings)

Joint Select Committee on Artificial Intelligence, proof Committee Hansard, public hearing, Sydney, 6 October 2026 (uncorrected proof) — [parlinfo.aph.gov.au](https://parlinfo.aph.gov.au/parlInfo/search/display/display.w3p;query=Id%3A%22committees%2Fcommjnt%2F29977%2F0000%22)

Joint Select Committee on Artificial Intelligence, proof Committee Hansard, public hearing, Sydney, 7 October 2026 (uncorrected proof) — [parlinfo.aph.gov.au](https://parlinfo.aph.gov.au/parlInfo/search/display/display.w3p;query=Id%3A%22committees%2Fcommjnt%2F29978%2F0000%22)

Joint Select Committee on Artificial Intelligence, proof Committee Hansard, public hearing, East Melbourne, 8 October 2026 (uncorrected proof) — [parlinfo.aph.gov.au](https://parlinfo.aph.gov.au/parlInfo/search/display/display.w3p;query=Id%3A%22committees%2Fcommjnt%2F29979%2F0000%22)

Criminal Code Act 1995 (Cth), Schedule, section 478.1, Unauthorised access to, or modification of, restricted data — [legislation.gov.au](https://www.legislation.gov.au/C2004A04868/latest/text)

OpenAI, How we will do better for Australia, 28 September 2026, updated 4 October 2026 — [openai.com](https://openai.com/index/how-we-will-do-better-for-australia/)

How a declared order and a signed decision at each step work — [agenticrail.nz/sequence-verification/](https://agenticrail.nz/sequence-verification/) · [a real sealed sequence](https://agenticrail.nz/proof/)
