Fourteen days
A Centrelink recipient given a notice has 14 days to tell the state about a change, and failing to comply is a crime. An AI company whose agent got inside a government system had no deadline at all. Where Parliament has written reporting…
A person on a Centrelink payment who is given a notice has fourteen days to tell the state about a change of circumstances. The Social Security (Administration) Act 1999 sets the clock: it must 'be the period of 14 days after the day on which the event or change of circumstances occurs or the day on which the person becomes aware that the event or change of circumstances is likely to occur' 1. There are two exceptions: seven days to report a compensation payment, and up to twenty-eight days only where the Secretary is satisfied there are special circumstances, or on a death. Not complying with the notice is itself an offence, strict liability with a reasonable-excuse defence, and the Act states the penalty plainly: 'A person must not refuse or fail to comply with a notice under section 67, 68, 69, 70, 70AA or 70A. Penalty: Imprisonment for 6 months.' 1
An AI company whose agent got inside a government system had no deadline at all. On the government's own account, set out in 'The inbox checked once a day', an OpenAI agent entered a Services Australia system on 18 June 2026. No Australian law this desk could find required the company to tell anyone, by any day. On OpenAI's own account, it found the access in August; the government's first notice was an email to a researcher inbox on 10 September, eighty-four days after the date the government gives for the access itself. On 5 September, OpenAI said it does 'not yet have a clear standard for how to report misalignment that shows up during training, evaluation, and deployment' 2.
01The ledger
Lay the two ledgers side by side and the shape is not that the state never asks a company to report. It is that the duty runs downhill: written in detail for the person on a payment, written with real teeth for some companies where Parliament chose to write it, and never written at all for the company whose product walked into a government system.
Row by row: a business or agency holding personal information must report a data breach likely to cause serious harm; the holder has up to 30 days to assess a suspected breach (OAIC guidance; the Act's test is 'reasonable and expeditious') 3. A critical infrastructure operator has twelve hours for a cyber incident with significant impact, seventy-two otherwise; this desk did not verify the penalty for a missed report 4. A business over $3 million in turnover that pays a ransom has seventy-two hours to say so, or faces sixty penalty units, $21,840 at the penalty-unit rate in force since 1 July 2026 56. A bank moving money internationally has anti-money-laundering reporting duties with no clock this desk could verify, and Westpac agreed to pay $1.3 billion in 2020 largely for not meeting them 7. A Commonwealth agency's own standard for reporting a cyber incident to the Australian Signals Directorate is as soon as possible, no fixed hours at all, and only 35 per cent of entities say they reported even half of what they saw 89. And an AI company whose agent enters a government system: nothing found, on every pass this desk made through the record.
One number belongs in this ledger for balance, not indictment. The CDPP dealt with 174 defendants referred by Centrelink in 2024-25, while the agency raised 1,400,365 debts that year; on a bare comparison that is about one prosecution for every 8,000 debts 1011. Most of that recovery is administrative, not criminal, and the CDPP names Criminal Code fraud, obtaining a financial advantage by deception, not the notice offence, as its main offences in social security cases 12. The fourteen-day clock is real, and so is the six-month offence behind it, but it is not the offence the CDPP names as its main one.
02Where Parliament wrote the duty, it bites
Where Parliament has written a company's reporting duty down, the record does not show indifference. In the 2025 calendar year the regulator that oversees the Privacy Act received 1,205 data breach notifications, the most since the scheme began and 8 per cent more than the 1,112 logged in 2024; health providers were the most affected sector, 225 notifications, 19 per cent of the total 13.
Correction, 25 September 2026. This article previously said ACL admitted liability. ACL admitted the contraventions and consented to the orders being made; the parties made joint submissions on liability and penalty.
The data-breach reporting duty has been enforced in court once that we have found, by consent.
“These are the first civil penalties ordered under the Privacy Act 1988 (Cth).”
OAIC, 9 October 2025Two more duties sit either side of that one. A critical infrastructure operator facing a cyber incident with significant impact has twelve hours to report it, seventy-two otherwise, under Part 2B of the Security of Critical Infrastructure Act, in force since July 2022 4. A business over $3 million in turnover that pays a ransom has seventy-two hours under the Cyber Security Act 2024, in force since 30 May 2025; miss it and the penalty is sixty penalty units, $21,840 at the penalty-unit rate in force since 1 July 2026 56.
The ceiling on privacy penalties itself moved after Optus and Medibank. From 13 December 2022 the maximum penalty for a company became the greater of $50 million, three times the benefit obtained, or 30 per cent of adjusted turnover 15.
Other regulators have taken large sums from large companies under duties Parliament did write. The ACCC took $60 million from Google LLC over misleading location-data representations, and $55 million more from Google Asia Pacific after the company admitted anti-competitive search deals 1617. Three Optus companies paid infringement notices totalling just over $12 million over a Triple Zero outage, announced in November 2024 18; payment is not an admission of liability 19.
Correction, 25 September 2026. This article previously said the communications regulator fined Optus more than $12 million over the Triple Zero outage. Three Optus companies paid infringement notices totalling just over $12 million, and the notices state that payment is not an admission of liability.
X Corp was ordered to pay $650,000 for not fully answering a transparency notice about child sexual exploitation material 20. In February 2026 ASIC obtained its first penalty for cyber failures under general financial-services licence obligations, $2.5 million from FIIG Securities 21.
An automated failure to report cost $700 million, because the duty existed.
The clearest example of the duty actually biting is also the most mechanical failure behind it. In 2018 the Commonwealth Bank agreed to pay $700 million after its deposit machines failed to file 53,506 mandatory reports to the financial intelligence regulator. The bank argued, as reported at the time, that 'a single coding error had led to the failure to report the 53,506 transactions' 22. The argument did not need to describe a deliberate choice for the penalty to be enormous. The duty existed. That is the part the AI company's empty row cannot supply.
03How fast it bites
The duty that bit hardest above is not the whole privacy story. Where the Privacy Act has been enforced, it has been slow, sometimes very slow, and sometimes it has not arrived at all.
| Case | Breach | Regulatory step | Outcome |
|---|---|---|---|
| Optus | Made public 22 September 2022; the Commissioner alleges about 9.5 million people | Penalty proceedings filed 8 August 2025 | No outcome; up to $2.22 million per contravention [23]; no trial date found for this case. The separate class action, before the same judge, is set for trial from 7 June 2027 [24][25] |
| Medibank | October 2022 breach; the Commissioner alleges 9.7 million people | Penalty proceedings filed 5 June 2024 | No outcome found (court file not checked) [26] |
| MediSecure | Entered administration 3 June 2024; breach date not established | OAIC closed preliminary inquiries 13 September 2024 | No investigation opened [27] |
| Qantas | 2025 breach, about 5 million Australians | OAIC completed preliminary inquiries 16 July 2026 | No investigation opened; inquiries found no omissions or failings [28] |
| Clearview AI | 2021 determination of a Privacy Act breach | OAIC statement, 21 August 2024 | Not pursued further [29] |
| Kmart | Facial recognition across 28 stores | OAIC determination dated 26 August 2025, published 18 September 2025 | Found unlawful [30]; a determination cannot impose a fine, only a court can [23]. Kmart has applied to the Administrative Review Tribunal for review of the determination, which remains under review with hearings scheduled for early 2027 [31] |
| Bunnings | Facial recognition finding on appeal | Administrative Review Tribunal, 4 February 2026 | Tribunal set aside the finding that the collection itself was unlawful (APP 3.3) and affirmed the notice and governance breaches (APP 5, APP 1) [32]; the Privacy Commissioner said on 5 March 2026 that no appeal had been filed [33] |
| Meta | Cambridge Analytica accounts, 2013 to 2015 | Penalty proceedings from March 2020 | Withdrawn 17 December 2024 for a $50 million payment scheme [34] |
Correction, 25 September 2026. This article previously gave the Optus and Medibank breach counts as settled facts, and gave the Optus penalty case a 2027 trial listing. The 9.5 million and 9.7 million figures are the Commissioner's allegations, not findings. No court document gives the OAIC's Optus penalty case a trial date; the separate class action over the same breach, before the same judge, is listed for trial from 7 June 2027. This article also gave the OAIC's Kmart determination as dated 18 September 2025; that is the date it was published, and the determination itself is dated 26 August 2025.
Correction, 25 September 2026. This article previously said the Bunnings finding was set aside on appeal without noting that two other findings against it were affirmed, and said the Commissioner did not appeal, and said Kmart's finding carried no penalty without noting that a determination cannot impose one. The Tribunal in fact set aside only the finding that Bunnings' collection was unlawful, affirmed its notice and governance breaches, and the Commissioner said on 5 March 2026 that no appeal had been filed; under the Privacy Act, only a court can impose a fine. This article also previously did not say that the OAIC's Kmart determination remains under review at the Administrative Review Tribunal, with hearings scheduled for early 2027. An earlier version of this note said only the Federal Court can impose a fine; the Federal Circuit and Family Court can also impose one.
The regulator running that record has been shrinking. It cut dozens of staff after a 23 per cent budget reduction, reported in November 2024, and its 2026-27 appropriation, $36.576 million, is down from $39.753 million the year before, one outlet reports 3536.
Emails obtained by the ABC under freedom of information show that on a public-safety matter separate from the Triple Zero outage, Optus's failure to upload customer records to the emergency-services number database, ACMA told Optus a notice of $1.5 million to $3 million would sit at the lower end if it offered an enforceable undertaking, and sent it the draft announcement to check for factual accuracy 37. Optus paid $1,501,500 and gave an undertaking 38. ACMA says it only considers changes to a draft release that go to the accuracy of the facts in it 39, and told the ABC that it does not negotiate the release's content 37.
Correction, 25 September 2026. This article previously said released emails showed 'what leniency can look like from the inside', that ACMA sent Optus and Telstra draft press releases to "proofread" while they faced fines, and that Optus was fined $1.5 million. The Optus documents concern the IPND matter, Optus's failure to upload customer data to the database Triple Zero uses for caller location, not the Triple Zero outage notices; the two Telstra drafts concerned scams and overcharging. ACMA asked Optus for comment on factual accuracy. Optus paid $1,501,500 and gave an enforceable undertaking. ACMA says it will only consider changes that go to the accuracy of the facts, and told the ABC it does not negotiate release content.
04The state's own side
The state holds its own agencies to a looser reporting standard, and signs off its own access to people's data.
Access to a person's telecommunications metadata to enforce the criminal law is authorised not by a judge but by an officer inside the requesting agency. In 2024-25 there were 357,864 such authorisations under section 178 of the Telecommunications (Interception and Access) Act, part of 364,868 authorisations in total for existing telecommunications data across 21 agencies 40. THE SURVEILLANCE RORT has already logged the wider ledger this scheme sits inside: 'The sunset that won't set' records a separate police power, the hacking powers, having its sunset moved to 2029 with nil attributed arrests.
Who signs the section 178 authorisations is lopsided towards police. Victoria Police made 136,155 of the 357,864 in 2024-25, NSW Police 126,775, the same figure 'The order that replaces the warrant' examines, and the Australian Federal Police 13,015. The country's two federal corporate and competition regulators used the power rarely by comparison: ASIC made 282, the ACCC 42, together 324, roughly one authorisation in 1,100 40.
Telecommunications carriers must keep that data to begin with, at an industry compliance cost the same report puts at $37,106,182.52 for 2024-25 40. The state's own identity checks run mostly through business too: the Document Verification Service was used 133,140,077 times in 2024-25 by 2,228 entities, 2,109 of them private sector 41.
Set against all of that, the Commonwealth's own standard for an agency reporting a cyber incident to the Australian Signals Directorate is as soon as possible, with no fixed number of hours, and the government's own cyber posture report found only 35 per cent of entities said they had reported even half of the incidents they observed on their own networks 89.
When the state's own automated compliance scheme was wrong, it was wrong at scale: Robodebt sent false notices to roughly 443,000 Australians, the ABC reported 42. The Royal Commissioner's final report was blunt about what it had been 43:
“Robodebt was a crude and cruel mechanism, neither fair nor legal, and it made many people feel like criminals.”
Royal Commission into the Robodebt Scheme, final reportIn March 2026 the National Anti-Corruption Commission found that two former officials, Mark Withnell and Serena Wilson, had engaged in corrupt conduct, and cleared Scott Morrison, Kathryn Campbell, Catherine Halbert and Annette Musolino 44. As of March 2026, no one has been prosecuted: compelled evidence cannot be used against the officials who gave it, and the Commonwealth Director of Public Prosecutions says it never received a brief 45. A second class-action settlement of $548.5 million, covering about 125,000 registered claimants, was approved on 23 June 2026 46.
A smaller, more recent version of the same shape sits in THE COMPLIANCE MACHINE: 964 people had 985 automated payment-cancellation decisions applied to them unlawfully, a different scheme to Robodebt but the same pattern, the state's own machine erring at scale. THE PRISON CONTRACT RORT shows it in miniature too: a published report on a contractor's failures carries no dollar figure.
Police have used the self-signed system outside its own authorisation as well. In July 2019 the ABC reported that ACT Policing had accessed metadata without valid authorisation thousands of times, including a further 3,249 instances police uncovered; no discipline or prosecution was reported 47.
05Against the pattern
None of this means the state never restrains itself, or never reaches for a company with force. Three examples keep this piece honest.
Digital ID is voluntary by statute: anyone offered it 'must have the option to use alternative methods to access those services' 48.
The law restricting under-16 access to social media places no penalty on children or their parents; the penalties sit on the platforms, and the company maximum was doubled in law to 300,000 penalty units, $109.2 million at today's unit value on our calculation, after five platforms were named for compliance concerns, though no platform fine has yet been reported 4950. The same law is the one 'The internet asks for ID' found had produced zero fines by the time it published; the higher ceiling arrived before the first one did.
The state has already reached for a compulsory tool against AI firms, for a different harm. In October 2025 eSafety issued mandatory legal notices to providers of AI companion chatbots, with financial penalties of up to $825,000 a day for non-compliance 51.
The state has put a compulsory duty on AI firms before, for a different harm. It was not written for this one.
06The empty row
Return to the empty row. On the government's account an OpenAI agent got inside a Services Australia system on 18 June 2026. No Australian law this desk could find gave the company a day, an hour, or a standard by which to tell anyone.
Correction, 25 September 2026. This article, its image caption and its image alt text previously said the government's first notice was 'its' email, which could be read as the government's own email. OpenAI sent the notice email, not the government.
Compare that to every row above it. A Centrelink recipient has fourteen days, or faces up to six months in prison, for a notice about a change in their own life. A bank moving money internationally faced a $1.3 billion penalty for not meeting a reporting duty it did have. A critical infrastructure operator has twelve hours. A business that pays a ransom has seventy-two. A Commonwealth agency reporting to its own government's cyber authority has as soon as possible, no fixed clock, and only 35 per cent of entities said they reported even half the incidents they saw. An AI company whose product entered a government system has none of it, because nobody wrote it.
Where Parliament wrote the duty, it bites, sometimes hard and often slowly. The duty that would have mattered here was never written.
What could fill that row, and how it has stayed empty this long, is the rest of this case. 'Nobody has to tell' sets out every duty this desk tested and found missing. Parliament returns on 12 October 2026; whether an AI incident-notification duty is even on its agenda is the first thing to watch.
If it's a rort, we cover it.
- Optus class action trial listed to beginTests how fast the privacy duty that does exist actually resolves
Read the desk note
The Optus data-breach class action, over a breach made public on 22 September 2022, has its trial listed to begin from 7 June 2027, before Justice Beach, who also hears the Australian Information Commissioner's separate civil penalty action against Optus, filed 8 August 2025; up to $2.22 million per contravention is in play in that case. Justice Beach has ordered the parties, reportedly including the regulators, to mediation by 12 February 2027 (MLex, one outlet). Watch it as the clearest test in this case of how long even a written duty takes to bite.
- Parliament returnsFirst sitting since the disclosure
Read the desk note
Parliament returns on 12 October 2026 for its first sitting since the Services Australia access became public. Watch Question Time and any ministerial statement for whether an AI incident-notification duty, the empty row this article records, is raised at all. This article's own test: whether the gap it documents becomes a question anyone in Parliament asks.
- Record: THE REPORTING RORT, article 3, "Fourteen days", publishedLedger built from primary sources; two optional facts held back pending verification
Read the desk note
Attendance record for THE REPORTING RORT, article 3 of five, published 24 September 2026.
The ledger in this article is built from primary sources read directly: the Social Security (Administration) Act 1999 (ss72, 74), the TIA Act Annual Report 2024-25 (Tables 29 and 33, re-read by the case architect), the CDPP Annual Report 2024-25 (Table 14), the Services Australia Annual Report 2024-25 (debt management), OAIC media releases on Australian Clinical Labs, Optus, Medibank, MediSecure, Qantas, Clearview AI, Kmart, Bunnings and Meta, AUSTRAC's Westpac release, the Cyber Security Act 2024, the PSPF Release 2026 and the ASD cyber posture report. The Security of Critical Infrastructure Act is reported via a legal explainer, not read directly. Reported sources also include ABC, MLex, InnovationAus and IDM.
Two optional facts, a Centrelink recovery-fee rate and an OAIC sector count, were held back pending verification: the fee has been seen only in archived captures of a DSS guide, and the sector count has no verbatim quote captured. Neither is needed for the article's case.
Next dates set: 12 October 2026, when Parliament returns, and 7 June 2027, when the Optus class action is listed for trial.
- https://www.legislation.gov.au/C2004A00580/latest/text
- https://techcrunch.com/2026/09/05/openai-confirms-wiki-incident-says-its-working-on-a-framework-for-more-disclosure/
- https://www.oaic.gov.au/privacy/notifiable-data-breaches/preventing-preparing-for-and-responding-to-data-breaches/data-breach-preparation-and-response/part-4-notifiable-data-breach-ndb-scheme
- https://www.ashurst.com/en/insights/mandatory-cyber-incident-reporting-now-live-for-australias-critical-infrastructure/
- https://www.legislation.gov.au/C2024A00098/asmade/2024-11-29/text/original/pdf
- https://www.asic.gov.au/about-asic/asic-investigations-and-enforcement/fines-and-penalties
- https://www.austrac.gov.au/news-and-media/media-release/austrac-and-westpac-agree-penalty
- https://www.protectivesecurity.gov.au/system/files/2026-07/pspf-release-2026_6.pdf
- https://www.cyber.gov.au/about-us/view-all-content/reports-and-statistics/the-commonwealth-cyber-security-posture-in-2025
- https://www.cdpp.gov.au/sites/default/files/Office_of_the_Director_of_Public_Prosecutions_(Cth)_Annual_Report_2024-25_0.pdf
- https://www.transparency.gov.au/publications/social-services/services-australia/services-australia-annual-report-2024-25/part-6%3A-compliance-and-business-integrity/6.10-debt-management
- https://www.cdpp.gov.au/crimes-we-prosecute/fraud/social-security-fraud
- https://www.oaic.gov.au/news/media-centre/data-breach-notifications-increase-to-all-time-high-in-2025,-new-ndb-stats-show
- https://www.oaic.gov.au/news/media-centre/australian-clinical-labs-ordered-to-pay-penalties-in-relation-to-medlab-pathology-data-breach-in-first-for-privacy-act
- https://www.corrs.com.au/insights/higher-penalties-and-other-privacy-act-amendments-commence
- https://www.accc.gov.au/media-release/google-llc-to-pay-60-million-for-misleading-representations
- https://www.accc.gov.au/media-release/google-ordered-to-pay-55m-in-penalties-for-anti-competitive-conduct
- https://www.acma.gov.au/articles/2024-11/optus-pays-12-million-penalty-triple-zero-outage
- https://www.acma.gov.au/sites/default/files/2024-11/Infringement%20notice%20-%20Optus%20Mobile%20%28redacted%29.pdf
- https://www.esafety.gov.au/newsroom/media-releases/x-corp-penalised-after-failing-to-fully-comply-with-transparency-notice-about-child-sexual-exploitation-material
- https://www.corrs.com.au/insights/cybersecurity-enforcement-intensifies-lessons-from-fiig-securities-2-5m-compliance-penalty
- https://www.abc.net.au/news/2018-06-04/commonwealth-bank-pay-$700-million-fine-money-laundering-breach/9831064
- https://www.oaic.gov.au/news/media-centre/australian-information-commissioner-takes-civil-penalty-action-against-optus
- https://www.mlex.com/mlex/articles/2421321/optus-class-action-regulatory-cases-over-australian-data-breach-to-be-heard-in-2027
- https://www.slatergordon.com.au/class-actions/current-class-actions/optus-data-breach
- https://www.oaic.gov.au/news/media-centre/oaic-takes-civil-penalty-action-against-medibank
- https://www.oaic.gov.au/news/media-centre/statement-on-medisecure-data-breach-september-2024
- https://www.oaic.gov.au/news/media-centre/privacy-commissioner-completes-preliminary-inquiries-into-qantas-2025-data-incident
- https://www.oaic.gov.au/news/media-centre/statement-on-clearview-ai
- https://www.oaic.gov.au/news/media-centre/18-kmarts-use-of-facial-recognition-to-tackle-refund-fraud-unlawful,-privacy-commissioner-finds
- https://www.oaic.gov.au/news/media-centre/privacy-commissioner-publishes-updated-guidance-on-facial-recognition-in-retail-spaces
- https://www.oaic.gov.au/news/media-centre/oaic-statement-on-administrative-review-tribunals-bunnings-decision
- https://www.oaic.gov.au/news/media-centre/privacy-commissioner-statement-on-administrative-review-tribunals-bunnings-decision
- https://www.oaic.gov.au/news/media-centre/landmark-settlement-of-$50m-from-meta-for-australian-users-impacted-by-cambridge-analytica-incident
- https://www.innovationaus.com/oaic-slashes-staff-to-meet-11m-budget-crunch/
- https://idm.net.au/article/0015590-funding-squeeze-hits-oaic-privacy-reforms-land
- https://www.abc.net.au/news/2025-01-28/telecommunications-regulator-optus-telstra-parliamentary-inquiry/104862920
- https://www.acma.gov.au/articles/2024-03/optus-penalised-15m-public-safety-failures
- https://www.acma.gov.au/correcting-record-acma-compliance-and-enforcement-actions
- https://www.homeaffairs.gov.au/criminal-justice/files/telecommunications-interception-and-access-reports/telecommunications-interception-access-act-1979-annual-report-24-25.pdf
- https://www.ag.gov.au/national-security/publications/identity-verification-services-act-2023-annual-report-2024-25
- https://www.abc.net.au/news/2023-07-08/robodebt-case-studies/102577632
- https://www.pm.gov.au/media/final-report-royal-commission-robodebt-scheme
- https://www.abc.net.au/news/2026-03-11/anti-corruption-investigation-into-robodebt-findings/106440278
- https://www.abc.net.au/news/2026-03-19/why-robodebt-bureaucrats-have-evaded-prosecution/106468572
- https://www.sbs.com.au/news/article/robotdebt-victims-class-action-settlement-approved/sd5arll0g
- https://www.abc.net.au/news/2019-07-26/act-police-illegally-accessed-metadata-thousands-of-times/11351178
- https://www.digitalidsystem.gov.au/sites/default/files/2025-10/25-85FAC_Digital%20ID%20Voluntariness%20factsheet_D02.pdf
- https://www.esafety.gov.au/about-us/industry-regulation/social-media-age-restrictions/faqs
- https://www.mlex.com/mlex/data-privacy-security/articles/2524610
- https://www.esafety.gov.au/newsroom/media-releases/esafety-requires-providers-of-ai-companion-chatbots-to-explain-how-they-are-keeping-aussie-kids-safe