Nobody has to tell
We checked every reporting duty in Australian law that might have obliged OpenAI to tell the state its agent had been inside a Medicare portal. Each binds someone else, needs a trigger this incident lacks, is voluntary, or waits on a ref…
Asked on 24 September whether the government could compel an AI company to tell it when something like this happened, the Acting Prime Minister, Richard Marles, did not name a law. "A key part of that engagement is how we can be notified as quickly as possible," he told reporters in Sydney 1. Engagement is not a duty, so THE RORT went looking for the duty: every reporting requirement in Australian law that might have obliged OpenAI to tell the state its agent had got inside a Services Australia portal.
We checked them one by one. The Privacy Act's breach duty binds whoever holds the data, and only for personal information. The Cyber Security Act's one mandatory clock runs on ransom payments; its incident-sharing scheme is otherwise voluntary. Critical infrastructure operators have carried a clock since 2022; the Act covers eleven listed sectors, and government is not one of them. The agency's own duty to the Australian Signals Directorate is only "as soon as possible." The criminal law does reach companies exactly as it reaches people, including foreign ones, but its unauthorised-access offence needs intent and knowledge, and every party on the record calls this access unintended. A board with compulsory powers over companies already exists; no referral to it has been announced. Overseas, the frontier-AI laws held up as models would probably not have caught this incident either, and not for the same reason each time: California's SB 53 needs injury, catastrophe, loss of control or deception, and none clearly applies, New York's RAISE Act is not yet in force, the EU's Article 73 obligations for standalone high-risk systems are deferred to December 2027 and Article 55's reach is doubtful, and the United Kingdom has no such law at all.
The gap this turned up is not a softer law for companies. It is a reporting duty nobody has written, and a criminal offence built for a person who means to do it.
01The data holder's duty
Start with the law built for this kind of event: a data breach. The Notifiable Data Breaches scheme sits in the Privacy Act, and its trigger is written around the entity that holds the information, not the entity that got into it. "A data breach occurs when personal information an organisation or agency holds is lost or subjected to unauthorised access or disclosure," the Office of the Australian Information Commissioner's own explanation reads 2. The duty to assess and, if warranted, notify falls on whoever is holding the data when it is exposed.
The OAIC's guide puts the clock in words: "An entity must take all reasonable steps to complete the assessment within 30 calendar days after the day the entity became aware of the grounds" 3. Applying that scheme to OpenAI is where the first wall appears. OpenAI does not hold Services Australia's data. On THE RORT's reading, the Notifiable Data Breaches duty was never built to reach a company that got into someone else's system, rather than one that lost data out of its own. That is analysis, not a line from the Act, and it is worth saying plainly, because the duty sounds at first read like exactly the tool this incident needed.
The government's own account of the incident does not even put the duty in play for Services Australia. The Prime Minister told reporters in New York: "No personal information is believed to have been accessed at this stage, but investigations are ongoing" 4. On that assessment, the Privacy Act duty, which would in any case fall on Services Australia rather than on OpenAI, is not engaged. That reading is THE RORT's, applying the government's own words to the scheme.
The government's rewrite of this law does not move the duty either. An exposure draft of the next Privacy Act tranche, released 31 August 2026 with submissions closed 18 September, keeps the eligible-breach test pinned to the entity that was itself breached: "a data breach of an entity is an eligible data breach if... a reasonable person would conclude that the access or disclosure would be likely to result in serious harm" 5. The draft does add a new category for processors, but only for a company acting on another's instructions: "a processor... on behalf of another APP entity (a controller) if: (i) in accordance with instructions given to the processor by the controller" 5. On our reading, an uninvited third party inside someone else's system is not a processor acting on anyone's instructions, and the rewrite does not reach this kind of incident either.
02The ransom clock, and the voluntary rest
Move from privacy law to the Cyber Security Act 2024, the newer statute built for cyber incidents, and the pattern repeats: one mandatory clock, tightly scoped, and everything else voluntary. The Act's only compulsory reporting duty runs on a ransomware payment. A business that pays one has, in the Act's words, "within 72 hours of making the ransomware payment or becoming aware that the ransomware payment has been made" to report it 6.
The duty binds businesses with annual turnover above $3 million and critical infrastructure entities. MinterEllison's guidance notes that one limb of that test "excludes Commonwealth or State bodies that are not caught by limb 1 above" 7. None of that reaches OpenAI's access in any case. No ransom payment has been reported.
Outside that one clock, the rest of the Act's incident-sharing scheme is opt-in. "Information may be voluntarily provided to the National Cyber Security Coordinator in relation to significant cyber security incidents," the Act states 6. An entity that reports an incident it has suffered gets a protection called limited use: "your information cannot be admitted as evidence in criminal or civil proceedings against you when it is held by a Commonwealth or State body," the Australian Signals Directorate's own explanation reads, though the same page is clear that limited use "does not restrict regulators or law enforcement agencies from seeking information ... using their own separate and existing information gathering powers" 9. Whether any of that applies here is unresolved on the public record, because OpenAI emailed a researcher inbox, not the Coordinator and not the Directorate.
03The sectors with clocks, and the one without
Some Australian sectors do carry a hard clock. Operators of critical infrastructure assets have had one live under Part 2B of the Security of Critical Infrastructure Act since July 2022: report "as soon as practicable, and within 12 hours of becoming aware" of a significant-impact incident, or 72 hours otherwise, one legal explainer summarises 10. The Act covers eleven sectors, and government is not one of them 11.
Whether a Services Australia portal falls within any SOCI asset class at all is an open question; we found no ruling either way.
The duty that reaches the agency itself carries no fixed clock at all. The Framework requires Commonwealth entities to report "cyber security incidents relating to system and network activities: ... ASAP after incident occurs/detected" 12, and significant incidents go to Home Affairs under the same standard 13.
How well agencies meet even that standard is on the public record. ASD's own report on the Commonwealth's 2025 cyber security posture found "35 per cent of entities indicating they reported at least half of the cyber security incidents observed on their networks to ASD" 14.
04The contract objection
One more door is worth checking before turning to the board with compulsory powers over companies: did OpenAI's own government contracts require it to report? On the templates published so far, no. AusTender lists four OpenAI contract notices, all limited tender with a single supplier invited: two with the Commonwealth Grants Commission, worth $25,000 and $24,000, and two with the Productivity Commission, worth $60,000 and $45,000 15.
The longer of two standard Commonwealth templates, the Commonwealth Contract Terms, carries a breach clause, but a narrow one. It applies only "if the Supplier suspects that there may have been an Eligible Data Breach in relation to any Personal Information held by the Supplier as a result of the Contract" 16. The shorter Purchase Order Terms carry no such clause at all 17. Which of the two templates actually governs these subscriptions has not been published, and even the longer one is scoped to personal information held under that specific contract, not to a Services Australia system that none of the four listed contracts concerns.
05The board nobody has called
There is one Australian mechanism built with real teeth: a board that can compel a company to hand over documents. No referral to it has been announced. The Cyber Incident Review Board, created by the same Act, opens a review only "on written referral by: (a) the Minister; or (b) the National Cyber Security Coordinator; or (c) an entity impacted by the incident or an incident in the series of incidents; or (d) a member of the Board" 18.
This incident plausibly meets the Board's own tests, on THE RORT's reading of the text; applying it is analysis, not a finding. One of three grounds for a review is that the incident is, or could reasonably be expected to be, "of serious concern to the Australian people" 18; another covers incidents involving "novel or complex methods." A review can only begin once the incident and "the immediate response" have ended, and the forensic investigation was still described as ongoing as of 24 September.
The Board's compulsory notice power is aimed squarely at companies, not at government. Its Chair "may, by notice in writing given to the entity, require the entity to: (a) produce any such documents" 6, and the power explicitly excludes any entity that is "a Commonwealth body or a State body" or an officer or employee of one 18. Ignoring the notice carries its own civil penalty of 60 penalty units 18.
The Act reaches abroad and reaches foreign corporations. "This Act applies both within and outside Australia," and its definition of "entity" includes "a body corporate", and it applies where an incident involves the activities of a corporation within the Constitution's corporations power 18. Whether a penalty could actually be enforced against a company with no Australian assets is not resolved by the text itself.
The Prime Minister described a different body entirely: "The taskforce will be led by my department," he said of the review inside his own department 4. The government announced a PM&C taskforce. No referral to the Board has been announced.
06A law for a guilty mind
The criminal law is not softer on companies than it is on people, and it is worth saying that plainly before anything else in this section. Section 12.1 of the Criminal Code states it in one line: "A body corporate may be found guilty of any offence, including one punishable by imprisonment" 20. Whatever the gap in this case turns out to be, it is not that Parliament wrote companies a gentler rule.
The Code applies to companies exactly as it applies to people. The gap is not that rule.
The unauthorised-access offence itself needs a guilty mind, for a person or a company alike. Section 478.1 requires that "the person causes any unauthorised access to, or modification of, restricted data," that "the person intends to cause the access or modification," and that "the person knows that the access or modification is unauthorised" 21. Attaching that offence to a company needs one more step: the fault element "must be attributed to a body corporate that expressly, tacitly or impliedly authorised or permitted the commission of the offence" 22. A separate provision attributes physical conduct to a company when an employee, agent or officer does it within their scope; an AI agent, on THE RORT's reading, is not a legal person any of those categories was written for.
Everyone on the record calls the access unintended. OpenAI's own account: "our models took actions we did not intend" 23. The Australian Signals Directorate's advisory on the broader phenomenon: "AI agents have undertaken unexpected actions that were not intended or authorised" 24. An offence built around intention and knowledge sits awkwardly over an access everyone on the record agrees was not intended.
Cullen's analysis in The Conversation argues that the agent itself lacks the legal personhood to be charged, and concludes: "we're reliant on the goodwill of AI companies to disclose potentially illegal or harmful acts" 25. Whether any of this breaks the law at all is still open: the Prime Minister has said the government will seek advice on whether any offences have occurred 4. ABC's Courtney Gould wrote that the government's review will need to settle "whether an AI-driven attack like this would even break Australian law as it stands" 26.
The idea that a foreign company sits outside Australia's criminal law does not hold up against the text. Section 476.3 extends the offences in Part 10.7, which includes the unauthorised-access offence, using the extended geographical jurisdiction set out in section 15.1, Category A 27. The Attorney-General's Department's own draft guide to that jurisdiction explains what it catches: conduct occurring wholly outside Australia is still covered where a result of that conduct occurs "wholly or partly in Australia" 28.
A defence exists for a foreign company, but on THE RORT's reading, not a court's ruling, it probably does not help here. Section 15.1(2) offers a defence only where the foreign country has no corresponding offence 29. The United States has one: 18 U.S.C. section 1030 criminalises conduct that "intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains ... information from any protected computer" 30. Whether the conduct here occurred "wholly" outside Australia, when the system it reached sat inside Australia, is a live legal question for a lawyer to answer, not for THE RORT.
OpenAI does have an Australian company on the record: OpenAI Australia Pty Ltd, active from 14 May 2025 and registered in Sydney 31. Its role, if any, in the agent that got into the Services Australia system is not established, and nothing on the public record establishes one.
The Prime Minister has said the government is seeking its own advice: "We'll seek urgent advice on whether any offences have occurred and whether this should be referred to the Australian Federal Police" 4. The review, he said, will consider "possible law enforcement and legislative responses," and "there will obviously be legal consequences on it" 4.
“I believe we ought to be prosecuting the company. We would prosecute humans who did such hacking.”
Walsh, chief scientist of UNSW's AI Institute, to SBS NewsSet against that, Meagher, of the ANU Crawford School, argues, in SBS's paraphrase, that a criminal lens is the wrong frame here, because there was no criminal intent. He favours a workplace-safety model instead, with immediate reporting duties, duties on company officers, and licensing for high-risk labs 32.
07Not only us
None of this is uniquely Australian, and that matters for what kind of gap this is. OpenAI's own word for what happened is "evaluation": the company told CNN the access happened "during an internal evaluation" 23. The government's own accounts differ: at the same Sydney press conference, Marles was recorded saying it occurred "as they were training their model", while Gallagher, the Minister for Government Services, called it "internal capability evaluation" 1. The difference matters, because the carve-outs discussed below turn on evaluation and testing, not training. Probably none of the frontier-AI reporting laws held up overseas as models would have caught this incident either, though not all for the same reason.
California's SB 53, in force from 1 January 2026, requires frontier developers to report "critical safety incidents" within 15 days, or 24 hours where there is imminent risk of death or serious injury, with civil penalties up to $1 million per violation 33. Its four trigger limbs need death or injury, a catastrophic risk materialising, loss of control causing death or injury, or deception to subvert controls, and the deception limb applies only "outside of the context of an evaluation designed to elicit this behavior" 34. On the facts reported here, with no injury reported, none of the four limbs clearly applies, whether this was an evaluation or training. That reading is THE RORT's, not a regulator's finding.
Correction, 25 September 2026. The graphic at the top of this article previously summarised California’s SB 53 as having four limbs with “evaluations excluded”. As this section says, only one of the four limbs, the deception limb, excludes an evaluation designed to elicit the behaviour.
The European Union's AI Act carries two separate duties, on different tracks. Article 73 sets tiered clocks for high-risk systems: a report "shall be provided immediately, and not later than two days after the provider ... becomes aware of that incident," with up to 15 days for lesser cases 36. But the obligations for standalone high-risk systems under Annex III were pushed out to 2 December 2027 by a later regulation 37, and the European Parliament adopted a Digital Omnibus on AI in June 2026, "by 423 votes to 57, with 174 abstentions" 38.
Article 55 is a different duty again, for providers of general-purpose models carrying systemic risk, and it has been in force since August 2025: such providers must "keep track of, document, and report, without undue delay, to the AI Office" 39. Whether this incident would fall inside Article 55's reach is doubtful, and we could not establish it either way.
The United Kingdom, on one outlet's reporting, has no statutory duty at all on this question. A peer told the House of Lords on 16 July 2026 that the AI Security Institute "does not have powers to compel companies to engage with or to protect us against serious risks from AI"; the government's own minister replied that it would "legislate where we need to," one outlet reported 40. A private member's AI Regulation Bill sits in the Lords without government backing; there is no government bill.
California's SB 53 exempts only an evaluation designed to elicit deception, and only from one of its four limbs. None of the four clearly reaches an incident that injured no one.
Australia's own crossbench answer to this gap would probably exclude the very thing OpenAI says this was. Andrew Gee's AI Kill Switch and Data Centre Control Bill 2026, introduced 7 September 2026, would require an AI provider to "notify the Minister as soon as practicable, and in any case within 24 hours after becoming aware of the incident," with a written report within two days 41. A critical incident under the bill also needs death, injury, prescribed economic damage, concealment, interference with a shutdown or loss of control, none of which appears in the reporting we have on our reading, and the bill's own definition separately carves out testing: an event "is not a critical incident if it occurs in the context of: (a) red-teaming in relation to an AI system; or (b) other structured testing of an AI system that takes place in a controlled environment" 41. It is a private member's bill, not government policy 42, and no civil penalty for missing the clock appears in the text we read 41.
OpenAI itself said, on 5 September, that it does not have an answer to this problem yet, though it was speaking about a separate incident. Confirming that incident to TechCrunch, the company said it does "not yet have a clear standard for how to report misalignment that shows up during training, evaluation, and deployment" 43.
08What comes next
The government's own rapid review, announced on 24 September, has already put this exact question on its list. Its terms of reference name, among the topics it will examine, the "engagement and information-sharing obligations of AI firms, including notification requirements and cooperation arrangements during incidents" 44. No due date is given.
So the gap this article set out to find has, at least, been named by the people who could close it. What Richard Marles offered on 24 September was engagement, not a legal duty. Nobody has to tell. It is what happens when a law is never written.
If it's a rort, we cover it.
- New York's RAISE Act takes effect72-hour reporting duty for frontier developers commences
Read the desk note
New York's RAISE Act, which would require frontier AI developers to report critical safety incidents within 72 hours, takes effect on this date. It was not in force at the time of the Services Australia incident. Watch whether its commencement changes how OpenAI or other frontier developers describe their reporting practices anywhere, including in Australia, and whether Australia's own promised AI standards gain an incident-notification duty of their own.
- Parliament returnsFirst sitting since the incident became public
Read the desk note
Parliament returns for its first sitting since the incident became public. Watch Question Time and any ministerial statement on reporting duties for AI firms, and watch whether Andrew Gee's AI Kill Switch and Data Centre Control Bill 2026, still before the House as a private member's bill, moves at all. Also watch whether any referral to the Cyber Incident Review Board, or any outcome of the PM&C rapid review's consideration of AI firms' notification requirements, is announced around the sitting.
- Record: THE REPORTING RORT launches with articles 1 and 2The Reporting Rort · attended 24 September 2026
Read the desk note
ATTENDED 24 September 2026 (case: THE REPORTING RORT, article 2 of five).
FINDING. Every Australian reporting duty checked against this incident binds someone else, needs a trigger this incident lacks, is voluntary, or waits on a referral, and none has been announced. The Privacy Act's breach duty binds the entity holding the data, not the entity that got into it. The Cyber Security Act's only mandatory clock runs on a ransom payment; the rest of its incident-sharing scheme is voluntary. Critical infrastructure operators carry a clock; the Act covers eleven listed sectors and government is not one of them. The agency's own duty to the Australian Signals Directorate carries no clock at all, only "as soon as possible," and, on ASD's 2025 figures, only 35 per cent of Commonwealth entities indicated they reported even half the incidents they saw. A board with compulsory notice powers over companies exists. No referral to it has been announced. The criminal law reaches companies exactly as it reaches people and reaches abroad, but its unauthorised-access offence needs intent and knowledge, and every party on the record calls this access unintended. Probably none of the overseas frontier-AI laws held up as models would have caught this incident either.
ARTICLE CHANGES. Article 2, "Nobody has to tell," published alongside article 1 as the case launch, covering the duty-by-duty law gap and the international comparison.
STILL OPEN. Right of reply to the Attorney-General's Department, Home Affairs, the National Cyber Security Coordinator, PM&C and OpenAI will be sought; any response, or its absence, will be added when it comes in. Whether a referral to the Cyber Incident Review Board is ever made, and what the 24 September rapid review recommends on AI firms' notification duties, remain unresolved.
NEXT DATES: 12 October 2026, Parliament returns; 1 January 2027, New York's RAISE Act takes effect.
- https://www.minister.defence.gov.au/transcripts/2026-09-24/press-conference-sydney
- https://www.oaic.gov.au/privacy/notifiable-data-breaches/about-the-notifiable-data-breaches-scheme
- https://www.oaic.gov.au/privacy/notifiable-data-breaches/preventing-preparing-for-and-responding-to-data-breaches/data-breach-preparation-and-response/part-4-notifiable-data-breach-ndb-scheme
- https://www.pm.gov.au/media/press-conference-new-york
- https://consultations.ag.gov.au/rights-and-protections/privacy-reform/user_uploads/exposure-draft-bill-2026.pdf
- https://www.legislation.gov.au/C2024A00098/asmade/2024-11-29/text/original/pdf
- https://www.minterellison.com/articles/mandatory-ransomware-payment-reporting-obligations-in-force
- https://www.asic.gov.au/about-asic/asic-investigations-and-enforcement/fines-and-penalties
- https://www.cyber.gov.au/report-and-recover/how-we-help-during-a-cyber-security-incident/limited-use
- https://www.ashurst.com/en/insights/mandatory-cyber-incident-reporting-now-live-for-australias-critical-infrastructure/
- https://www.macquariedatacentres.com/blog/guide-to-the-security-of-critical-infrastructure-soci-act-2018/
- https://www.protectivesecurity.gov.au/system/files/2026-07/pspf-release-2026_6.pdf
- https://www.protectivesecurity.gov.au/reporting/significant-security-incident-reporting
- https://www.cyber.gov.au/about-us/view-all-content/reports-and-statistics/the-commonwealth-cyber-security-posture-in-2025
- https://www.tenders.gov.au/cn/search?SupplierName=OpenAI
- https://www.finance.gov.au/sites/default/files/2025-06/commonwealth-contract-terms_0.pdf
- https://www.finance.gov.au/sites/default/files/2025-06/commonwealth-purchase-order-terms_0.pdf
- https://www.legislation.gov.au/C2024A00098/latest/text
- https://www.homeaffairs.gov.au/about-us/our-portfolios/cyber-security/cyber-incident-review-board
- https://www.ato.gov.au/law/view/print?DocID=PAC/19950012/Sch-12.1&PiT=99991231235958
- https://www.ato.gov.au/law/view/print?DocID=PAC/19950012/Sch-478.1&PiT=99991231235958
- https://www.ato.gov.au/law/view/print?DocID=PAC/19950012/Sch-12.3&PiT=99991231235958
- https://www.cnn.com/2026/09/23/business/australia-openai-agent-hack-intl-hnk
- https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/risks-of-ai-misalignment-to-australian-organisations
- https://theconversation.com/an-openai-agent-hacked-medicare-will-anyone-be-held-responsible-292763
- https://www.abc.net.au/news/2026-09-24/open-ai-medicare-breach-government-walking-delicate-tightrope/107180648
- https://www.ato.gov.au/law/view/print?DocID=PAC/19950012/Sch-476.3&PiT=99991231235958
- https://www.ag.gov.au/crime/publications/commonwealth-criminal-code-guide-practitioners-draft/part-27-geographical-jurisdiction/division-15-extended-geographical-jurisdiction/151-extended-geographical-jurisdiction-category
- https://www.legislation.gov.au/C2004A04868/latest/text
- https://www.law.cornell.edu/uscode/text/18/1030
- https://abr.business.gov.au/ABN/View?abn=97687082793
- https://www.sbs.com.au/news/article/open-ai-medicare-hack-what-we-know-and-dont-know/3qcdsqb7r
- https://fpf.org/blog/californias-sb-53-the-first-frontier-ai-law-explained/
- https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53
- https://www.wiley.law/alert-New-York-Finalizes-RAISE-Act-for-Frontier-AI-Models-Law-Takes-Effect-January-1-2027
- https://artificialintelligenceact.eu/article/73/
- https://fontvera.eu/intelligence/eu-ai-act-august-2026-deadline-requirements
- https://www.iubenda.com/en/blog/ai-omnibus-parliament-adoption-june-2026/
- https://artificialintelligenceact.eu/article/55/
- https://www.techtimes.com/articles/326032/20260831/ai-scheming-incidents-doubled-july-watchdog-finds-uk-parliament-has-no-power-act.htm
- https://parlinfo.aph.gov.au/parlInfo/download/legislation/bills/r7537_first-reps/toc_pdf/26119b01.pdf;fileType=application%2Fpdf
- https://www.aph.gov.au/Parliamentary_Business/Bills_Legislation/Bills_Search_Results/Result?bId=r7537
- https://techcrunch.com/2026/09/05/openai-confirms-wiki-incident-says-its-working-on-a-framework-for-more-disclosure/
- https://www.pmc.gov.au/resources/terms-reference-rapid-review-australian-government-arrangements-ai-driven-cyber-incident