The reporting runs one way. A Centrelink recipient given a notice has 14 days to report a change, and failing to comply is an offence; agency officers, not judges, signed 357,864 criminal-law authorisations for telecommunications data in 2024-25. When an OpenAI agent got inside a Services Australia portal on 18 June 2026, by the government's account, no Australian law we could find required the company to tell anyone, and it emailed a researcher inbox 84 days later. The state holds its own agencies to 'as soon as possible'. Where Parliament has written corporate reporting duties, they have been enforced, if slowly; for frontier AI firms it has never written one. A review announced on 24 September will make recommendations, with no due date.
The Optus data-breach class action, over a breach made public on 22 September 2022, has its trial listed to begin from 7 June 2027, before Justice Beach, who also hears the Australian Information Commissioner's separate civil penalty action against Optus, filed 8 August 2025; up to $2.22 million per contravention is in play in that case. Justice Beach has ordered the parties, reportedly including the regulators, to mediation by 12 February 2027 (MLex, one outlet). Watch it as the clearest test in this case of how long even a written duty takes to bite.
New York's RAISE Act, which would require frontier AI developers to report critical safety incidents within 72 hours, takes effect on this date. It was not in force at the time of the Services Australia incident. Watch whether its commencement changes how OpenAI or other frontier developers describe their reporting practices anywhere, including in Australia, and whether Australia's own promised AI standards gain an incident-notification duty of their own.
The Prime Minister said the incident would be referred to the Joint Select Committee on Artificial Intelligence, established by Parliament on 20 August 2026. The committee is due to report on 30 November 2026. Watch for whether its report addresses AI firms’ notification duties, one of the topics of the PM&C rapid review, whose published terms of reference carry no due date.
Parliament returns on 12 October 2026 for its first sitting since the Services Australia access became public. Watch Question Time and any ministerial statement for whether an AI incident-notification duty, the empty row this article records, is raised at all. This article's own test: whether the gap it documents becomes a question anyone in Parliament asks.
Parliament returns for its first sitting since the incident became public. Watch Question Time and any ministerial statement on reporting duties for AI firms, and watch whether Andrew Gee's AI Kill Switch and Data Centre Control Bill 2026, still before the House as a private member's bill, moves at all. Also watch whether any referral to the Cyber Incident Review Board, or any outcome of the PM&C rapid review's consideration of AI firms' notification requirements, is announced around the sitting.
Parliament returns on 12 October 2026 for its first sitting since the 24 September disclosure. Hansard for 14 to 17 September, the sitting days that overlapped with Services Australia’s handling of OpenAI’s email, carries no reference to the incident. Watch this sitting for Question Time on the breach, any ministerial statement, and whether the government’s taskforce or the Joint Select Committee on Artificial Intelligence reports back to the chamber.
This article previously said ACL admitted liability. ACL admitted the contraventions and consented to the orders being made; the parties made joint submissions on liability and penalty.
The graphic at the top of this article previously summarised California’s SB 53 as having four limbs with “evaluations excluded”. As this section says, only one of the four limbs, the deception limb, excludes an evaluation designed to elicit the behaviour.
ATTENDED 24 September 2026 (case: THE REPORTING RORT, article 2 of five).
FINDING. Every Australian reporting duty checked against this incident binds someone else, needs a trigger this incident lacks, is voluntary, or waits on a referral, and none has been announced. The Privacy Act's breach duty binds the entity holding the data, not the entity that got into it. The Cyber Security Act's only mandatory clock runs on a ransom payment; the rest of its incident-sharing scheme is voluntary. Critical infrastructure operators carry a clock; the Act covers eleven listed sectors and government is not one of them. The agency's own duty to the Australian Signals Directorate carries no clock at all, only "as soon as possible," and, on ASD's 2025 figures, only 35 per cent of Commonwealth entities indicated they reported even half the incidents they saw. A board with compulsory notice powers over companies exists. No referral to it has been announced. The criminal law reaches companies exactly as it reaches people and reaches abroad, but its unauthorised-access offence needs intent and knowledge, and every party on the record calls this access unintended. Probably none of the overseas frontier-AI laws held up as models would have caught this incident either.
ARTICLE CHANGES. Article 2, "Nobody has to tell," published alongside article 1 as the case launch, covering the duty-by-duty law gap and the international comparison.
STILL OPEN. Right of reply to the Attorney-General's Department, Home Affairs, the National Cyber Security Coordinator, PM&C and OpenAI will be sought; any response, or its absence, will be added when it comes in. Whether a referral to the Cyber Incident Review Board is ever made, and what the 24 September rapid review recommends on AI firms' notification duties, remain unresolved.
NEXT DATES: 12 October 2026, Parliament returns; 1 January 2027, New York's RAISE Act takes effect.
ATTENDED 24 September 2026 (case: THE REPORTING RORT, article 1 of five).
FINDING. The government’s own account, given at press conferences in New York and Sydney on 24 September 2026, puts eighty-four days between an OpenAI agent’s access to a Services Australia portal (18 June 2026, the government’s date) and the company’s first notice to the state (10 September 2026, by email to a researcher inbox the minister says is checked once a day). This article lays those dates, and the fourteen days that followed to public disclosure, side by side against the government’s own record.
ARTICLE CHANGES. Article 1, “The inbox checked once a day”, published, covering the incident chronology and who knew on which day. Four more articles are planned in this case.
STILL OPEN. This article carries no responses from Services Australia, PM&C or OpenAI.
NEXT DATE: 12 October 2026, when Parliament returns for the first time since the disclosure.
Attendance record for THE REPORTING RORT, article 3 of five, published 24 September 2026.
The ledger in this article is built from primary sources read directly: the Social Security (Administration) Act 1999 (ss72, 74), the TIA Act Annual Report 2024-25 (Tables 29 and 33, re-read by the case architect), the CDPP Annual Report 2024-25 (Table 14), the Services Australia Annual Report 2024-25 (debt management), OAIC media releases on Australian Clinical Labs, Optus, Medibank, MediSecure, Qantas, Clearview AI, Kmart, Bunnings and Meta, AUSTRAC's Westpac release, the Cyber Security Act 2024, the PSPF Release 2026 and the ASD cyber posture report. The Security of Critical Infrastructure Act is reported via a legal explainer, not read directly. Reported sources also include ABC, MLex, InnovationAus and IDM.
Two optional facts, a Centrelink recovery-fee rate and an OAIC sector count, were held back pending verification: the fee has been seen only in archived captures of a DSS guide, and the sector count has no verbatim quote captured. Neither is needed for the article's case.
Next dates set: 12 October 2026, when Parliament returns, and 7 June 2027, when the Optus class action is listed for trial.