Wollongong · Sydney · Australia
Australia's Watchdog
Independent
No ads. No masters.
THE RORT · CASE FILE · THE REPORTING RORTCASE OPEN · TRACKING
CASE FILE · CORPORATEARTICLES · 3

The Reporting Rort

STATUS · Ongoing · unresolved6 duties, 1 empty rowThe ledger this article builds runs from a Centrelink recipient's fourteen days to an AI company's nothing. Every…

The reporting runs one way. A Centrelink recipient given a notice has 14 days to report a change, and failing to comply is an offence; agency officers, not judges, signed 357,864 criminal-law authorisations for telecommunications data in 2024-25. When an OpenAI agent got inside a Services Australia portal on 18 June 2026, by the government's account, no Australian law we could find required the company to tell anyone, and it emailed a researcher inbox 84 days later. The state holds its own agencies to 'as soon as possible'. Where Parliament has written corporate reporting duties, they have been enforced, if slowly; for frontier AI firms it has never written one. A review announced on 24 September will make recommendations, with no due date.

Fig. 02 / The chain, in order

Fig. 02Source: case chain · every investigation in this case, in sequenceAs of 2026‑07‑06Auto-assembled

Fig. 03 / Who's named in this case

Fig. 03Source: entity scan · names appearing across this caseAs of 2026‑07‑06Auto-assembled

From the desk

  • 7 June 2027Watch
    Optus class action trial listed to begin
    Fourteen days · The Reporting Rort
    Tests how fast the privacy duty that does exist actually resolves
    Read the desk note

    The Optus data-breach class action, over a breach made public on 22 September 2022, has its trial listed to begin from 7 June 2027, before Justice Beach, who also hears the Australian Information Commissioner's separate civil penalty action against Optus, filed 8 August 2025; up to $2.22 million per contravention is in play in that case. Justice Beach has ordered the parties, reportedly including the regulators, to mediation by 12 February 2027 (MLex, one outlet). Watch it as the clearest test in this case of how long even a written duty takes to bite.

  • 1 January 2027Watch
    New York's RAISE Act takes effect
    Nobody has to tell · The Reporting Rort
    72-hour reporting duty for frontier developers commences
    Read the desk note

    New York's RAISE Act, which would require frontier AI developers to report critical safety incidents within 72 hours, takes effect on this date. It was not in force at the time of the Services Australia incident. Watch whether its commencement changes how OpenAI or other frontier developers describe their reporting practices anywhere, including in Australia, and whether Australia's own promised AI standards gain an incident-notification duty of their own.

  • 30 November 2026Watch
    Joint Select Committee on Artificial Intelligence reports
    The inbox checked once a day · The Reporting Rort
    The Prime Minister said the incident will be referred to this committee
    Read the desk note

    The Prime Minister said the incident would be referred to the Joint Select Committee on Artificial Intelligence, established by Parliament on 20 August 2026. The committee is due to report on 30 November 2026. Watch for whether its report addresses AI firms’ notification duties, one of the topics of the PM&C rapid review, whose published terms of reference carry no due date.

  • 12 October 2026Watch
    Parliament returns
    Fourteen days · The Reporting Rort
    First sitting since the disclosure
    Read the desk note

    Parliament returns on 12 October 2026 for its first sitting since the Services Australia access became public. Watch Question Time and any ministerial statement for whether an AI incident-notification duty, the empty row this article records, is raised at all. This article's own test: whether the gap it documents becomes a question anyone in Parliament asks.

  • 12 October 2026Watch
    Parliament returns
    Nobody has to tell · The Reporting Rort
    First sitting since the incident became public
    Read the desk note

    Parliament returns for its first sitting since the incident became public. Watch Question Time and any ministerial statement on reporting duties for AI firms, and watch whether Andrew Gee's AI Kill Switch and Data Centre Control Bill 2026, still before the House as a private member's bill, moves at all. Also watch whether any referral to the Cyber Incident Review Board, or any outcome of the PM&C rapid review's consideration of AI firms' notification requirements, is announced around the sitting.

  • 12 October 2026Watch
    Parliament returns, first sitting since the disclosure
    The inbox checked once a day · The Reporting Rort
    Watch Question Time and any ministerial statement on the incident
    Read the desk note

    Parliament returns on 12 October 2026 for its first sitting since the 24 September disclosure. Hansard for 14 to 17 September, the sitting days that overlapped with Services Australia’s handling of OpenAI’s email, carries no reference to the incident. Watch this sitting for Question Time on the breach, any ministerial statement, and whether the government’s taskforce or the Joint Select Committee on Artificial Intelligence reports back to the chamber.

  • 25 September 2026Correction
    Correction published
    Fourteen days · The Reporting Rort

    This article previously said ACL admitted liability. ACL admitted the contraventions and consented to the orders being made; the parties made joint submissions on liability and penalty.

  • 25 September 2026Correction
    Correction published
    Nobody has to tell · The Reporting Rort

    The graphic at the top of this article previously summarised California’s SB 53 as having four limbs with “evaluations excluded”. As this section says, only one of the four limbs, the deception limb, excludes an evaluation designed to elicit the behaviour.

  • 24 September 2026Record
    Record: THE REPORTING RORT launches with articles 1 and 2
    Nobody has to tell · The Reporting Rort
    The Reporting Rort · attended 24 September 2026
    Read the desk note

    ATTENDED 24 September 2026 (case: THE REPORTING RORT, article 2 of five).

    FINDING. Every Australian reporting duty checked against this incident binds someone else, needs a trigger this incident lacks, is voluntary, or waits on a referral, and none has been announced. The Privacy Act's breach duty binds the entity holding the data, not the entity that got into it. The Cyber Security Act's only mandatory clock runs on a ransom payment; the rest of its incident-sharing scheme is voluntary. Critical infrastructure operators carry a clock; the Act covers eleven listed sectors and government is not one of them. The agency's own duty to the Australian Signals Directorate carries no clock at all, only "as soon as possible," and, on ASD's 2025 figures, only 35 per cent of Commonwealth entities indicated they reported even half the incidents they saw. A board with compulsory notice powers over companies exists. No referral to it has been announced. The criminal law reaches companies exactly as it reaches people and reaches abroad, but its unauthorised-access offence needs intent and knowledge, and every party on the record calls this access unintended. Probably none of the overseas frontier-AI laws held up as models would have caught this incident either.

    ARTICLE CHANGES. Article 2, "Nobody has to tell," published alongside article 1 as the case launch, covering the duty-by-duty law gap and the international comparison.

    STILL OPEN. Right of reply to the Attorney-General's Department, Home Affairs, the National Cyber Security Coordinator, PM&C and OpenAI will be sought; any response, or its absence, will be added when it comes in. Whether a referral to the Cyber Incident Review Board is ever made, and what the 24 September rapid review recommends on AI firms' notification duties, remain unresolved.

    NEXT DATES: 12 October 2026, Parliament returns; 1 January 2027, New York's RAISE Act takes effect.

  • 24 September 2026Record
    Record: THE REPORTING RORT opens, article 1 published 24 September 2026
    The inbox checked once a day · The Reporting Rort
    This article carries no responses from Services Australia, PM&C or OpenAI
    Read the desk note

    ATTENDED 24 September 2026 (case: THE REPORTING RORT, article 1 of five).

    FINDING. The government’s own account, given at press conferences in New York and Sydney on 24 September 2026, puts eighty-four days between an OpenAI agent’s access to a Services Australia portal (18 June 2026, the government’s date) and the company’s first notice to the state (10 September 2026, by email to a researcher inbox the minister says is checked once a day). This article lays those dates, and the fourteen days that followed to public disclosure, side by side against the government’s own record.

    ARTICLE CHANGES. Article 1, “The inbox checked once a day”, published, covering the incident chronology and who knew on which day. Four more articles are planned in this case.

    STILL OPEN. This article carries no responses from Services Australia, PM&C or OpenAI.

    NEXT DATE: 12 October 2026, when Parliament returns for the first time since the disclosure.

  • 24 September 2026Record
    Record: THE REPORTING RORT, article 3, "Fourteen days", published
    Fourteen days · The Reporting Rort
    Ledger built from primary sources; two optional facts held back pending verification
    Read the desk note

    Attendance record for THE REPORTING RORT, article 3 of five, published 24 September 2026.

    The ledger in this article is built from primary sources read directly: the Social Security (Administration) Act 1999 (ss72, 74), the TIA Act Annual Report 2024-25 (Tables 29 and 33, re-read by the case architect), the CDPP Annual Report 2024-25 (Table 14), the Services Australia Annual Report 2024-25 (debt management), OAIC media releases on Australian Clinical Labs, Optus, Medibank, MediSecure, Qantas, Clearview AI, Kmart, Bunnings and Meta, AUSTRAC's Westpac release, the Cyber Security Act 2024, the PSPF Release 2026 and the ASD cyber posture report. The Security of Critical Infrastructure Act is reported via a legal explainer, not read directly. Reported sources also include ABC, MLex, InnovationAus and IDM.

    Two optional facts, a Centrelink recovery-fee rate and an OAIC sector count, were held back pending verification: the fee has been seen only in archived captures of a DSS guide, and the sector count has no verbatim quote captured. Neither is needed for the article's case.

    Next dates set: 12 October 2026, when Parliament returns, and 7 June 2027, when the Optus class action is listed for trial.

The desk record →

Nobody wrote this page. It assembled itself from the 3 investigations that make up The Reporting Rort, and it deepens automatically each time The Rort publishes another in the series. The named actors, the sourced figures and the evidence chain stay in lockstep with the archive.

← THE DOCKET
Independent · No ads · No masters · If it's a rort, we cover it
Submit a Tip →
Engine DΛREΛKT_Contract site.therort 1.0.0Core 94216cc946eeBuild 2026-09-26T11:59:16Z