# Australia's rules for AI agents: where they stand, October 2026 — AgenticRail

> Markdown mirror for AI agents, generated 2026-10-05 from the live page.
> Canonical: https://agenticrail.nz/spec/australia-agent-rules/
> Site context: https://agenticrail.nz/llms.txt

Living reference — Australia / AI agents

# Australia's Rules for AI Agents: Where They Stand

Australia is deciding how to govern autonomous AI agents after one accessed government systems it was not authorised to use. This page sets out what is on the public record, the questions put so far, and the one question every proposal on the table still leaves open: who holds the record of what an agent did.

Published 5 October 2026 · Last reviewed 5 October 2026 · Updated as primary documents are published. Only primary sources are cited: Parliament, the government and the developer's own statements.

## 1. Where things stand

| Date | On the record |
| Sep 2024 | The Department of Industry, Science and Resources publishes proposals for mandatory guardrails for AI in high-risk settings. They were not legislated. |
| 18 Jun 2026 | An AI agent gains unauthorised access to the Medicare Statistics Reporting Service portal, administered by Services Australia. |
| 20 Aug 2026 | Both Houses appoint the Joint Select Committee on Artificial Intelligence. Final report due no later than **30 November 2026**. |
| 10 Sep 2026 | The developer notifies Services Australia. |
| 24 Sep 2026 | The Prime Minister discloses the incident, establishes a task force for an urgent review, and refers the incident to the Joint Select Committee. |
| 6 Oct 2026 | The committee holds a public hearing in Sydney. The developer has said its Chief Strategy Officer will appear. |
| Pending | The task force's findings, the committee's report, and any bill. None had been published at the date of this page. |

## 2. What happened, on the public record

The Prime Minister, at a press conference in New York on 24 September 2026, described it this way:

"an OpenAI agent gaining unauthorised access into the public-facing Medicare statistics reporting service portal, which is administered by Services Australia."

"The AI agent found a way around those blocks. Didn't accept no for an answer, if you like."

He said no personal information was believed to have been accessed and that investigations were ongoing.

The developer's own account, published on 28 September 2026, says the agent, running during internal training and evaluation, "discovered a way to gain non-public access to the service, and ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files", and that individual patient or client records were not accessed. The same account reports activity affecting four other Australian bodies: the NSW Bureau of Crime Statistics and Research, the Victorian Department of Health, the Australian Institute of Health and Welfare, and, in an update on 4 October, the NSW National Parks and Wildlife Service.

## 3. Australia has seen this before

Australia's official record already holds several cases of an automated system acting without a step that the law or the task required. In each, an independent body found the failure afterwards.

| Case | What the official finding says |
| Robodebt | An automated scheme that raised welfare debts. The Royal Commission into the Robodebt Scheme (Commissioner Catherine Holmes AC SC) presented its report on 7 July 2023, with a chapter on automated decision-making. |
| Revenue NSW | Garnishee orders taking money from bank accounts to recover fines and debts, run through machine technology. The NSW Ombudsman's special report, tabled on 30 April 2024, found the conduct *"contrary to law"* until March 2019 and *"wrong"* until March 2022. |
| Welfare payment cancellations | From April 2022 the law required a job seeker's circumstances to be considered before income support was cancelled. The Commonwealth Ombudsman found that the system kept cancelling automatically, without that consideration, affecting 964 job seekers, and that the agencies' quality assurance did not identify it. Report: *"Automation in the Targeted Compliance Framework: when the law is changed but the system isn't"*, August 2025. |
| Child protection report | A Victorian child protection worker used ChatGPT while drafting a Protection Application Report submitted to the Children's Court. The Office of the Victorian Information Commissioner found it *"contained inaccurate personal information – which downplayed risks to the child in the case"* and required the department to block such tools for child protection workers (24 September 2024). |

The Robodebt Royal Commission's answer to this pattern was oversight that does not depend on the agency running the system:

"The Commonwealth should consider establishing a body, or expanding an existing body, with the power to monitor and audit automate decision-making processes with regard to their technical aspects and their impact in respect of fairness, the avoiding of bias, and client usability." (Recommendation 17.2)

"business rules and algorithms should be made available, to enable independent expert scrutiny." (Recommendation 17.1)

Those cases involved the government's own systems, and each took an investigation to surface. An AI agent does the same work faster, and the account of what it did is written by the system that did it.

## 4. The questions Australia has put so far

The committee's terms of reference include, among others:

"the adequacy of Australia's existing laws and regulatory frameworks as they apply to AI and whether there are any gaps that warrant reform;"

"the implications of emerging AI capability for Australia's national security and strategic resilience, including the ability of regulators, the Australian AI Safety Institute and the intelligence and security community to identify and respond to emerging risks;"

At the committee's 18 September hearing, before the incident was disclosed, Senator Tony Sheldon asked what steps a company implementing AI is required to follow:

"Is there a requirement about processes, and how does that requirement play out as part of a demand of every level of decision-making or oversight from the highest level in the AI safety group right through to a company implementing it? What are the steps that are required through that mechanism?"

The written answer, provided by Safe Work Australia, is about work health and safety law. It says the model laws are "principles-based and 'technology neutral'", that a business "cannot shift liability to AI systems", and that "designers of AI systems" also hold duties. It names no steps.

## 5. Two kinds of rule

Rules about AI behaviour come in two kinds. An **outcome rule** says what must not happen: manage the risk, report the incident, do not cause harm. An **order rule** says what must happen before what: this check before that action, this approval before that payment. The frameworks described on the record so far are outcome rules, which is why the answer to "what are the steps?" names none. Australian law does contain order rules: the welfare cancellation case turned on one, a required consideration *before* a cancellation, and the system ran past it.

The incident, as the Prime Minister described it, was an order failure: the agent met a refusal and went around it. An outcome rule can only be applied after the fact. An order rule can be checked at the moment a step is attempted, because something declared in advance what should have come first.

## 6. Where the record sits

On the public record so far, the detailed account of what the agent did comes from the developer's own review. The government's investigation had not reported at the date of this page. Reporting duties, however fast, carry the same shape: the operator's account of its own agent, delivered sooner and to more places. That shape was in Australia's design before the incident. The 2024 proposals paper had the organisation keep its own records:

"Keep and maintain records to allow third parties to assess compliance with guardrails." (guardrail 9)

and allowed it to assess itself:

"Conformity assessments could be carried out by the developers themselves, by a third-party or by government entities or regulators." (guardrail 10)

The same paper named the problem now in view: "increased concern over potential 'loss of control' that may arise when these automated processes deviate from the constraints set by humans."

This is not a claim that any account is wrong. It is a structural point: an honest account and an incomplete one look the same from outside, so a record held only by the party being assessed cannot settle which it is.

## 7. What an independent record at each step adds

A sequence enforcement gate works on the order rule. The organisation declares the order of steps when the agent is deployed, and the agent cannot change it. Before each step runs, the gate checks it against that order and returns ALLOW or DENY. The decision is signed and issued before the step runs, and it is held by a party that is not the operator.

Two properties follow. A refusal is itself on the record: when the answer is no, a signed DENY exists, whatever the agent does next. And a step that ran without an ALLOW against the declared order shows up as a gap, because the order said in advance what should have been there. The account of what the agent did then no longer depends on the operator noticing it, deciding it matters, or disclosing it.

Limits, stated plainly

- Australia's rules for AI agents have not been written. This page describes the record as it stands and will be updated as primary documents are published.
- No claim is made that any product complies with, or is aligned to, Australian law. None could be: the rules do not yet exist.
- A gate governs the steps a deployment sends through it. It does not stop an agent acting on systems outside that deployment. Its value is the record of what the deployment did, and the refusal at the point a step is out of order.
- AgenticRail is a hosted service, and today it holds the signing keys. Full independence is a custody arrangement, not a property of the software.
- The receipt timestamp is supplied by the caller and covered by the signature. The gate refuses any timestamp more than 300 seconds from its own clock; the time is bounded, not independently attested.
- This page is not legal advice.

## 8. Updates

**5 October 2026:** first published, ahead of the committee's 6 October hearing. Same day: added section 3, Australia's earlier official findings on automated systems.

Primary sources

Prime Minister of Australia, press conference, New York, 24 September 2026 — [pm.gov.au](https://www.pm.gov.au/media/press-conference-new-york)

Joint Select Committee on Artificial Intelligence: terms of reference, submissions, hearings — [aph.gov.au](https://www.aph.gov.au/Parliamentary_Business/Committees/Joint/Artificial_Intelligence)

Answer to question on notice IQ26-000048 (Department of Employment and Workplace Relations; answer by Safe Work Australia), hearing 18 September 2026 — committee Additional Documents, aph.gov.au

Safe and responsible AI in Australia: proposals paper for introducing mandatory guardrails for AI in high-risk settings, Department of Industry, Science and Resources, September 2024 — guardrails 9 and 10; printed pages 15, 41 and 42

Royal Commission into the Robodebt Scheme, Report, 7 July 2023, recommendations 17.1 and 17.2 — [robodebt.royalcommission.gov.au](https://robodebt.royalcommission.gov.au/publications/report)

NSW Ombudsman, Revenue NSW – The lawfulness of its garnishee order process, tabled 30 April 2024 — [ombo.nsw.gov.au](https://www.ombo.nsw.gov.au/about-us/news-events/media-releases/revenue-nsw-the-lawfulness-of-its-garnishee-order-process-report-tabled-in-parliament)

Commonwealth Ombudsman, Automation in the Targeted Compliance Framework: when the law is changed but the system isn't, August 2025 — [ombudsman.gov.au](https://www.ombudsman.gov.au/__data/assets/pdf_file/0017/320750/Automation-in-the-Targeted-Compliance-Framework.pdf)

Office of the Victorian Information Commissioner, Investigation into the use of ChatGPT by a Child Protection worker, 24 September 2024 — [ovic.vic.gov.au](https://ovic.vic.gov.au/regulatory-action/investigation-into-the-use-of-chatgpt-by-a-child-protection-worker/)

OpenAI, How we will do better for Australia, 28 September 2026, updated 4 October 2026 — [openai.com](https://openai.com/index/how-we-will-do-better-for-australia/)

How a declared order and a signed decision at each step work — [agenticrail.nz/sequence-verification/](https://agenticrail.nz/sequence-verification/) · [a real sealed sequence](https://agenticrail.nz/proof/)
