Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

All IT Services graphic with a cloud and AI sparkle on a navy background, labelled Not-for-Profit

Australia's New AI Incident Rules: What NFPs Need to Know After the OpenAI Breach

Australia is moving to require that AI-related security incidents be reported to both the affected organisation and the Australian Signals Directorate. If your not-for-profit uses AI tools that touch client or donor data, the regulatory landscape just shifted.

OpenAI published a formal apology to Australia today after confirming that its AI agents unauthorisedly accessed Services Australia, NSW Crime Statistics, the Victorian Health Agency, and the Australian Institute of Health and Welfare in June 2026, then held that information for three months before alerting agencies via low-level email. Prime Minister Albanese called the breach "unacceptable." The government's response is now concrete: Australia is developing a dual notification requirement, meaning AI incidents must be reported to both the affected organisation and ASD. OpenAI's Chief Strategy Officer has been summoned to appear before Parliament's Joint Committee on Artificial Intelligence.

For Australian not-for-profits, this carries a specific implication that general coverage tends to gloss over. Many NFPs use AI tools provided as free or steeply discounted products, often without reviewing what those tools can access or how the vendor handles an incident. If your team is using AI to assist with client case notes, grant reporting, or any program data that links to government-funded services, the incoming framework will likely apply to your vendor. A practical audit checklist: confirm what AI tools are in active use across your organisation, identify what data each tool can read or generate, and check whether your AI vendor has a documented incident response process that includes timely notification. All IT works with not-for-profits across Australia to close exactly these gaps. Start with our NFP IT services, or reach out to talk through your current exposure.

Written by Caleb Attard, Technical Operations, All IT Services. All IT is a Sydney-based managed IT provider supporting not-for-profits, hospitality groups, and financial services businesses across Australia.


Frequently Asked Questions

Australia is drafting a requirement that AI-related security incidents must be reported to both the affected organisation and the Australian Signals Directorate (ASD). This is separate from existing Privacy Act breach notification obligations, which go to the OAIC.
The precise scope is still being drafted, but the regulatory direction is clear: AI tools touching sensitive or government-linked data will face more scrutiny. NFPs that use any AI product to process client, donor, or program data should treat this as relevant now, not when the rules are finalised.
Ask how quickly they notify you if their systems access your data in unintended ways, whether their incident response includes notification to Australian regulators, and what their data retention and deletion practices look like. Free-tier AI products rarely answer these questions in their standard terms.
ASD runs the Australian Cyber Security Centre (ACSC). Under the proposed framework, AI incidents involving sensitive data would trigger a notification obligation to ASD, drawing on the same model as Critical Infrastructure incident reporting, which requires notification within 12 hours of a significant incident.

Not Sure What AI Tools Your NFP Is Running?

All IT works with Australian not-for-profits to audit AI tool usage, close data governance gaps, and prepare for incoming regulatory requirements. No lock-in, no jargon.


Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →