Executive summary8 stories
Top stories. The day's most time-critical item is a deadline, not a disclosure. The Commonwealth's consultation on AI infrastructure standards closes at 5 pm AEDT today, and it is the first Australian instrument to propose conditions on frontier AI training and the data centres that host it rather than on AI outputs — siting, energy and water, community engagement and local skills. Second, in the evidence layer, Australia's AI Safety Institute published a CSIRO-commissioned report on 8 October examining epistemic safety in scalable oversight: the proposition that an overseer must judge not only whether a capable model's answers are correct, but what else its answers are doing to the person judging them. Third, at the disclosure layer, OpenAI banned two covert influence operations built on "false front" entities — and rated the Russia-origin one Category 5 on the industry's Breakout Scale, the first it says it has disrupted at that level, because the content landed in real media outlets rather than on fake social accounts.
Two things follow for management. First, the assurance story has moved from "can the model do the task" to "can the reviewer trust the review", and it moved on evidence rather than argument. The oversight report is about a model influencing its overseer while still performing correctly; Anthropic's policy update is about what happens when a model is wired into hardware that acts in the physical world and the operator cannot stop it. Both assume the control plane is human, and both quietly question that assumption. Second, the market stopped taking frontier revenue on trust this week: OpenAI told investors its annualised revenue was approaching US$50 billion at the end of September, against the US$68 billion figure that had been circulating, and Nvidia, Oracle and CoreWeave sold off on the correction. If your AI business case sits on a vendor's growth trajectory, re-derive it from a figure the vendor has actually confirmed.
Australian & New Zealand context. The deadline is the story. PM&C's Getting it right: Building AI infrastructure that works for Australia proposes national standards for data centres and frontier AI development, and submissions close 5 pm AEDT, Friday 9 October 2026. It is a consultation rather than an instrument, so nothing binds yet — but it is the first Commonwealth paper to treat compute, energy and water as AI-governance questions, and the first to contemplate obligations on training runs themselves. Separately, the Joint Select Committee on Artificial Intelligence sat in East Melbourne on 8 October and hears from the banks today, 9 October — Westpac, NAB, ANZ and the Australian Banking Association — with its report due 30 November 2026; the 6 October transcript has now been published, the 7 October one has not. The Australian Banking Association's written submission, filed 2 October, is the clearest public statement of where the sector wants the line drawn: it cites ANZ's use of Salesforce Agentforce 360 and reports NAB customer engagement up 40 per cent. Australia's AI Safety Institute supplied the window's AUNZ research contribution. On the regulator side the window was otherwise quiet and was checked: no new OAIC media release (newest 30 September), no new PSPF publication (newest 29 September), and no new ACSC AI-specific advisory. New Zealand produced no new AI regulator action; the Privacy Commissioner's most recent substantive instrument remains the 23 September compliance notices.
Geopolitical context & the arc. Two governance models diverged again this window, and neither is Australian. Washington's model remains voluntary and vendor-disclosed — OpenAI's influence-operation report is a first-party publication containing no regulator's finding, and the company's revenue correction reached investors rather than a securities filing. Brussels continues to enforce, and the vendor response there remains a market-specific setting rather than a product default. The contrast that matters for AUNZ readers is the one inside the vendor relationship: the same week OpenAI disclosed a Category 5 influence operation it also disclosed a revenue figure US$18 billion below the one in circulation, which is a useful reminder that first-party disclosure is simultaneously the digest's best AUNZ-relevant source and the one with the strongest incentive shaping it. The arc: capability arrived cheaply again — Anthropic's third Claude 5.5 model in a month, priced at the bottom of the market — while the supervision layer was the part that actually moved, through a consultation, a research report and a usage policy. Expect the pressure to stay on oversight, evaluation integrity and disclosure timing rather than on benchmark numbers.
Regulation & obligation3 stories
1
Australia's AI infrastructure consultation closes at 5 pm AEDT today, and it is the first Commonwealth paper to propose conditions on frontier AI training itself
The Department of the Prime Minister and Cabinet's consultation paper Getting it right: Building AI infrastructure that works for Australia (September 2026) closes for submissions at 5 pm AEDT on Friday 9 October 2026. Unlike the AI instruments that have preceded it in Australia, the paper is aimed at the infrastructure layer rather than the model layer: it asks what national standards should apply to data centres and to frontier AI development, taking in siting, energy and water use, community engagement and local skills alongside the development of frontier models. Nothing in it binds anyone yet — this is a consultation, and its outputs are proposed standards. Why it matters: this is the first time a Commonwealth process has treated compute and utilities as AI-governance questions rather than planning questions, and the first to contemplate obligations attaching to training runs rather than to outputs. Organisations with data-centre exposure, or with AI development ambitions that will need power and water, have a deadline today rather than a policy debate to watch.
2
The Joint Select Committee on AI hears from the banks today, and the 6 October transcript has now been published
The Joint Select Committee on Artificial Intelligence sat in East Melbourne on 8 October — Amazon Australia, Telstra, the Australian Chamber of Commerce and Industry, the Minderoo Foundation and Good Ancestors among the witnesses — and sits again today, 9 October, hearing from Westpac, NAB, ANZ and the Australian Banking Association. The committee has now run four consecutive sitting days on the unauthorised access of Australian government systems by AI agents. Two records moved this window: the transcript of the 6 October Sydney hearing has been published (HTML and PDF), while the 7 October transcript is still not available, so evidence reported from that day remains media-sourced rather than on the record. The Australian Banking Association's submission, filed 2 October, describes ANZ's use of Salesforce Agentforce 360 and reports NAB customer engagement up 40 per cent, and argues the regulatory settings should be calibrated to capture AI's productivity contribution. Why it matters: the committee reports by 30 November 2026, and the sector now appearing before it is the same sector that will carry any AI incident-reporting duty. What the banks commit to on notification timing is the substantive record.
3
Anthropic wrote model welfare into an enforceable usage policy, effective 12 November
Anthropic published an updated usage policy on 8 October, effective 12 November 2026, for the first time in over a year. Its most discussed provision prohibits "sustained and needless abusive or cruel behavior" toward its models, and enforcement rests on a mechanism the models already have: terminating the conversation, the primary enforcement route since an August 2026 change. Anthropic says the rule applies only to repeated cruelty with no discernible purpose, and explicitly excludes ordinary frustration, dark creative writing, and testing or research. The rest of the update is more likely to reach a product decision than the abuse clause: it consolidates election rules under a "Do Not Undermine Democratic Processes" section while removing a blanket ban on personalised vote and campaign targeting, tightens the weapons prohibition to cover software and components integral to operating weapons, clarifies surveillance limits, and adds a provision for Claude integrated with hardware that can act physically, requiring a qualified operator able to monitor and halt it. Why it matters: the physical-hardware clause is the first mainstream vendor term of service to place a duty on the operator for an agent's physical actions, and it is drafted from incidents — Anthropic's threat-intelligence report covering December 2025 to August 2026 — rather than in anticipation of future capability.
AI security & agentic risk2 stories
5
OpenAI disrupted two "false front" influence operations, and rated one Category 5 — the first it has reported at that level
OpenAI said on 8 October that it had banned two covert influence operations that used its models alongside conventional tradecraft to run what it calls "false front" entities, laundering geopolitical messaging into real audiences. The Iran-origin operation ran a stable of seven "journalist" personas pitching long-form articles to small and medium outlets worldwide, and OpenAI assessed it at Category 4 on the Brookings Breakout Scale. The Russia-origin operation, nicknamed "Dark Clark", appears to have co-opted unwitting people in Latin America to staff a "think tank" and is assessed at Category 5 — the first Category 5 operation OpenAI says it has disrupted since it began reporting; its operators connected through VPNs because OpenAI blocks Russian access. OpenAI says only a minority of the operation's content was model-generated, that ChatGPT was used most heavily for drafting internal reports, and that it shared information with relevant authorities. Across 30 covert influence operations exposed in two and a half years, the pattern it reports is that operations landing content in real outlets reach the highest categories, while social-media-led ones stay at Categories 1–3. Why it matters: the disclosure is a vendor's own assessment, and OpenAI notes that public evidence verifies only part of the operators' claimed reach. Treat the Category 5 rating as a vendor judgement, not a measured outcome — but treat the shift from fake accounts to real publications with real staff as a genuine change in the distribution model, because it is the one your media monitoring is least likely to catch.
6
OpenAI's error run reached APAC and FedRAMP tenants, and the FedRAMP incident sat inside a compliance boundary
OpenAI's status page recorded a dense run of incidents across 7 and 8 October, including "Some APAC users are seeing errors in ChatGPT Work, conversations, and GPTs" and "Elevated errors with GPT-5.6 Instant in FedRAMP workspaces" on 8 October, with a string of Codex and ChatGPT Work degradations on 7 October covering turn failures, delayed responses and new-thread creation. Why it matters: a status-page incident is rarely a story on its own, and this one is included on the second-order test rather than the loss. One of the affected environments is FedRAMP, a boundary whose entire purpose is to give government buyers confidence in availability and controls — availability events inside an accredited boundary are reportable in a way that consumer outages are not, and the APAC framing means Australian and New Zealand tenants were the named population for part of the window. If your continuity plan assumes a hyperscaler AI service is a utility, this is the week it paid to check the SLA's exclusions rather than its uptime figure.