This week in compliance: AI agents in the hot seat, a live Citrix alert and a scaffold lesson

Big week if you look after compliance. The OpenAI Medicare saga landed in a hearing room, Canberra and Singapore both told us how they'll regulate AI, and a Queensland coroner reminded us a rule of thumb isn't a risk assessment. Here's what happened and what I'd do about it, starting at home.
π¦πΊ Australia
OpenAI says sorry to the AI inquiry
6 October 2026
OpenAI's chief strategy officer Jason Kwon fronted the Joint Select Committee on AI in Sydney on Tuesday and apologised for one of its agents getting into Services Australia's Medicare statistics portal back in June. The agent found a non public access point, ran commands and pulled internal files and credentials, and OpenAI didn't tell the government until 10 September, by email to a general mailbox. Kwon said OpenAI would welcome mandatory incident reporting.
What it means for you: If you or your suppliers are running AI agents against real systems, ask what they can reach, who's watching the logs and how quickly you'd find out.
Sources: ABC News, 6 Oct; iTnews, 29 Sep
Canberra wants AI companies to prove their safety systems work
8 October 2026
Assistant Minister Andrew Charlton used a speech at the Sydney Trust and Safety Festival to lay out "systems regulation" for frontier AI under the National AI Standards. Rather than banning specific behaviours, companies would have to run a rigorous process for finding, testing, reporting and managing risks, and be held accountable for whether that process actually works. The standards are due by the end of the year, with legislation planned for 2027.
What it means for you: This is the same model you already know from WHS and ISO management systems. Expect customers and regulators to ask for evidence that your AI controls operate day to day, not just a policy on the intranet. ISO 42001 is a sensible place to start.
Sources: Minister Charlton's speech, 8 Oct; ABC News, 8 Oct
Citrix NetScaler flaws are hitting Australian organisations
Alert 28 September, updated 30 September and 3 October 2026
ASD's ACSC issued a critical alert for eight Citrix NetScaler ADC and Gateway vulnerabilities, two of them exploited before a patch existed. By 30 September it had reports of exploitation in Australia and told organisations to look for compromise back to at least 4 September. On 3 October it flagged a separate SAML issue. This comes as Epoch AI data, also charted by a16z, shows critical vulnerabilities reported by 21 big software vendors jumped from 98 in April 2026 to 606 in July.
What it means for you: If you run NetScaler, patch, check logs back to 4 September and write down what you did. More broadly, hitting Essential Eight patching time frames gets a lot harder when the volume is six times what it was, so know exactly which internet facing systems you own before the next alert lands.
Sources: ASD's ACSC alert, last reviewed 3 Oct; Epoch AI CVE data; a16z chart
Privacy Commissioner investigates the app behind Kmart's smart glasses
7 October 2026
The OAIC has opened an investigation into Shenzhen Qingcheng, maker of the HeyCyan app used by low cost smart glasses including Kmart's Anko range and devices sold on Big W Marketplace and Amazon. The company didn't respond to preliminary inquiries about how recordings are stored and who can access them. Commissioner Carly Kind has asked retailers to think about whether they should keep selling them.
What it means for you: Recording wearables on site are a privacy question as well as a safety one. Your site rules should say what's allowed, and your supplier due diligence should cover where the data ends up.
Source: OAIC, 7 Oct
π¦πΊ Queensland
Queensland coroner says a rule of thumb isn't enough for tower scaffolds
Findings 30 September, industry response 6 October 2026
Coroner Megan Fairweather handed down findings into the 2021 death of Andrew Jones, who was struck by a freestanding tower scaffold that blew over at a Brisbane football club. The tower met the usual height to base ratio, but she found that ratio alone doesn't assess wind risk. She recommended the Scaffolding Code define "strong winds" and require extra controls like outriggers, tie downs or counterweights for towers in public places, then education and compliance campaigns. Scaffolding Association Australia backed the education push on 6 October.
What it means for you: Look at your temporary works. If a scaffold is staying up for weeks, who checks it when a wind warning comes through?
Sources: Scaffmag, 2 Oct; Scaffolding Association Australia, 6 Oct
π Around the world
πΈπ¬ Singapore weighs tougher safeguards for high risk AI
6 October 2026
Minister Josephine Teo told Parliament in a written answer that the government is studying stronger safeguards for high risk AI uses. That could mean more rigorous testing, independently verifiable evidence that safety measures work and tighter controls on deployment in essential services. It's also looking at how CSA's incident reporting channels can pick up AI incidents.
What it means for you: Australia and Singapore are landing in the same spot: show your working. If you operate in both, build one evidence pack that answers both.
Source: CNA, 6 Oct (updated 8 Oct)
Still on the radar
π ISO 9001:2026 was published on 16 September. Existing certificates have until 30 September 2029 to transition. (Global ACI, 16 Sep)
πͺπΊ The EU Cyber Resilience Act reporting duties have applied since 11 September. If you sell digital products into the EU, actively exploited vulnerabilities need a 24 hour early warning through ENISA's platform. (ENISA, 11 Sep)
One thing to do this week
From 10 December 2026, your privacy policy has to say if a computer program makes, or does something substantially tied to making, decisions that significantly affect people using their personal information. The OAIC published a fact sheet and flowchart on 30 September. Spend an hour listing where software decides things about people in your business, like rostering, fitness for work checks, contractor prequalification or candidate screening, then run each one through the OAIC flowchart.
That's the week. If you'd like to see how Vissibl keeps track of these duties across your frameworks, flags what's about to expire and chases the evidence, with you signing off, a demo takes 20 minutes.
Sean