Submission on Australia's AI data centre standards

Four points on health data, reserved computing power and incident reporting. Lodged with the Department of the Prime Minister and Cabinet, October 2026.

By Samantha Pillay

Submission on Australia's AI data centre standards

Managing growth

Is a single threshold such as an energy capacity (MW) sufficient to identify the data centres that should be subject to the AI standards? If not, what additional thresholds should be considered?

Energy capacity is a sensible threshold for the requirements about energy, water, land and communities, because those impacts scale with size. It is the wrong threshold for requirements about data.

A data centre's risk to Australians depends on what it holds, not how much power it draws. A facility of 20 MW that stores or processes Australian health data, or that trains AI on it, carries more public risk than a facility of 200 MW running commercial workloads. Under a single megawatt threshold, the smaller facility would sit outside the standards entirely.

I propose a second trigger that applies regardless of size: any facility, or any operator within it, that stores, processes or trains AI on Australian health data should have to meet requirements on where that data is stored, who holds the keys to it, and whether it can be used to train AI. Size decides the environmental obligations. The data decides the security obligations. The two tests should run independently.

I am a surgeon, not an engineer, so I offer no view on the 30 MW, 100 MW and 150 MW figures themselves.

Following the passage of the proposed legislation, when should compliance start? For example, immediately, or staggered for different requirements, recognising practical constraints around planning and approvals, and to ensure regulation is proportionate. How should certainty for, and impacts on, the Australian community be balanced with these considerations?

Requirements about energy, water and planning may need a staggered start because they depend on approvals and construction. Requirements about Australian health data should start immediately. They concern where the data is stored, who holds the keys and whether it can be used to train AI, none of which depends on building anything. A facility that already holds Australian health data on the day the legislation passes should be required to comply from that day, or to show within a short, fixed period how it will.

Do you have any additional comments on this topic?

The section notes that a data centre can involve owners, operators, tenants and AI developers, but does not ask who should carry which obligation. For requirements about Australian health data, this matters more than the requirement itself. The duty has to sit with whoever controls the data. Put it on the wrong party and they cannot act on it.

Each obligation should sit with the party that controls the thing it governs:

The building owner controls where the building is located, power, water and physical security, and should be responsible for those, and for knowing and reporting which tenants hold Australian health data.

Whoever runs the computers controls three things: where the data is stored, who can reach it, and who holds the encryption keys that unlock it. That party should be responsible for keeping Australian health data in Australia, with keys held in Australia by an Australian-controlled entity, and for not using it to train AI without Australian approval.

An AI developer training in Australia should be responsible for not using Australian health data in training without Australian approval.

Public health buyers, meaning Commonwealth and state health departments, public hospitals and agencies such as Services Australia and the Australian Digital Health Agency, should be required to purchase only from providers that meet these conditions. That is the enforcement mechanism, and it needs no new regulator.

Data centre operators have argued that building owners cannot control computers they do not run. That is right, and it is why the data obligations should attach to whoever runs the computers rather than to the building. The consultation paper's own definitions already separate the data centre owner from the data centre user. The standards should use that distinction.

Requirements for data centres

What does best practice community engagement look like for data centres, including with nearby businesses?

Community engagement for data centres usually covers traffic, noise, water and power, because those are the questions people ask. In my experience talking to patients and the public about AI, those are not the questions people are worried about. People are worried about AI itself: what it knows about them, who controls it, and what it will do to their jobs and their children. They cannot see it or touch it. A data centre is the one part of AI they can point at, so it collects the objections that belong to the technology.

That has two consequences for engagement. First, answering the energy and water questions well will not settle the opposition, because the opposition is not entirely about energy and water. Second, the engagement that works is the kind that gives the community something to name: what the facility holds, who can reach it, and what the community gets back. A data centre that keeps Australian health data in Australia under Australian control, and that reserves part of its capacity for public uses such as health, has an answer to the question people are actually asking.

What role should the Commonwealth's mandatory requirements play in relation to location and community engagement? For example, the Commonwealth could promote transparency around where new data centres are being developed or plans for community engagement.

If the Commonwealth promotes transparency about where data centres are being built, it should also require transparency about what they hold. A public register of facilities that store or process Australian health data, naming the operator responsible and confirming that the data and its encryption keys are held in Australia under Australian control, would do more for community trust than any engagement plan. People are more accepting of infrastructure they can see into.

How can communities and industry work together to ensure data centres deliver lasting community benefits? How can this upfront commitment be reflected in state and territory planning processes or community engagement?

The lasting benefit of a data centre is what it computes, not what it spends locally during construction. A facility that reserves part of its capacity for public uses, with health first, gives the community and the country a benefit that continues for as long as the facility runs. That commitment should be made before approval and written into the conditions of approval, so it cannot be withdrawn once the facility is built. I set out how reserved capacity should work in the Conditions for AI training section.

Should data centres be required to locate a minimum distance away from sensitive sites such as schools or residential homes? If so, what should the mandatory minimum distance be? Which level of government is best placed to issue and administer location requirements?

I would be careful with this one. Data centres have real local impacts, noise, traffic and backup generators among them, and those should be managed under the same planning rules that apply to any large industrial building. But a mandatory minimum distance from schools and homes says something different. It tells the public that these facilities are dangerous to children and the elderly in a way that needs a buffer, when they are not. A requirement framed that way will increase the fear it is meant to address, and it will attach that fear to AI generally. Manage the measurable impacts through ordinary planning rules, administered by the states, and do not create a new category of hazard that does not exist.

Conditions for AI training

What international approaches, including regulatory and non-regulatory frameworks, should inform the type of safety, transparency or security conditions Australia applies to developers of frontier AI models?

The model for incident reporting should be confidential and no-blame, as it is in aviation and in hospitals. If reporting a near miss could end a pilot's career, pilots would stop reporting near misses. Hospitals learnt the same about clinicians, which is why clinicians are encouraged to report incidents and are not punished for doing so. An incident reported promptly and in good faith is reviewed for what it teaches, not prosecuted for what it reveals. Anyone who acted deliberately, or who knew and said nothing, gets no protection. The result is more reports and fewer repeat incidents. Australia already runs such a system for aviation through the Australian Transport Safety Bureau (ATSB). The conditions for frontier AI developers should be modelled on it.

I understand international standards bodies are developing a common format for AI incident reports. Australia should set its own rules for how quickly an incident must be reported and who it is reported to, and adopt whatever international format emerges for the report itself.

How should safety and security conditions for AI training be designed to keep pace with rapid technological change, while providing sufficient legal certainty for investors and operators?

Conditions that describe the technology, such as model size, training method or compute thresholds, will be out of date within a year or two and will need rewriting each time.

Conditions that describe what is done with data and what happens when something goes wrong do not date. Where health data is stored, who holds the keys, whether it can be used for training, how quickly an incident is reported and to whom: none of these depends on how the models work. Write the conditions about the data and the conduct, and they will still fit whatever the technology becomes.

What information should AI developers be required to share with the Australian Government and how?

Proactively, within a fixed time, to a designated confidential reporting channel. The Medicare statistics portal incident shows what happens without those three things. OpenAI's agent entered the portal on 18 June 2026. OpenAI found it on 11 August and told Services Australia on 10 September, by email to a public mailbox. The email was read the next day but took four more days to reach the Australian Signals Directorate. The public heard on 24 September. That is 54 days to find it, 30 days to say so, and 14 days inside government before anyone outside knew.

Four requirements would fix this:

  1. A designated confidential reporting channel for AI developers, run by the Australian Signals Directorate's Australian Cyber Security Centre, with receipt acknowledged. Not a general inbox.
  2. Initial notification within 72 hours of the developer becoming aware, matching the Security of Critical Infrastructure Act, which the consultation paper already proposes to use. A full written report within 30 days.
  3. Every report must state the date the developer first detected the incident. "In August" is not a date. Without it, nobody can tell how long the problem went unnoticed from how long the company sat on it.
  4. The same obligations on the agency that receives the report: escalation to the Australian Signals Directorate within 72 hours, and public disclosure within a fixed period. Guardrails have to cover the systems that hold our data as well as the companies whose models reach them.

Reporting should be a condition of authorisation to train in Australia. Individual reports should go to the regulator and stay confidential. The government should publish a summary of incidents each year. A developer that expects its report to be a headline the next morning will report less.

What safeguards should apply?

A protection for the developer that reports properly, so that reporting is the obvious choice.

A developer that reports an incident within the required time, in good faith, where no personal data was taken, sold or used and no harm resulted, should be protected from prosecution for the model's access. The incident is still investigated and reviewed, with both the developer and the agency at the table, because the point of the review is to find how the holes lined up and close them before someone with real intent finds them first.

The protection is from charges, not from scrutiny.

The protection should not apply to anyone who accessed a system deliberately, reported late, used or kept the data, or knew and said nothing. Under the 72-hour rule proposed above, OpenAI's 30-day delay would not have qualified. This is not leniency. It is a rule with a clock.

The unauthorised access offence requires intent, and an AI agent has none in the legal sense. Threatening prosecution spends legal resources on a case that is unlikely to succeed, and it discourages the timely reporting the government needs. The threat produces headlines, not reports.

Hospitals and aviation learnt this decades ago. A system that punishes reporting gets fewer reports, not fewer incidents.

What contributions would add the greatest value to Australia's future industries and research and innovation system? For example: sourcing local AI solutions, access to compute capacity, locally based research and engineering staff, investing in Australian research presence, university and public research organisation partnerships, investing in the VET system, and commercialisation activity.

Access to compute capacity, reserved for public use, with health first.

The number of Australians over 65 will more than double over the next 40 years and the number over 85 will more than triple. The care workforce would need to double to keep pace, and it cannot fill its rosters now. The health system will not meet that demand with more staff, because the staff do not exist. It will meet it, if at all, with AI doing work that people currently do, and that requires computing power the health system does not own and cannot buy at the prices a frontier lab pays.

A frontier lab authorised to train in Australia should be required to reserve a defined share of its Australian capacity for public use. Three conditions make the reserve real rather than a gesture:

  1. It must be capacity Australia allocates, not credits the company issues. Credits are access on the company's terms and can be withdrawn or repriced. Reserved capacity cannot.
  2. A public body allocates it, with health first and independent safety testing of models beside it, and research, start-ups, vocational education and not-for-profits sharing the rest.
  3. Use of the reserve is reported publicly each year, so Australians can see what their share of the facility produced.

Compute access is already the bottleneck. The ACCC told the Joint Select Committee on Artificial Intelligence that because only a few companies own the computing power, everyone else has to rent it from them on their terms, which keeps those companies on top. A reserve is how a country that hosts the computers makes sure some of them work for it.

What mechanisms should the government consider for securing these contributions? For example: negotiated in-kind contributions, a compute reservation scheme, a public-interest research payment, or other approaches.

A compute reservation scheme, written into the conditions of authorisation to train in Australia, so that it applies to every lab on the same terms and cannot be negotiated away.

Negotiated in-kind contributions, where each lab agrees its own package of research funding or free services with the government, vary from deal to deal and depend on the government's bargaining position on the day. A public-interest payment is money, and money buys compute credits on the company's terms, at the company's prices, for as long as the company chooses. A reservation of real capacity, allocated by a public body and reported each year, is the only one of the three that gives Australia something the company cannot later withdraw.

Are frontier AI developers best placed to make contributions in these areas? Should other actors be considered, for example, hyperscalers and neocloud providers?

The reservation should sit with whoever owns and runs the computers in the data centre, which is often not the frontier developer. OpenAI trains on computers owned by Microsoft. If the obligation applies only to developers, a developer can avoid it by renting. If it applies to whoever operates the computers, whether a hyperscaler, a neocloud provider or a developer running its own, the reserve is there regardless of who is renting. The same principle applies to the health data conditions: the duty sits with the party that controls the thing it governs.

If frontier AI developers or other actors reserved some compute for Australian research, innovation and public-interest purposes, what conditions or terms should apply?

Four terms. The reserve is a share of real capacity, not credits, so it cannot be withdrawn or repriced. A public body allocates it, with health first, independent safety testing of models beside it, and research, start-ups, vocational education and not-for-profits sharing the rest. Use is reported publicly each year. And any data processed on the reserve is held under the same conditions as all Australian health data: stored in Australia, keys held in Australia, no training on it without Australian approval. Without that, the reserve hands the operator the health data the other conditions are there to protect.

What indicators could best demonstrate contribution to Australian research, innovation and public interest purposes? For example: locally based research and engineering staff, university and public research organisation partnerships, research outputs and commercialisation activity, or other approaches.

For reserved compute, the indicator is the annual public report: how much capacity was reserved, how much was used, by whom, and for what. For health, that report should name the clinical uses, which patients benefited and what it replaced.

Staff numbers and partnerships are inputs. Australians should be able to see outputs.

The Commonwealth proposes reporting and transparency requirements at a federal level for large data centres, so that impacts and benefits to communities are transparent and trusted. Where might this proposed approach interact with existing legislation? Please note if these are Commonwealth, state and territory, or local government legislation.

Three Commonwealth instruments, all of which already do part of what I am proposing for health data.

The My Health Records Act 2012, section 77, requires My Health Record data not to be held or taken outside Australia. Parliament has already decided that this kind of health data stays onshore. The AI standards should extend the same rule to Australian health data held by any data centre operator, and add what section 77 does not say: who holds the keys, and whether the data can be used to train AI.

The Commonwealth's Hosting Certification Framework, run by the Digital Transformation Agency, already assesses providers that host government data on ownership and foreign control, not only location. The standards should apply that test to health data wherever it is held.

The Security of Critical Infrastructure Act, which the consultation paper proposes to use, already sets reporting windows of 12 and 72 hours for cyber incidents. The AI incident reporting proposed earlier in this submission should use the same windows.

What additional regulatory reforms or incentives would encourage frontier AI training in Australia?

For health data, the conditions in this submission are the incentive, not the cost.

The data centre industry will argue that conditions deter investment. For most workloads that may be true. For sensitive data it is backwards. A government deciding where its citizens' health data can sit is choosing a legal system, not a block of land. If Australia legislates that health data stays where it is put, that the keys are held by an Australian-controlled party, that nothing trains on it without permission, and that part of the capacity is reserved for the data owner's own use, then Australia becomes a place other countries can put data they would not put anywhere cheaper.

The consultation paper already describes Australia as a trusted infrastructure partner for the region. Trust is made by rules that bind. The reforms that would attract this kind of investment are the ones that make the rules clear, national and enforced.

Do you have any additional comments on this topic?

The consultation paper's introduction says sovereign AI capability relies on secure, onshore data centre infrastructure. For health data, onshore is not enough, and the standards should say so.

Control over data follows three things, and the address of the building is not one of them. First, who owns the company running the computers. The United States CLOUD Act allows US authorities to require a US company to hand over data it holds anywhere in the world. A US cloud company operating a data centre in Sydney is still a US company, and the location of the server does not change what a US court can order. Second, who holds the encryption keys. Whoever holds the key can read the data or be ordered to hand it over. Third, whose law prevails when Australian law and a foreign law conflict. The company answers to its home government.

So a Medicare dataset held in an Australian building, by a US-owned operator, with keys held by that operator, is data a foreign government can reach without asking Australia.

The standards should define what onshore must mean for health data: stored in Australia, keys held in Australia by an Australian-controlled party, and access decisions that cannot be overridden from outside Australia. Where that cannot be delivered, the provider should not be eligible to hold Australian health data.

The same principle applies to testing. The Australian AI Safety Institute has begun frontier model testing. A model that will touch Australian patients should be tested by a body that answers to Australia, not accepted on the developer's word or on tests run elsewhere.