AI & Data Centres

Independent research submitted to the Australian Senate inquiry into artificial intelligence and data centres, August 2026.

About this page

This page contains a web-readable edition of my submission to the Australian Senate inquiry into artificial intelligence and data centres, together with the 108 publicly available sources cited in it. The submission has been accepted for publication by the Senate Environment and Communications References Committee.

The official parliamentary publication remains the authoritative version. This HTML edition is provided to make the research and its sources easier to read, search, inspect, and follow online.

This site is hosted using Codeberg Pages. It uses no advertising, analytics, cookies, external fonts, or client-side JavaScript. The hosting choice is also part of the point: digital literacy includes making informed choices about which services we use, what information they collect, who operates them, and whether less extractive alternatives exist.

Artificial intelligence and data centres

Submission to the Senate Environment and Communications References Committee
30 August 2026 · Personal submission · Evidence-led public-interest research

Support independent public-interest research

I conducted this research independently and without funding. If you found it useful, you can support future public-interest research with a voluntary one-off contribution.

Access to this research is and will remain free. Contributions provide no editorial influence or privileged access.

Support independent research →

Payments are processed by PayPal. No PayPal scripts or tracking are loaded on this page. If you click the payment link, PayPal may collect personal, device/browser, transaction, location, and cookie/tracking data. For a quick privacy check, open PayPal’s current Australian Privacy Statement (accessed 1 September 2026) and use Ctrl+F (Windows/Linux) or ⌘F (Mac) for “Personal Information We Collect”, “How We Use Personal Information”, “Share Personal Information”, and “Cookies and Tracking Technologies”.

Why this research exists

This research first entered the world through my first-ever LinkedIn post.

I have never been particularly comfortable with the language of professional self-promotion. Too much professional writing seems designed to make ordinary human activities sound mysterious. People don’t “organise projects”; they “drive strategic outcomes”. They don’t “fix inefficient processes”; they “deliver transformation”. Nobody seems self-assured enough to say “I used a spreadsheet” when instead they can disgorge some obscurantist swill like “I leveraged a data-driven solution.”

George Orwell complained in 1946 that political language too often consists of words “falling upon the facts like soft snow”, concealing what really lies underneath.

The linguistic crimes committed on LinkedIn have industrialised Orwell’s proverbial snowfall.

Here is a recent achievement of mine, which I feel is objectively substantive enough not to require any cloaking in mystique.

Over the past weekend, on top of ordinary commitments, I researched and prepared a 28-page submission for the Australian Senate inquiry into artificial intelligence and data centres: an evidence-led examination of Australian AI and data-centre policy.

I directly consulted 108 relevant sources with my own human eyes.

These included government, regulatory, legal, academic, and corporate materials concerning privacy, copyright, data sovereignty, cybersecurity, consumer protection, environmental regulation, energy and water use, education, digital inclusion, competition, employment, procurement, and digital preservation.

Generative AI (ChatGPT 5.6 Sol) helped extensively with my research process.

It made me considerably faster. It did not make anything the AI said true.

AI helped me rapidly locate sources, interrogate unfamiliar subject areas, find connections, structure questions, draft prose, and maximise my own efficiency ahead of the Senate’s impending deadline. I also kept an organised evidence register (a fancy spreadsheet) and used a basic VBA macro to automate repetitive clicks. These tools were perhaps less “orchestrated and frictionless” than an AI agent might be, but nonetheless did the jobs they were intended to do, without requiring me to provide AI with more access to my workflow than I felt comfortable with.

When I use AI, I try to limit computation to the smallest practical unit of work required to advance the project. This is partly an environmental principle, but largely self-interest. A habitable planet is useful to me personally. Computing ultimately has physical costs, however enthusiastically those costs are abstracted into “productivity gains”. In my research methodologies, I obey the laws of thermodynamics.

Of course, I didn’t need to test whether AI could write a report for me, because I can write perfectly well on my own. I wanted to test whether AI could increase the volume of reliable evidence that one independent researcher could collate, verify, cite, and demystify for a general readership within a compressed timeframe.

AI did an excellent job in this bounded use case.

AI meant that one determined Australian constituent, with a budget approaching $0, a second-hand MacBook, far too many spreadsheets, a ChatGPT Plus subscription, and an unreasonable quantity of Mi Goreng, was able to investigate tough questions spanning multiple regulators, industries, and levels of government, then suggest immediately actionable and economically sound policy solutions.

In two days.

So I am clearly not inherently against AI.

And yet, I have questions.

The Senate Environment and Communications References Committee has now accepted the submission for publication. The full paper appears below, followed by its reference list of 108 publicly available sources.

My submission argues that many ostensibly separate AI-policy questions are not separate at all. They are consequences of the rapid deployment of one technology, yet responsibility for regulating that technology is fragmented across different laws, regulators, industries, and levels of government.

If regulation can be understood as ERP architecture, then it requires smooth API integration, posthaste — or, as somebody with LinkedIn brainrot might put it, “a cross-functional API transformation initiative, orchestrating seamless system interoperability to unlock scalable, frictionless experiences across the ecosystem.”

I will close with another Orwell:

“The great enemy of clear language is insincerity.”

— George Orwell, Politics and the English Language (1946)

I first published this explanation on 1 September, the closing date for submissions to the Australian Senate inquiry into artificial intelligence and data centres.

That Genesys Xperience 2026 in Las Vegas also begins on 1 September is entirely a coincidence.

The research is now also reproduced here in full so that it can be read independently of LinkedIn or any other commercial platform.

Visual transparency: AI-generated promotional images used when sharing this research were produced using prompting strategies ranging from “minimalist corporate tech iconography that emotionally evokes The Scream” to asking the AI to pretend it worked for Miranda Priestly and apply the minimum Vogue-quality airbrushing necessary.

Distribution transparency: Initial distribution of this research on LinkedIn was supported by promotional credit included with a free LinkedIn Premium trial. During the trial, I am informally examining whether Premium features affect access to professional networking, visibility, and employment opportunities, and whether any such effects might reinforce socioeconomic inequity.

Executive summary

For too long, Australian AI policy has treated AI’s demonstrated and ongoing impacts on energy, water, planning, the environment, privacy, cybersecurity, copyright, consumer protections, technology procurement, and governance as substantially separate concerns.

The result is a regulatory framework that has struggled to keep pace with four years of extraordinarily rapid technological change.

These impacts all arise from the same technological shift and frequently intersect. Any Office of AI must therefore be empowered to investigate AI’s effects across regulatory boundaries, coordinate specialist regulators, and identify gaps that no individual regulator is presently responsible for closing.

This submission is intended to be apolitical and evidence-led. It examines a broad cross-section of AI’s emerging impacts on Australian infrastructure, institutions, communities, and individuals. It draws upon 108 distinct sources, including legislation, government publications, regulatory material, planning documents, corporate disclosures, academic research, and contemporary legal reporting. Taken together, these sources reveal a fragmented regulatory landscape, struggling to keep pace with the growth of AI.

The scale of the infrastructure challenge is no longer hypothetical. AEMO forecasts National Electricity Market data-centre consumption rising from about 5 TWh, or around 3 per cent of grid-supplied electricity, in 2025–26, to about 34 TWh, or around 13 per cent, by 2035–36. (AEMO 2026a) The Commonwealth has already acknowledged the need for intervention through its Data Centre Expectations, announcing mandatory requirements for large facilities to underwrite new power supply, pay connection costs, and reduce demand when required. (Ayres 2026; DISR 2026a) Equivalent principles are emerging for water. (DISR 2026a; Watt 2026a, 2026b) These are sensible developments, but they must be consolidated into a transparent, nationally coherent statutory regime, rather than remain a series of expectations, sectoral rules, and project-specific negotiations.

The same fragmentation appears across data governance. An Australian organisation can purchase what is advertised as an Australian-region cloud service, while particular features, subprocessors, or AI components process data elsewhere. APP 8 does not impose a simple localisation rule, nor should it be misrepresented as doing so. (OAIC n.d.-a, n.d.-b) But the absence of a localisation rule makes accurate feature-level disclosure more important, not less. The policy question is not merely where our data is stored, and if this is compliant with data sovereignty law. There are thousands of unresolved questions surrounding who can process, access, infer from, or receive information; under what legal basis; and most importantly by far, whether the individuals whose data is at this moment being fed into AI can realistically provide informed consent. 1, 2

This submission uses Genesys Cloud as a case study, because the author has personal experience interacting with Genesys Cloud AI through public services without his informed knowledge or consent.

Helpfully, Genesys’ compliance documentation is unusually extensive. That documentation, ironically, makes the regulatory gaps even more glaring.

Genesys permits Australian regional hosting, publishes AI Product Cards, describes human-in-the-loop mechanisms, and says it does not use customer communications to train shared or third-party foundation models without customer consent. (Genesys n.d.-a, n.d.-b, n.d.-c) At the same time, some of its default or optional services involve US, EU, or global processing. The onus should be on AI vendors to ensure that data sovereignty compliance is opt-in by default. Genesys’ own Agentic Virtual Agent privacy notice describes US-East-1 hosting and US transfers; customer-provided LLM integrations can transmit interaction text to third parties; and the term “consent” refers primarily to the organisational customer, not the individual whose data is actually being processed. (Genesys n.d.-a, n.d.-d, n.d.-e, n.d.-f, 2025, 2026a) 3, 4

These examples show why broad labels such as “Australian hosted”, “customer controlled”, and “with consent” are insufficient substitutes for auditable, traceable data trails.

The Genesys case study concerns information infrastructure. A second case study, the recently approved Bell Bay data-centre in northern Tasmania, concerns physical infrastructure, and exposes comparable regulatory gaps.

Commonwealth and Tasmanian environmental systems are more than capable of examining noise, air, water, biodiversity, and matters of national environmental significance. (ARPANSA n.d.; DCCEEW 2026a; EPA Tasmania n.d.-a, n.d.-b; National EPA n.d.-a, n.d.-b; Olaguer et al. 2016; Tao and Gao 2025; US EPA n.d.) Yet whether the right questions are asked, by whom, and at what level of detail, depends heavily on the assessment pathway triggered by a particular proposal. Nearby comparable projects to the Bell Bay data-centre have generated dedicated protected matters studies and EPBC referrals. (National EPA n.d.-a, n.d.-b) The policy weakness is therefore not that environmental law is unequipped to regulate. It is that one rapidly expanding class of infrastructure, data-centres, can impose cumulative energy, water, noise, generator, land-use, and biodiversity pressures, without a single assessment framework requiring that all those impacts be considered together.

The Committee should therefore treat data-centre regulation as a systems problem. Siloes do not work. The digital solution is API integration. The solution, here, is regulatory integration. 5

Australia needs mandatory baseline infrastructure standards; cumulative impact assessments; mandatory public reporting of energy, water, and environmental performance; feature-level datasovereignty disclosure from AI vendors; transparent procurement and change-control obligations; clear lines of accountability for consequential AI services; and a measurable public-benefit test for AI projects receiving public funding, regulatory facilitation, or privileged access to scarce resources.

That final point matters most. Data centres should not be evaluated only by capital expenditure and temporary construction employment. Public policy should ask what enduring value remains in the community after the building is energised.

Recommendations

1. Set a national, statutory data-centre standard

Legislate a nationally consistent baseline for large data-centres covering energy supply, grid connection costs, demand response, water sourcing and efficiency, backup generation, emissions reporting, environmental monitoring, and community consultation. The Commonwealth’s 2026 Data Centre Expectations provide a starting point. (Ayres 2026; DISR 2026a; Watt 2026a, 2026b)

2. Demand cumulative impact assessments

Require large data-centre proposals and data-centre precincts to assess cumulative electricity demand, water demand, backup-generator emissions, noise, land use, and biodiversity impacts rather than considering each impact through separate approval pathways. Thresholds should be capable of capturing clusters of facilities as well as single large projects. (ARPANSA n.d.; DCCEEW 2026a; EPA Tasmania n.d.-a, n.d.-b; National EPA n.d.-a, n.d.-b; Olaguer et al. 2016; Tao and Gao 2025; US EPA n.d.)

3. Keep a public performance register

Create a mandatory public register for large data-centres, subject to genuine security exceptions, to report: annual electricity consumption, power-use effectiveness, water consumption and water-use effectiveness, source and quality of water, operational emissions, use and scale of offsets, backup- generation capacity, major incidents, and compliance against any grid-flexibility obligations. 6

4. Insist upon precise environmental claims

Require all environmental marketing and procurement claims such as “carbon neutral” or “sustainable” to disclose the operational boundary, material exclusions, estimation methods, assurance level, and role of offsets in a standardised, up-front form — not buried in the small print. (Genesys 2026b; Genesys n.d.-g)

5. Legislate feature-level data-sovereignty disclosure

Require cloud and AI service providers supplying government or consequential services to provide a current and constantly updated feature-level map of storage, processing, support access, subprocessors and optional integrations. “Australian region” should never be treated as synonymous with “Australian-only processing”, unless that is actually what the contract and architecture provide. (Genesys 2026a; Genesys n.d.-a, n.d.-d, n.d.-e, n.d.-f, n.d.-h; OAIC n.d.-a, n.d.-b)

6. Require clear notice, and informed consent wherever consent is required

Wherever AI records, transcribes, summarises, profiles, or materially assists consequential interactions, require clear notice at the point of interaction, and preserve a practical human alternative where appropriate. Affirmative consent should be obtained wherever existing law

requires it. Privacy policies and contracts should not substitute for clear notice to the individuals whose data is actually at stake. (Genesys n.d.-a, n.d.-b, 2025; OAIC n.d.-c, n.d.-d, n.d.-e, n.d.-f)

7. Put agentic AI safeguards in place

Translate ASD’s cautious deployment principles into mandatory baseline controls for high-risk or sensitive uses of agentic AI: least privilege, strong identity, continuous monitoring, human oversight, staged deployment, and strict constraints on access to sensitive information or critical systems. (ASD 2026a, 2026b, 2026c)

8. Ensure that vendors and deployers share accountability

Clarify allocation of responsibility when AI outcomes depend jointly on vendor design, customer configuration, and third-party integrations. Contracts and law should distinguish responsibilities that cannot sensibly be shifted to enterprise customers through configuration choices alone. (Genesys n.d.-b, 2025; Treasury 2024, 2025)

9. Mandate AI change controls in procurement

Require suppliers to notify customers before AI features, subprocessors, processing locations, or model endpoints change. Require enterprise customers to reassess privacy, security and impact assessments before activation. (Department of Finance 2024; DTA 2025a, 2025b; Genesys n.d.-d)

10. Make technology-vendor relationships visible

Require public-sector agencies to record and manage employee participation in vendor-operated advocacy, ambassador, champion, award, or incentive programs where those employees influence technology strategy, implementation, governance, or procurement. Relevant benefits, approvals, declarations, recusals, and conflicts should be recorded. Procurement oversight should also trace material commercial relationships beyond the immediate supplier.

11. All data-centres must pass a public benefit test for scarce resource use

For large facilities receiving public infrastructure, expedited approvals, or access to scarce energy/water capacity, assess enduring local benefits in addition to capital expenditure. Relevant measures should include operational employment, training, local procurement, research access, community infrastructure, and favourable compute access for Australian start-ups, researchers, and not-for-profits. (DISR 2026a; IGEA 2026; Jobs and Skills Australia n.d.-a, n.d.-b; NSW Government 2025; NSW Planning Portal 2022)

12. Pilot a publicly-owned data-centre model

Consider a publicly owned or public-interest compute facility combining secure sovereign compute with research access, digital literacy services, public programming, and a video game preservation archive. Existing Australian cultural, copyright, and labour evidence shows that these functions are institutionally plausible, commercially viable, and could create skilled, public-facing jobs beyond the relatively narrow operational workforce of a closed, private facility. (ADII 2025; Copyright Act 1968 (Cth) ss 113H–113J; eSafety Commissioner 2018, n.d.; IGEA 2025, 2026; Jobs and Skills Australia n.d.-a, n.d.-b; Libraries Tasmania 2026; NFSA 2024, n.d.-a, n.d.-b; NSW Government 2025; Screen Australia 2026)

1. Fragmentation (the core issue)

Australia does not have a regulatory vacuum. It has a regulatory jigsaw, and critical pieces are missing. Privacy law applies to personal information. The Australian Consumer Law (generally) applies to AIenabled products and services. Cyber-security agencies issue technical guidance. Planning and environmental regimes examine physical impacts. The Digital Transformation Agency governs Commonwealth AI use. Specialist regulators retain responsibility within their existing domains. (Department of Finance 2024; DISR 2026b, 2026c; DTA 2025a, 2025c; OAIC 2025; Parliament of Australia 2026; PM&C 2026; Treasury 2025) This distribution does have some advantages, as specialist regulators can possess subject expertise that no single new “AI regulator” could instantly reproduce.

The critical weakness is in the spaces between.

Contemporary AI services are not self-contained software products. They are combinations of models, cloud infrastructure, data stores, subprocessors, telemetry, customer configuration, integrations, and human decisions. A change that appears minor on the surface can alter the entire processing jurisdiction, privacy risk, security boundary, or terms of consent. (Genesys n.d.-d, n.d.-e, n.d.-f, n.d.-h) Legal questions asked by one single regulator about AI describe only a fraction of the whole.

The same is true physically. Data-centres are simultaneously electricity loads, water users, industrial developments, sources of backup-generation emissions and noise, cyber infrastructure, repositories of economically and personally sensitive information, and platforms through which global AI services enter Australian institutions. Treating each attribute as a separate regulatory problem makes it extremely difficult to assess cumulative public cost or benefit.

The Commonwealth has already begun moving toward a more integrated approach. The 2026 Data Centre Expectations expressly address energy, water, community engagement, and access to compute, and the Government has announced mandatory energy obligations for large centres. (Ayres 2026; DISR 2026a; Watt 2026a, 2026b) This Committee must accelerate that trajectory. The objective of this Committee should not be AI deregulation versus AI prohibition. The goal should be to mandate transparency, above all else, and I think everybody on this Committee would agree. Who doesn’t want their personal information, environment, and resources protected? A regulator, enterprise customer, affected community, and individual citizen, no matter their level of digital literacy, should be able to understand exactly what an AI project consumes, how it benefits them, where their data moves, who is responsible for protecting their privacy, and what happens when configurations in the system change. Otherwise, they cannot provide informed consent to having a data-centre in their backyard.

2. Copyright (the elephant in the room, getting very tired of being ignored)

The expansion of AI infrastructure is rapidly being allowed to occur while the most basic legal question underlying generative AI remains unresolved.

On what terms may copyrighted works be used to train commercial AI systems? Australian copyright law gives copyright owners exclusive rights, including reproduction of protected works. (AGD n.d.; Copyright Act 1968 (Cth) s 31) The Commonwealth itself acknowledges unresolved “legal uncertainties” and “regulatory gaps” at the intersection of AI and copyright, and in 2025 expressly declined to introduce a general text-and-data-mining exception while continuing work on

licensing, AI outputs and enforcement. (AGD 2025a, 2025b) The current Joint Select Committee on Artificial Intelligence has likewise been expressly directed to examine copyright, and the use of Australian creative, cultural and media content in AI training. (Parliament of Australia 2026)

Australians are entitled to question any substantive infrastructure being constructed to support an industry whose treatment of copyrighted material remains the subject of active litigation.

In the United States, proceedings brought by the New York Times and other publishers against OpenAI and Microsoft remain active as of 2026. (Reuters 2026a) WikiHow commenced a further action against OpenAI in August 2026, alleging unauthorised scraping and use of thousands of its instructional articles for AI training. (Reuters 2026b) These are allegations, not findings, and United States copyright law is not Australian copyright law. Their relevance is nevertheless incredibly difficult to dismiss. Why on Earth is the Australian Government facilitating unprecedented investment in AI infrastructure, before it has resolved whether, when, and how creators and artists should be compensated for the use of copyrighted works in commercial AI training?

Australia should not wait for years of overseas litigation to determine its own cultural policy.

If commercial AI creates demand for increasingly large amounts of Australian electricity, water, land, and infrastructure, while deriving substantial value from vast quantities of human cultural production whose lawful use remains contested, public policy should ensure that the resulting infrastructure returns enduring value to the cultural commons.

This is the underlying rationale for the public-access data-centre model proposed in this report.

Public compute capacity could support libraries, archives, the NFSA, universities, researchers, artists, and Australian cultural institutions; preserve digital art that is facing extinction; and provide licensed public access to culturally significant digital material.

This would not resolve the copyright issues surrounding AI training, nor would it constitute legal compensation for any alleged infringement. It would, however, establish a principle of reciprocity.

An infrastructure transformation built upon mass data-scraping of human knowledge and culture should help preserve that culture, nourish it, and ensure it remains accessible to future generations.

3. Environment (energy, water, health, and wildlife impacts are the same issue)

AEMO’s current forecast should end any argument that data-centres are merely another ordinary commercial load. It projects NEM data-centre consumption rising from about 5 TWh in 2025–26 to about 34 TWh by 2035–36: from around 3 per cent to around 13 per cent of grid-supplied electricity. (AEMO 2026a) AEMO has introduced dedicated forecasting precisely because data-centre demand is large, complex and rapidly growing. (AEMO 2026b)

Projected NEM data-centre electricity consumption: 5 TWh in 2025–26 and 34 TWh in 2035–36.
Figure 1. Projected NEM data-centre electricity consumption. Source: AEMO (2026a).

The Government’s response is directionally sound, but implementation is not keeping pace with approvals. Its Data Centre Expectations say developers should secure additional clean generation or storage, cover an appropriate share of grid costs, minimise energy demand and emissions, support grid security, and provide demand flexibility. (DISR 2026a) Yet these expectations do not equate to a nationally enforceable baseline, which is what infrastructure of this scale requires.

In July 2026, the Government announced planned legislation requiring large centres to underwrite new power supply, pay full connection costs, and reduce power when required. (Ayres 2026) The principle is straightforward: the cost of integrating a very large new load should not be silently socialised onto households and other industries. The fundamental problem is, this legislation has not come into effect, but data-centres that do not meet the requirements are nonetheless still being approved.

Water requires the same discipline. The national Expectations call for locally appropriate and secure water sources, efficient cooling, non-potable or circular water where possible, cost-sharing, and transparent reporting. (DISR 2026a) In August 2026, the Commonwealth said that Tasmania (the author’s state), along with most jurisdictions, had agreed to proposed minimum standards prioritising reduced use, recycled or non-drinking water, and transparent reporting, with federal legislation intended. (Watt 2026a, 2026b) These principles must become measurable public reporting obligations, as swiftly as possible, with common definitions.

As for other environmental concerns, EPA Tasmania recognises that environmental noise can impair work, leisure and sleep, and assesses nuisance through intensity, duration, timing, location and effect. (EPA Tasmania n.d.-a, n.d.-b) Ergo, the methods already exist to monitor compliance, so compliance can easily be monitored. Data-centres also commonly rely on stationary combustion engines or turbines for backup power; the US EPA regulates these as air-emission sources, and modelling literature identifies potentially material local NO2 effects from banks of diesel generators. (Olaguer et al. 2016; US EPA n.d.) The available community-health literature remains limited, which is itself a reason for more monitoring, rather than a reason to assume there is no impact. (Tao and Gao 2025)

The evidence does not support sensational claims about every possible exposure. ARPANSA states that there is no established evidence that ordinary, extremely low-frequency electromagnetic-field exposure around homes, offices, or powerlines causes long-term health effects. (ARPANSA n.d.) Yet that does not mean that ongoing investigation is unwarranted. Environmental transparency should measure all community concerns and potential exposures, compare them with standards, continuously monitor them, and update advice whenever evidence changes.

Biodiversity and nationally significant environmental matters add another complex layer. Commonwealth guidance makes it clear that projects capable of significantly affecting protected matters may require EPBC referral. (DCCEEW 2026a) Australian data-centre projects have already entered that system. The 96 MW Huntingwood proposal, and an 800 MW Bundey campus, provide recent examples. (National EPA n.d.-a) A more salient example of markedly different assessment expectations and pathways is the proposed Firmus 288 MW data-centre in Bell Bay, Tasmania. 7

4. Physical infrastructure case study: Bell Bay (aka, nationally protected species do not vanish simply because an area is industrially zoned)

Firmus Technologies’ proposed Bell Bay data-centre is a useful comparative case, because the surrounding industrial landscape is already subject to substantial environmental scrutiny. Equis’ Bell Bay Wind Farm is undergoing Commonwealth assessment, and its referral material includes dedicated analysis of matters of national environmental significance, supported by flora, fauna, bird and bat studies. (National EPA n.d.-b) Protected-matters material for the area also records the 2007 Gunns pulpmill proposal in the Bell Bay area as a controlled action under the EPBC Act. The current Firmus project is proposed for the former Gunns pulp-mill site (Firmus 2026; National EPA n.d.-b)

Yet the Bell Bay data-centre proposal has not been referred under the EPBC Act. That fact does not establish that referral is legally required, but it produces a striking contrast with other major developments in the area that have entered the Commonwealth assessment system.

Firmus, unlike Equis, did not seek referral.

Environmental scrutiny therefore depends strongly on the regulatory pathway that a project triggers, or that which a proponent elects to enter. Equis, which is developing a renewable-energy project, sought EPBC referral; Firmus did not. If the proposed Bell Bay data-centre is to include 276 backup diesel generators, as the council assessment material records (ABC 2026), that scale only strengthens the case for a nationally consistent framework capable of examining cumulative impacts.

288 MWproposed Bell Bay capacity
162Backup diesel generators — originally declared by Firmus
276Backup diesel generators in revised DA — +70% from number originally reported

Sources: Firmus (2026); ABC (2026).

For infrastructure of this scale, the regulatory question should not be, “in which narrow zoning category does this project fit”, but “what physical and environmental footprint will this project create, and what public infrastructure must also exist because it is here?” A nationally consistent, thresholdbased data-centre assessment framework would make those questions unavoidable, while leaving ordinary planning and environmental laws intact.

This matters particularly in regions being asked to host infrastructure serving global markets. Firmus’ specific customers proposed for the Bell Bay site have not been publicly identified. Local communities, however, bear the physical consequences: land occupation, water demand, construction impacts, noise risk, and opportunity cost. The benefits of the data-centre may be real, but they must be demonstrated, rather than assumed. Capital expenditure is not a valid measure of local wellbeing.

The Bell Bay case study reveals an obvious contradiction in the order in which Australia is accelerating infrastructure. The Australian Government has committed to 82 per cent renewable electricity generation by 2030 (DCCEEW 2025), while rapidly growing data-centre demand will require enormous quantities of additional electricity. Renewable-energy projects must, quite rightly, undergo environmental assessment where required. But if compliance with those processes delays the renewable generation that Australia says it urgently needs, while new data-centres capable of

consuming that generation proceed more quickly through different approval pathways, our regulatory system has its priorities backwards. While mandatory data-centre standards and new AI regulatory architecture are still being developed, Australia should be accelerating the renewable generation required to meet existing commitments, not accelerating gargantuan drivers of electricity demand.

This is not an argument that data-centres should never be built.

It is an argument for building things in a logical order.

5. Data sovereignty (is not static)

Discussions of “data sovereignty” are frequently reduced to the physical location of a server. Australian privacy law is significantly more complicated than that. OAIC distinguishes overseas ‘disclosure’ from overseas ‘use’ under an entity’s effective control, (OAIC n.d.-a) which makes simplistic statements such as “the data is hosted in Australia, therefore it stays in Australia” particularly unhelpful.

A modern cloud service can store a core tenant in Sydney, while telemetry, security services, speech processing, support, or optional AI features process in other jurisdictions. The relevant public-interest questions are therefore: where is information stored; where is it processed; who may access it; which subprocessors receive it; what metadata is exported; what optional features alter those answers; and who remains legally accountable for privacy breaches? 8

Where consent is relied upon for cross-border disclosure, OAIC requires the individual to be expressly informed of the consequences. Consent must be informed, voluntary, current and specific. (OAIC n.d.-a) This is very difficult to reconcile with the generic, bundled or invisible processing arrangements offered by contemporary AI vendors. The more modular the AI service, the more important it becomes to communicate the precise security consequences of enabling a particular module.

6. Data infrastructure case study: Genesys Cloud (aka, nice privacy documentation, still inadequate to enforce individual rights)

As previously stated, Genesys publishes a great deal of compliance documentation. Genesys’ public materials say that customers choose a tenant region, customers retain ownership and control of their data, and that customer communications are not used to train shared or third-party foundation models without customer consent. AI Product Cards describe models, training-data scope, benchmarks and limitations; and human-in-the-loop mechanisms are incorporated into products such as Agent Assist and Copilot. (Genesys n.d.-a, n.d.-b, n.d.-c)

These are far less substantive governance claims than they appear to be at first glance, because of a subtle linguistic ambiguity.

‘Customer’, for Genesys, does not mean the individual citizen whose data is being processed.

It means the organisation who has bought into Genesys’ services.

Genesys lists AWS in-region hosting but also default US-based subprocessors for specified telemetry and cyber-security functions, while optional speech and bot services have feature-dependent regional

arrangements. (Genesys n.d.-a, n.d.-e, n.d.-f, n.d.-h) Its June 2026 notice for its own Agentic Virtual Agent states that the service is hosted in AWS US-East-1 and that personal data may be transferred to the United States. (Genesys 2026a) Customer-provided LLM functionality can send interaction text and related fields to a customer-selected third party. (Genesys n.d.-d)

This does not make the phrase “Australian region” false. It makes the phrase incomplete. Australianhosted is not necessarily Australian-processed, Australian-only-accessed, or Australian-controlled.

A procurer should be required to know, and publicly declare, which proposition it has actually bought.

The word “consent” illustrates a second ambiguity. Genesys states that it processes customer data with “your consent” in order to provide selected services. (Genesys n.d.-a) “You”, once again, means the organisational customer. Organisational consent is not the same thing as informed consent from the individual whose data is being processed, who may not even know that AI has access to their data. Genesys’ processor model allocates many direct privacy obligations to its organisational customers, (Genesys 2025) but the customers of the customer, those whose privacy is actually at stake, have little to no say in how and where their data is processed.

One recent legal case underlines why this distinction matters.

Genesys publicly promotes its implementation within the US National Domestic Violence Hotline as providing “100% availability with complete confidentiality”, while describing voicebot/chatbot and AI automation. (Genesys n.d.-i) In 2025, however, three users sued Genesys alleging interception, recording, and analysis without consent. In July 2026, a proposed US$2.5 million class settlement was reported. (Bloomberg Law 2025, 2026) A settlement is not a finding of liability and must not be misrepresented as one. Nor does US litigation establish a breach of Australian law. The policy relevance, though, is immediately apparent. A person can interact with an essential service and provide exceptionally sensitive data, while the legal and technical allocation of data-processing responsibility is invisible to them.

Documented Australian users of Genesys’ services — which include contact-centre technologies, not just AI — include the below public-sector, publicly funded, and community-service organisations.

§ Anglicare Sydney (Genesys n.d.-t) § Better Regulation Division (Digital NSW n.d.) § Central Coast Council (Digital NSW n.d.) § Charles Sturt University (Genesys n.d.-o) § City of Newcastle (Genesys Community 2026) § City of Wollongong (City of Wollongong 2024) § Fair Work Ombudsman (pilot) (Fair Work Ombudsman 2026) § Hobsons Bay City Council (Telstra n.d.) § icare NSW (Digital NSW n.d.) § Lifeline Australia (Lifeline Australia 2025) § Northern Beaches Council (Genesys n.d.-q) § NSW Department of Communities and Justice (Genesys n.d.-p) § NSW Department of Customer Service (Digital NSW n.d.) § NSW Department of Education (Digital NSW n.d.) § Revenue NSW (Digital NSW n.d.) § SafeWork NSW (Digital NSW n.d.)

§ The Salvation Army Australia (Genesys n.d.-s) § Service NSW (Digital NSW n.d.) § State Insurance Regulatory Authority (SIRA) (Digital NSW n.d.) § Super SA (Super SA 2021) § Transport for NSW (including 131 500) (Digital NSW n.d.) § Western Sydney University (Genesys n.d.-r) § World Vision Australia (Genesys 2026e)

The NSW Government’s Genesys-based Virtual Contact Centre alone supports 15 million calls annually. (Digital NSW n.d.)

This concentration raises a legitimate resilience question. How much essential and community-service infrastructure should depend upon a single vendor ecosystem? What if something breaks?

Genesys’ environmental claims provide yet another example of why AI’s infrastructural, privacy, and environmental impacts cannot be considered separately. The company says Genesys Cloud operations have been carbon neutral since FY25; its supporting material then identifies estimated AWS and internal-computing emissions, exclusions, residual carbon credits, and different assurance levels across scopes. (Genesys 2026b; Genesys n.d.-g) A claim such as “carbon neutral” is only useful when the reader can readily see what was counted, what was estimated, what was excluded, and what was offset.

If a comparatively well-documented enterprise platform still requires a technically literate individual like myself to traverse dense privacy policies, trust-centre material, subprocessor lists, feature documentation, regional mappings, and product cards to reconstruct a single data flow, existing disclosure practices plainly do not work for ordinary, affected individuals trying to understand how their data has been handled.

Regulation must make AI privacy architecture legible, auditable, and traceable, on an individual level.

7. Genesys/AWS (or, the integrity concerns arising from interconnected vendors)

The Genesys case study exposes yet another weakness in Australia’s AI policy (or lack thereof): procurement oversight. Government may contract with one technology company, but the benefits of that decision flow upstream to several others.

Genesys and Amazon Web Services (AWS) have an extensive and open strategic relationship. Genesys describes AWS as a global strategic alliance partner, and Genesys Cloud is built on AWS.

Genesys states that Genesys Cloud expenditure can be applied towards an organisation's AWS enterprise cloud commitment. (AWS n.d.; Genesys n.d.-j) Genesys and AWS also market jointly to the public sector; Genesys reports more than 4,000 joint customers. (Genesys n.d.-k) In July 2026 the companies announced an expanded strategic collaboration intended to accelerate agentic AI, global availability, and joint go-to-market activity. (Genesys 2026c)

This relationship already intersects directly with Australian public infrastructure.

The Commonwealth has welcomed AWS’ announced $20 billion investment in Australian data-centre infrastructure over five years. (Prime Minister of Australia 2026) Separately, the Digital Transformation Agency entered a new whole-of-government AWS arrangement in 2025, and reported that more than 140 Commonwealth, state and territory public-sector agencies were already using AWS. (DTA 2025d)

$20bannounced AWS Australian data-centre investment
140+Australian public-sector agencies using AWS
4,000+joint Genesys/AWS customers reported by Genesys

Sources: Prime Minister of Australia (2026); DTA (2025d); Genesys (n.d.-k). Different measures; presented together only to illustrate ecosystem scale.

In NSW, the interdependence is not merely theoretical. Revenue NSW’s procurement documentation for Genesys Cloud data services expressly sought near-real-time access to Genesys data and integration with Revenue NSW’s existing AWS-based data infrastructure. (Revenue NSW 2025)

Let’s be clear. Strategic partnerships are normal commercial arrangements. Governments require cloud infrastructure (of course, you guys could just … build your own, if you made sovereign datacentres civic infrastructure, but we’ll get to that). Integration between compatible services can produce genuine efficiencies. But the Genesys/Amazon interdependency demonstrates why government cannot assess technology vendors as isolated entities. Adoption of one platform may generate dependence upon, increased consumption from, or commercial benefit for another. At sufficient scale, these relationships can compound into infrastructure concentration and vendor lock-in.

The Genesys/AWS partnership provides a concrete illustration of why procurement concerns must be part of the jurisdiction of the Office of AI. Australia’s growing dependence upon AI should not quietly become a dependence upon a tiny number of vertically interconnected technology ecosystems.

There is a second, more immediate, integrity question.

Genesys operates an individual customer advocacy program known as the “Genesys Orchestrators” scheme. Its own terms describe the program as one intended “to incentivize advocacy participants”. (Genesys n.d.-l) Participants can earn points through engagement and redeem them for benefits including event or conference passes, training and certifications, branded products, and professional services. (Genesys n.d.-m) Genesys’ Global Advocacy Program Lead has publicly explained that pointgenerating activities can include speaking at breakout sessions. (Genesys Community 2026) Within the broader Orchestrators awards program, eligible participants may compete for benefits including airfare to the Genesys Xperience conference, accommodation, event access, and associated experiences, alongside agreement to participate in promotional material. (Genesys 2026d)

Mere participation in such a program is not necessarily evidence of misconduct.

Vendor communities can disseminate expertise, recognise excellent work, and create legitimate professional development opportunities.

But an incentivised vendor-advocacy relationship involving a public official, who may influence technology strategy, implementation, or procurement, is plainly capable of creating an actual, potential, or perceived conflict of interest.

The appropriate regulatory response is not to assume corruption. It is to make relevant relationships visible, and manage actual, potential, or perceived conflicts before they become integrity failures.

NSW’s own integrity rules recognise the underlying risk with vendor advocacy programs. NSW procurement guidance states, as a general rule, that government personnel must never accept gifts or benefits from suppliers. (NSW Government n.d.-a) The NSW Independent Commission Against Corruption warns that gifts and benefits can create perceived influence, indebtedness, conflicts between public duty and personal interests, and reputational damage, even where benefits are comparatively modest. (ICAC n.d.) The NSW Supplier Code of Conduct encompasses financial and nonfinancial benefits and expects disclosure of real or perceived conflicts. (NSW Government n.d.-b) The integrity question is simple.

Do existing disclosure systems actually capture the sorts of benefits and relationships created through contemporary technology-vendor advocacy programs?

The evidence that I have reviewed for this submission does not establish that any NSW official improperly accepted a benefit, failed to make a required declaration, influenced a procurement decision, or acted corruptly. Those facts are not ascertainable from what I have been able to access.

Government, however, can access more than I can.

For public officials involved in technology procurement, governance, or implementation, agencies must be able to identify participation in vendor-operated advocacy, ambassador, champion or incentive programs; benefits offered or received; relevant approvals and declarations; recusals from procurement or governance decisions; and material procurements involving both the immediate vendor and its strategic commercial partners.

If those records show that every relevant relationship was declared and appropriately managed, that would be evidence that the integrity system is working. If agencies do not even know which of its employees participate in incentivised vendor-advocacy programs, that is its own governance problem.

A broader principle should therefore be incorporated into Commonwealth and state technology procurement: trace the commercial relationships beyond the company name printed on the contract.

Public-sector probity frameworks designed around a purchaser and a single supplier are increasingly ill-suited to an AI market composed of cloud providers, SaaS platforms, model providers, implementation partners, subprocessors, and strategic alliances whose financial interests overlap. 9

At a time when tens of billions of dollars are being invested in Australian compute infrastructure, perceived conflicts should not have to become proven scandals before government decides they are worth recording and examining.

8. Procurement (is one of the Commonwealth's strongest regulatory levers)

The Commonwealth does not need to wait for a perfect, economy-wide AI statute before improving outcomes in the services it is already purchasing. Existing government assurance guidance already expects AI procurement contracts to address ethics, accountabilities, data transparency, information access, and lifecycle performance. (Department of Finance 2024) The APS AI Plan is developing AIspecific procurement pathways and contract clauses requiring suppliers to disclose planned AI use and clarify accountability. (DTA 2025a) DTA has also identified the practical problem of AI features being introduced into products without sufficient prior notice or guidance. (DTA 2025b)

Given that Commonwealth procurement involved 86,926 AusTender contracts worth $104.90 billion in 2024–25, it should be obvious that procurement standards can heavily influence vendor behaviour, well beyond individual agencies. (Department of Finance 2026) A mandatory contract schedule for consequential cloud/AI services should therefore record data location(s), processing location(s), subprocessors, model providers, training uses, retention, support access, assurance status, and material feature changes. New features should trigger reassessment, in case data flows or risk levels change.

$104.90bCommonwealth contract value, 2024–25
86,926AusTender contracts, 2024–25

Source: Department of Finance (2026).

This is also a better allocation of administrative burden. An individual citizen (this author) should not need to reverse-engineer an enterprise contact-centre architecture, and submit a paper to a Senate Committee, merely to understand how and where AI may have interacted with his own private data. Government purchasers and regulated organisations have the negotiating power to require legible data-governance arrangements from vendors before deployment.

9. Agentic AI (raises the stakes)

Agentic AI dramatically raises AI’s risk profile, because it can do more than just generate responses. ASD and its international partners describe distinct security, governance, and accountability risks arising from autonomy and interconnected architecture. (ASD 2026a) Their guidance recommends incremental deployment, strict privilege controls, continuous monitoring, strong identity management, human oversight, and restricting early use to low-risk, non-sensitive tasks. (ASD 2026b) 10

Why, then, does Genesys advertise Charles Sturt University as deploying agentic AI for the below?

For example, after hours a student can ask the AI Guides powered virtual agent about withdrawing from a course. Rather than simply outlining the process, the Agent explores what is driving the question. If the student is experiencing financial pressure or competing life commitments, the Agent can suggest relevant options, such as support to help manage cost of living pressures, information about scholarships, or reducing study load to better balance work, family and study.

– Verbatim, from Genesys’ promotional material. (Genesys n.d.-o)

I would personally rather not give an AI agent information about my cost-of-living pressures, thank you very much. I would consider that a sensitive task, and I would prefer it be handled by a human.

In July 2026, ASD highlighted testing in which advanced agentic models accessed information outside their intended environment and exploited a previously unknown vulnerability. (ASD 2026c) The lesson is not that agentic systems should be prohibited altogether. It is that granting AI services the ability to act across systems can exponentially change the run-on consequences of a mistaken permission, compromised identity, prompt injection, model error, or poorly understood integration. 11

(Genesys n.d.-n) Genesys’ Australian customer material provides a concrete example of agentic AI being deployed in education, while its broader Australian customer base demonstrates how extensively Genesys technologies are already embedded across consequential service environments. (Digital NSW n.d.; Genesys n.d.-n, n.d.-r) Not every Genesys deployment is agentic AI, but agentic deployment in consequential Australian service environments is no longer hypothetical.

The Committee should therefore rapidly enforce mandatory safeguards wherever agentic systems touch sensitive information, essential public services, or critical operational systems.

10. Public benefit (should be measured after construction ends)

Data-centre developments are commonly presented (sold to us, the public, largely unsuccessfully) in terms of capital investment and construction employment. Those figures obscure the long-term employment intensity of the completed facilities. A 144 MW Sydney proposal expected approximately 300 construction jobs but only 50 operational jobs. (NSW Planning Portal 2022) A $3.1 billion, 504 MW data-centre campus approved at Marsden Park is projected to support 265 operational jobs across six data-centre buildings. (NSW Government 2025) This is approximately 0.53 direct operational jobs per MW of capacity. Both these examples demonstrate that while very large data-centres can create skilled permanent employment, their direct operational employment intensity remains modest relative to their capital costs, physical footprints, and resource requirements.

$3.1bMarsden Park capital investment
504 MWapproved campus capacity
265projected operational jobs

Source: NSW Government (2025). These values illustrate project scale; capital investment is not treated as a causal “cost per job” measure.

When governments facilitate access to scarce electricity, water, land, or enabling infrastructure, they must ask what continuing, long-term public value the project returns. The Government has already moved in this direction by saying that large-scale compute providers should benefit local communities and enable favourable compute access for Australian start-ups, researchers and not-for-profits. (DISR 2026a) That expectation must become measurable.

Employment is one such measure. Jobs and Skills Australia records 11,900 librarians and 9,800 archivists, curators, and records managers in Australia. (Jobs and Skills Australia n.d.-a, n.d.-b) Australia’s video game development sector also supports thousands of skilled jobs and brings in substantial revenue. (ABS 2023; IGEA 2026; Screen Australia 2026; Treasury 2022) These are both sectors that could materially benefit from the compute infrastructure of AI data-centres.

Australian workforce scale comparison: data-centre operations and information/cultural professionals.
Figure 2. Workforce scale.

11. The solution (sovereign compute as civic infrastructure)

It should be a mandatory condition that at least some capacity within data-centres be designed as civic infrastructure, rather than fenced industrial infrastructure. A public-interest data centre could combine secure sovereign compute for government, research, and approved public-interest uses with a digital preservation facility, plus public digital literacy services, education, exhibitions, research access, and potentially (the processing power is there) a national video game archive, providing a lawful preservation pathway for culturally significant games that currently survive primarily through piracy.

Public-facing functions can be physically separated from secure compute while sharing a campus, power infrastructure, specialist staff, and an institutional mission. The proposed model is thus akin to a national library, archive, museum, and research-computing facility built around digital collections.

There is already a national cultural mandate to preserve digital art. The NFSA is building a national video game collection and preserves not only playable titles but source code, prototypes, design documents, art, publicity material, hardware, and other digital artefacts. (NFSA n.d.-a, n.d.-b) Its international preservation work reports that more than 96 per cent of classic Australian video games are critically endangered, and that cultural organisations frequently lack dedicated staff, financial resources and technical/legal access. (NFSA 2024, 2026)

>96%of classic Australian video games are critically endangered

Source: NFSA (2026).

Australian copyright law already provides preservation and research pathways for qualifying libraries and archives to collect video games, including controlled on-site access in specified circumstances. (Copyright Act 1968 (Cth) ss 113H–113J) Ordinary recreational access would generally require negotiated permission or licensing where no exception applies. (AGD n.d.) That is a design challenge, not a reason to abandon the concept. Government could pilot institutional concurrent-use licences with game publishers, developers, and platform holders while maintaining classification and age-access obligations. (Australian Government n.d.)

This solution also addresses the growing digital divide.

The 2025 Australian Digital Inclusion Index reports that 20.6 per cent of all Australians are excluded or highly excluded from technology, rising dramatically among people aged 75 and over; regional gaps remain substantial, and generative-AI use is distributed unevenly by age, education and occupation. (ADII 2025) eSafety research shows strong demand among older people for face-to-face assistance with technology. (eSafety Commissioner 2018, n.d.) Libraries Tasmania similarly identifies trusted local hubs, training quality, infrastructure, and familiar frontline services as central to inclusion. (Libraries Tasmania 2026)

Digital exclusion in Australia: 20.6 per cent for all Australians and 66.5 per cent for people aged 75 and over.
Figure 3. Digital exclusion in Australia. Source: Australian Digital Inclusion Index (2025).

A publicly accessible data-centre campus could therefore make the social bargain visible.

The community surrounding such a data-centre would not merely host machines that disproportionately consume local electricity and water for non-local stakeholders. It would gain a public space where people can learn how contemporary digital systems work, access cultural collections, receive practical digital literacy assistance, entertain themselves, participate in research and public programming, and work in skilled technical, archival, educational, and curatorial roles.

Such a facility would not replace private investment. It would exist alongside it. It would provide a benchmark for what public value can look like, and it could also receive contributions from private operators through community-benefit obligations, compute allocations, research partnerships, and licensing support. There are genuine economic, cultural, and reputational incentives for private companies to support and finance public digital preservation projects.

If Australia is to devote a rapidly growing share of its electricity to computation, a portion of that computation must be unmistakably for the benefit of Australians.

12. What I am not claiming

The evidence reviewed for this submission does not establish that all overseas cloud processing breaches APP 8; it does not. (OAIC n.d.-a, n.d.-b) It does not establish that ordinary electromagnetic-field exposure from data-centre-related electrical infrastructure causes long-term health effects; ARPANSA says no such effect has been established. (ARPANSA n.d.) It does not establish that every AI-enabled product requires new product-safety law; Treasury considers the existing ACL generally capable, while recognising areas for clarification. (Treasury 2024, 2025)

Nor does the evidence available to me establish that Genesys has breached Australian law, that its “carbon neutral” claim is legally misleading, or that the US$2.5 million National Domestic Violence Hotline settlement was an admission of liability. The point of the Genesys case study is not to manufacture wrongdoing. It is to demonstrate how the complexity of AI infrastructure can obscure the most basic question for individual citizens forced to interact with AI-enabled services:

“Is my private data safe?”

Similarly, the existence of EPBC assessment for nearby or comparable projects does not prove that the Bell Bay data-centre proposal requires referral. (National EPA n.d.-a, n.d.-b) I would just like to know why two major infrastructure projects in the same industrial region face materially different levels of environmental scrutiny, even where protected matters are known to occur in the broader area.

13. Conclusion

This Committee has a once-in-a-lifetime opportunity to make AI transparent.

The urgency cannot be overstated. Agentic AI has raced into essential services. Mandatory standards, cumulative environmental assessment, transparent resource reporting, feature-level data-flow disclosure, agentic AI safeguards, procurement change control, and measurable community benefits would not deter useful AI deployment. These safeguards would simply make the costs, responsibilities, and consequences of AI visible before they further impact communities, consumers, and regulators.

Data-centres will earn public legitimacy once their proponents can demonstrate that they are environmentally supportable, secure, accountable, and socially useful.

The burden is on AI service providers to demonstrate those benefits clearly.

A regulatory system that requires an aggrieved member of the public to assemble unsatisfying answers from countless planning files, privacy policies, subprocessor lists, technical documentation, and marketing small print is not transparent simply because all of those documents happen to exist, and because this author is fortunate enough to be digitally literate enough to decipher them.

This was exhausting.

Appendix A: About the author

I am an Australian library and information services professional with a background in data analysis, information management, and bookselling. I hold a Bachelor of Arts and Social Sciences with First Class Honours from UNSW, as well as a Diploma of Library and Information Services. My professional experience includes, but is not limited to: public library work, private sector procurement, managing product and bibliographic data, data visualisation, digital literacy teaching, and freelance editing.

I am an active member of the Australian Library and Information Association (ALIA). I felt morally compelled to make this submission in order to maintain ALIA’s values: most pertinently, the free flow of information and ideas in support of Australian culture, democracy and society; dedication to fostering reading, information and digital literacies; high standards in information provision; adherence to information privacy principles; management, organisation and preservation of the human record; and upholding the principles of Article 19 of the Universal Declaration of Human Rights .

My formal library and information services training included ALIA-accredited, nationally recognised units of study directly relevant to the contents of this submission. The most applicable are BSBINS602 — Extend own information literacy skills to locate information , which taught me to critically evaluate the credibility and relevance of sources, and compile reference lists and bibliographies according to various referencing styles; BSBINS504 — Maintain Digital Repositories , which is why I know on a technical level that a public-access data-centre is eminently practical as a digital archive, and finally, BSBINS503 — Monitor compliance with copyright and licence requirements , which speaks for itself.

This submission is made in a personal capacity as a private citizen. It is intended to be apolitical and relies on established facts drawn from publicly accessible sources. It does not represent the views of ALIA, any of my current or former employers, or anybody apart from myself.

Appendix B: AI transparency statement

This entire report was produced in under 48 hours alongside work and domestic commitments.

I directly consulted every single source cited with my own human eyes.

AI, which is a fascinating digital tool, helped me extensively in preparing this submission.

I also did not trust it.

AI — specifically, OpenAI’s ChatGPT (GPT-5.6 Sol) — proved indispensable in locating sources, refining research questions, comparing documents, organising evidence, identifying connections between policy areas, and assisting with structuring and drafting the final report. I could not have produced this submission – at least, not before the deadline – without AI assistance. However, every claim that I relied upon, I independently traced back to its source, to be certain that nothing had been hallucinated.

Every factual claim made in this report has been verified by a human with a literature degree.

Throughout my research process, I kept an evidence register (spreadsheet) recording all relevant sources and claims. This register is available upon request, because any research using public sources, intended to inform public policy, should be open to public scrutiny. With considerable assistance from ChatGPT, I wrote a Visual Basic macro to make opening source URLs and checking evidentiary claims faster. Mindless repetition was automated. Truth-seeking was not.

This submission is therefore also an experiment in what AI, which I am clearly not inherently against, can now make possible for trained, ethical, and digitally literate independent researchers.

Relatively simple, non-AI tools, which don’t require gobbling up vast amounts of energy — macros, organised spreadsheets, and effective research questions — can, when combined with rapid AI-assisted search and optical character recognition (OCR) analysis, substantially increase the amount of primary evidence that an individual can locate, organise, and review within a limited period.

The speed at which I gathered and reviewed this evidence has significant implications for the Australian Government as well as for individual advocacy. I, one very determined and motivated constituent, produced this report in under two days with a budget of approximately $0, ample Mi Goreng, and a second-hand MacBook with a failing battery. I did this because I have a deeply personal stake in AI transparency, as well as ongoing AI-related complaints with the NSW Information and Privacy Commission, the Australian Human Rights Commission, and other regulatory bodies.

Meanwhile, national, integrated AI regulation is somehow four years behind.

Appendix C: VERITAS

This submission was compiled using VERITAS (Verified, Empirical, Reproducible, Information Transparency & Analysis System) , an AI-assisted, human-verified research methodology originally developed by the author, in collaboration with OpenAI’s ChatGPT (GPT-5.6 Sol), for private research.

VERITAS combines AI-assisted rapid searching, document analysis, and optical character recognition (OCR) with structured data collection, human verification, and judgement. Its purpose is not to replace human research, but to use digital tools to accelerate the parts of research where these tools perform reliably well, while retaining human accountability for interpretation and final conclusions.

For this project, potentially relevant claims and sources were identified through both conventional and AI-assisted searching, then were recorded in a structured evidence register. AI was used extensively to locate sources, compare documents, extract and organise information, identify relationships between evidence, test lines of inquiry, and assist with drafting, editing, and formatting. No AI-generated statement, summary, or interpretation was admitted as evidence. Every factual claim relied upon in this submission has been human-verified against its underlying source.

That is to say, all pertinent evidence was manually read with two human eyeballs. The author opened the source URL, located the relevant passage, claim, or statistic, and examined sufficient context to determine whether the claim was supported. Basic macros were used to accelerate repetitive navigation through the evidence register. The decision to accept evidentiary claims remained human.

As an environmental consideration, VERITAS mandates an Energy Expenditure Rule . This decrees that AI computation should be limited to the smallest practical unit of work required to advance research. Wherever reasonable, conventional search, deterministic software, spreadsheets, scripts, previously verified information, and direct human review are preferred to wasteful generative computation. This is a proportionality principle, rather than an absolute prohibition. The unusually compressed preparation period for this submission required substantially greater AI assistance, particularly when it came to drafting prose, than would ordinarily be preferred by this author.

Approximation, projection, and uncertainty were retained, rather than allowing generative AI to convert ambiguity into false yet confident precision. Interpretive conclusions were rigorously distinguished from empirical claims. Final responsibility for source selection, verification, accuracy, analysis, argumentation, and recommendations remains with the author.

This is what transparent, ethical, and informed use of AI can look like.

Technical term endnotes

  1. Subprocessor: a person or organisation that processes personal data on behalf of another processor; Genesys, a significant AI vendor operating in Australia, defines its subprocessors as persons or bodies processing personal data on behalf of Genesys. (Genesys n.d.-e)
  2. APP 8: Australian Privacy Principle 8, which governs cross-border disclosure of personal information. (OAIC n.d.-a)
  3. LLM: large language model. (NIST 2026)
  4. Foundation model: a model trained on broad data that can be adapted for a variety of downstream tasks. (NIST 2026)
  5. API: application programming interface — a defined interface through which software or code accesses specified functionality. (NIST 2026)
  6. Power-use effectiveness (PUE): compares total data-centre energy use with the energy used by IT equipment. Water-use effectiveness (WUE): relates site water use to IT-equipment energy use. (US Department of Energy 2019)
  7. EPBC: Environment Protection and Biodiversity Conservation. An EPBC referral is the process for determining whether a proposed action may require Commonwealth assessment under the Environment Protection and Biodiversity Conservation Act 1999 (Cth). (DCCEEW 2026a)
  8. Telemetry: measurement data collected and transmitted for remote monitoring, interpretation or recording. (NIST 2026)
  9. SaaS: software as a service — cloud software in which the provider runs the application on cloud infrastructure, and the customer uses the application without managing the underlying infrastructure. (NIST 2026)
  10. Agentic AI: AI systems that can independently plan, decide and take actions toward a goal, using models together with tools, data, memory or workflows and operating with a degree of autonomy. (ASD 2026a)
  11. Prompt injection: an attack that exploits untrusted input incorporated into a higher-trust prompt, potentially causing an AI system to follow unintended instructions. (NIST 2026)

Appendix D: References

References follow the Australian Government Style Manual author–date system. Links open the underlying public source. Two URLs absent from the submitted bibliography — Lifeline Australia (2025) and Super SA (2021) — have been restored here from the publishers’ official websites.

  1. ABC (21 August 2026) ‘Tasmanian planners recommend approval of Firmus AI data centre at Bell Bay’, ABC News, accessed 30 August 2026.
  2. ABS (Australian Bureau of Statistics) (2023) Film, television and digital games, Australia, 2021–22 financial year, ABS, Australian Government, accessed 30 August 2026.
  3. ADII (Australian Digital Inclusion Index) (2025) 2025 findings, ADII website, accessed 30 August 2026.
  4. AEMO (Australian Energy Market Operator) (2026a) 2026 Electricity Statement of Opportunities [media release], AEMO, accessed 30 August 2026.
  5. AEMO (Australian Energy Market Operator) (2026b) Digital demand surge: preparing Australia’s power systems for the rise of data centres, AEMO, accessed 30 August 2026.
  6. AGD (Attorney-General’s Department) (2025a) Copyright and Artificial Intelligence Reference Group (CAIRG), AGD, Australian Government, accessed 30 August 2026.
  7. AGD (Attorney-General’s Department) (2025b) Copyright and AI Reference Group – governance framework, AGD, Australian Government, accessed 30 August 2026.
  8. AGD (Attorney-General’s Department) (n.d.) Copyright owners, AGD, Australian Government, accessed 30 August 2026.
  9. ARPANSA (Australian Radiation Protection and Nuclear Safety Agency) (n.d.) Electricity and health, ARPANSA, Australian Government, accessed 30 August 2026.
  10. ASD (Australian Signals Directorate) (2026a) New joint guidance provides mitigations for careful adoption of agentic AI services, Australian Cyber Security Centre, accessed 30 August 2026.
  11. ASD (Australian Signals Directorate) (2026b) Careful adoption of agentic AI services, Australian Cyber Security Centre, accessed 30 August 2026.
  12. ASD (Australian Signals Directorate) (2026c) Careful adoption of agentic AI in cyber defence, Australian Cyber Security Centre, accessed 30 August 2026.
  13. Australian Government (n.d.) Classification of films, videos, publications and computer games, Australian Business Licence and Information Service, accessed 30 August 2026.
  14. AWS (Amazon Web Services) (n.d.) Genesys, AWS Marketplace, accessed 30 August 2026.
  15. Ayres T, Albanese A and Charlton A (15 July 2026) AI in Australia’s interests [media release], Department of Industry, Science and Resources, Australian Government, accessed 30 August 2026.
  16. Bloomberg Law (2025) ‘Genesys hit with suit for recording domestic abuse hotline calls’, Bloomberg Law, accessed 30 August 2026.
  17. Bloomberg Law (2026) ‘Genesys settles abuse-hotline privacy lawsuit for $2.5 million’, Bloomberg Law, accessed 30 August 2026.
  18. City of Wollongong (2024) Contracts register – class 1 details: E1000099, City of Wollongong, accessed 30 August 2026.
  19. DCCEEW (Department of Climate Change, Energy, the Environment and Water) (2025) Renewable energy developments and environmental protection, Australian Government, accessed 30 August 2026.
  20. DCCEEW (Department of Climate Change, Energy, the Environment and Water) (2026a) Referral applications and proposals, Australian Government, accessed 30 August 2026.
  21. Department of Finance (2024) National framework for the assurance of artificial intelligence in government, Australian Government, accessed 30 August 2026.
  22. Department of Finance (27 August 2026) Procurement, Australian Government, accessed 30 August 2026.
  23. Digital NSW (n.d.) Virtual Contact Centre, NSW Government, accessed 30 August 2026.
  24. DISR (Department of Industry, Science and Resources) (2026b) Australia’s AI Safety Institute, Australian Government, accessed 30 August 2026.
  25. DISR (Department of Industry, Science and Resources) (2026c) Keep Australians safe – National AI Plan, Australian Government, accessed 30 August 2026.
  26. DISR (Department of Industry, Science and Resources) (23 March 2026a) Expectations of data centres and AI infrastructure developers, Australian Government, accessed 30 August 2026.
  27. DTA (Digital Transformation Agency) (2025a) AI Plan for the Australian Public Service 2025 – Appendix A: plan deliverables, Australian Government, accessed 30 August 2026.
  28. DTA (Digital Transformation Agency) (2025b) APS AI Plan 2025 – Tools, Australian Government, accessed 30 August 2026.
  29. DTA (Digital Transformation Agency) (2025c) Policy for the responsible use of AI in government – Version 2.0, Australian Government, accessed 30 August 2026.
  30. DTA (Digital Transformation Agency) (31 January 2025d) New Whole-of-Government Arrangement signed with Amazon Web Services (AWS) Australia [media release], Australian Government, accessed 30 August 2026.
  31. EPA Tasmania (n.d.-a) Guidelines for assessing noise nuisance, Tasmanian Government, accessed 30 August 2026.
  32. EPA Tasmania (n.d.-b) Legislative context – noise, Tasmanian Government, accessed 30 August 2026.
  33. eSafety Commissioner (2018) Millions of older Australians missing out online [media release], Australian Government, accessed 30 August 2026.
  34. eSafety Commissioner (n.d.) Digital behaviours of older Australians, Australian Government, accessed 30 August 2026.
  35. Fair Work Ombudsman (2026) Privacy, Fair Work Ombudsman, Australian Government, accessed 30 August 2026.
  36. Firmus (2026) Bell Bay Industrial Precinct AI Factory Project, Firmus Technologies, accessed 30 August 2026.
  37. Genesys (10 June 2026a) Privacy notice – Genesys.com Agentic Virtual Agent, Genesys, accessed 30 August 2026.
  38. Genesys (19 May 2026e) ‘The 2026 Orchestrators Innovation Awards finalists set the bar for experience innovation’, Genesys, accessed 30 August 2026.
  39. Genesys (2026b) Sustainability 2026, Genesys, accessed 30 August 2026.
  40. Genesys (2026d) Genesys Orchestrators Innovation Awards, Genesys, accessed 30 August 2026.
  41. Genesys (22 July 2026c) Genesys deepens strategic collaboration with AWS to accelerate global AI innovation [media release], Business Wire, accessed 30 August 2026.
  42. Genesys (n.d.-a) Privacy, Genesys Cloud Trust Center, accessed 30 August 2026.
  43. Genesys (n.d.-b) Genesys Cloud AI ethics, Genesys, accessed 30 August 2026.
  44. Genesys (n.d.-c) What datasets are used to train and refine your AI services or products?, Genesys Cloud Resource Center, accessed 30 August 2026.
  45. Genesys (n.d.-d) Configure and activate the Genesys Summarization Connector, Genesys Cloud Resource Center, accessed 30 August 2026.
  46. Genesys (n.d.-e) Genesys subprocessors, Genesys Cloud Resource Center, accessed 30 August 2026.
  47. Genesys (n.d.-f) AWS regions for Google Cloud TTS and STT integrations, Genesys Cloud Resource Center, accessed 30 August 2026.
  48. Genesys (n.d.-g) Sustainability practices in business: our commitment to a greener future, Genesys, accessed 30 August 2026.
  49. Genesys (n.d.-h) AWS regions for Genesys Cloud, Genesys Cloud Resource Center, accessed 30 August 2026.
  50. Genesys (n.d.-i) National Domestic Violence Hotline customer story, Genesys, accessed 30 August 2026.
  51. Genesys (n.d.-j) Genesys AWS partnership, Genesys, accessed 30 August 2026.
  52. Genesys (n.d.-k) AWS and public sector competency, Genesys, accessed 30 August 2026.
  53. Genesys (n.d.-l) Genesys Customer Advocacy Program – terms and conditions, Genesys, accessed 30 August 2026.
  54. Genesys (n.d.-m) Genesys Customer Advocacy Program, Genesys, accessed 30 August 2026.
  55. Genesys (n.d.-n) Agentic virtual agent, Genesys, accessed 30 August 2026.
  56. Genesys (n.d.-o) Charles Sturt University powers empathetic student support with agentic AI, reducing costs by 13%, Genesys, accessed 30 August 2026.
  57. Genesys (n.d.-p) Agile cloud solution empowers agents to provide same-day customer outcomes: NSW Department of Communities and Justice, Genesys, accessed 30 August 2026.
  58. Genesys (n.d.-q) Integrating disparate processes to enhance operational efficiency: Northern Beaches Council, Genesys, accessed 30 August 2026.
  59. Genesys (n.d.-r) Streamlining interactions and enhancing student services: Western Sydney University, Genesys, accessed 30 August 2026.
  60. Genesys (n.d.-s) Leveling up CX sparks exceptional engagement at Salvation Army, Genesys, accessed 30 August 2026.
  61. Genesys (n.d.-t) Boosting client service by streamlining the contact centre: Anglicare Sydney, Genesys, accessed 30 August 2026.
  62. Genesys (September 2025) Genesys Privacy Policy, Genesys, accessed 30 August 2026.
  63. Genesys Community (2026) ‘For Orchestrators, what activities add points?’, Genesys Community, accessed 30 August 2026.
  64. ICAC (Independent Commission Against Corruption NSW) (n.d.) Gifts and benefits, ICAC, accessed 30 August 2026.
  65. IGEA (Interactive Games & Entertainment Association) (2025) Australia Plays 2025, IGEA, accessed 30 August 2026.
  66. IGEA (Interactive Games & Entertainment Association) (2026) Australian Game Developer Survey 2025, IGEA, accessed 30 August 2026.
  67. Jobs and Skills Australia (n.d.-a) Librarians, Australian Government, accessed 30 August 2026.
  68. Jobs and Skills Australia (n.d.-b) Archivists, curators and records managers, Australian Government, accessed 30 August 2026.
  69. Libraries Tasmania (2026) Digital Inclusion Review, Tasmanian Government, accessed 30 August 2026.
  70. Lifeline Australia (2025) Annual report 2024–25, Lifeline Australia, accessed 30 August 2026.
  71. Mandala Partners (21 October 2024) Empowering Australia’s Digital Future, Mandala Partners, accessed 30 August 2026.
  72. National EPA (National Environmental Protection Agency) (n.d.-a) SYD01 (Huntingwood) Data Centre – EPBC 2025/10391, EPBC Act Public Portal, accessed 30 August 2026.
  73. National EPA (National Environmental Protection Agency) (n.d.-b) Bell Bay Wind Farm – EPBC 2024/09868, EPBC Act Public Portal, accessed 30 August 2026.
  74. NFSA (National Film and Sound Archive of Australia) (2024) International video games survey points to threat to collection and preservation [media release], NFSA, Australian Government, accessed 30 August 2026.
  75. NFSA (National Film and Sound Archive of Australia) (2026) International video games preservation, NFSA, Australian Government, accessed 30 August 2026.
  76. NFSA (National Film and Sound Archive of Australia) (n.d.-a) Video games at the NFSA, NFSA, Australian Government, accessed 30 August 2026.
  77. NFSA (National Film and Sound Archive of Australia) (n.d.-b) National Audiovisual Collection, NFSA, Australian Government, accessed 30 August 2026.
  78. NIST (National Institute of Standards and Technology) (2026) Computer Security Resource Center Glossary, US Department of Commerce, accessed 30 August 2026.
  79. NSW Government (2025) Southern Hemisphere’s biggest data centre gets the green light [media release], NSW Government, accessed 30 August 2026.
  80. NSW Government (n.d.-a) Probity and fairness, buy.nsw, accessed 30 August 2026.
  81. NSW Government (n.d.-b) Supplier Code of Conduct, buy.nsw, accessed 30 August 2026.
  82. NSW Planning Portal (2022) Mowbray Road Data Centre – hazards and risk, NSW Government, accessed 30 August 2026.
  83. OAIC (Office of the Australian Information Commissioner) (2025) Corporate plan 2025–26, Australian Government, accessed 30 August 2026.
  84. OAIC (Office of the Australian Information Commissioner) (n.d.-a) Chapter 8: APP 8 – cross-border disclosure of personal information, Australian Government, accessed 30 August 2026.
  85. OAIC (Office of the Australian Information Commissioner) (n.d.-b) Guide to data analytics and the Australian Privacy Principles, Australian Government, accessed 30 August 2026.
  86. OAIC (Office of the Australian Information Commissioner) (n.d.-c) Chapter 5: APP 5 – notification of the collection of personal information, Australian Government, accessed 30 August 2026.
  87. OAIC (Office of the Australian Information Commissioner) (n.d.-d) Chapter B: key concepts – consent, Australian Government, accessed 30 August 2026.
  88. OAIC (Office of the Australian Information Commissioner) (n.d.-e) Privacy Act Review Issues Paper submission – Part 5: notice and consent, Australian Government, accessed 30 August 2026.
  89. OAIC (Office of the Australian Information Commissioner) (n.d.-f) Chapter 3: APP 3 – collection of solicited personal information, Australian Government, accessed 30 August 2026.
  90. Olaguer EP, Knipping E, Shaw S and Ravindran S (2016) ‘Microscale air quality impacts of distributed power generation facilities’, Journal of the Air & Waste Management Association, 66(8):795–806, doi:10.1080/10962247.2016.1184194.
  91. Parliament of Australia (2026) Joint Select Committee on Artificial Intelligence, Parliament of Australia, accessed 30 August 2026.
  92. PM&C (Department of the Prime Minister and Cabinet) (2026) Office of AI, Australian Government, accessed 30 August 2026.
  93. Prime Minister of Australia (2026) Amazon data centre investment in Australia [media release], Australian Government, accessed 30 August 2026.
  94. Reuters (24 August 2026b) ‘WikiHow sues OpenAI for copyright infringement over AI training’, Reuters, accessed 30 August 2026.
  95. Reuters (9 July 2026a) ‘New York Times-led group asks court to sanction OpenAI in US copyright dispute’, Reuters, accessed 30 August 2026.
  96. Revenue NSW (2025) Revenue NSW – Data Services for Genesys Cloud – RNSW/5108, buy.nsw, NSW Government, accessed 30 August 2026.
  97. Screen Australia (2026) Screen Currency 2026 – framework and economic insights, Screen Australia, Australian Government, accessed 30 August 2026.
  98. Super SA (2021) Annual report 2020–21, Government of South Australia, accessed 30 August 2026.
  99. Tao Y and Gao P (2025) ‘Global data center expansion and human health: a call for empirical research’, Eco-Environment & Health, 4(3):100157, doi:10.1016/j.eehl.2025.100157.
  100. Telstra (n.d.) Hobsons Bay City Council case study, Telstra, accessed 30 August 2026.
  101. Treasury (2022) Digital Games Tax Offset, Australian Treasury, Australian Government, accessed 30 August 2026.
  102. Treasury (2024) Review of AI and the Australian Consumer Law – consultation, Australian Treasury, Australian Government, accessed 30 August 2026.
  103. Treasury (3 October 2025) Final report – Review of AI and the Australian Consumer Law, Australian Treasury, Australian Government, accessed 30 August 2026.
  104. US Department of Energy (2019) Cooling Water Efficiency Opportunities for Federal Data Centers, US Department of Energy, accessed 30 August 2026.
  105. US EPA (United States Environmental Protection Agency) (n.d.) Clean Air Act resources for data centers, US EPA, accessed 30 August 2026.
  106. Watt M (14 August 2026a) Interview with Patricia Karvelas, ABC Afternoon Briefing [transcript], Australian Government, accessed 30 August 2026.
  107. Watt M (27 March 2026b) Address to the Australian Water Association National Policy Forum [speech], Australian Government, accessed 30 August 2026.
  108. Copyright Act 1968 (Cth), Federal Register of Legislation, accessed 30 August 2026.