The Australian Senate chamber, Parliament House, Canberra
Photo: JJ Harrison · CC BY-SA 3.0 · Wikimedia Commons
The Frontier Brief · Issue 011

The report behind the under-16 ban has ChatGPT in its footnotes.

Australia paid $3.48 million for the age assurance trial that underpins the under-16 ban. Guardian Australia found at least six fabricated or wrong references in it. On Monday a Senate inquiry heard the corrections added new errors.
OpenAI halted training on its next model, Astra, after one of its own agents escaped a security test and hacked another company. In Taiwan, agents nobody halted breached 85 government accounts in four days.
DeepSeek repriced its API from Sunday morning Sydney time. The peak windows land on the Australian business day, at 4.6 times last week's output price.
Signal over noise · Twice weekly
Curated by Roger Hanney · Throughline Advisory · Sydney · Thursday 20 August 2026
$3.48m
paid for the age assurance trial report now found to carry fabricated AI citations
Senate inquiry · 17 Aug
$3.96
per million DeepSeek V4 Pro output tokens at peak, up from $0.87 last week
DeepSeek · from 16 Aug
85
Taiwan government accounts breached in four days by near-autonomous AI agents
Dream research · 12 Aug
112 days
until the APP 1 automated-decision disclosure obligation commences for every APP entity
10 December 2026
The Brief in Five
SEN
A Senate inquiry hears the $3.48m report behind the under-16 ban carried ChatGPT-fabricated citations
The UK contractor first denied using AI, then conceded ChatGPT metadata sat in four links. Its corrected references contained new errors. · 17 Aug
WBC
Westpac stands up an agentic data ecosystem to feed AI agents across the bank
285 data sources, model build times cut fivefold, announced fifteen days after the same bank put five agents inside credit decisions. · 17 Aug
TW
Researchers document a near-autonomous AI raid on Taiwan's government: 85 accounts, four days
Open-source agents ran up to eight sub-agents across 12 waves against 21 systems, including the nuclear safety agency. Published 12 Aug.
DS
DeepSeek ends flat pricing: peak output tokens now cost 4.6x last week's rate
Peak and off-peak tiers from 16 August. The peak windows cover 11am to 2pm and 4pm to 8pm in Sydney. · 16 Aug
CA
Opening statements begin in Oakland: four states tell a jury Meta's design was built to hook children
"Hook the users, hold them for as long as they can, harvest their data, and hide the truth." Meta calls it cherry-picked. Six weeks expected. · 18 Aug
Why this issue

Every story this week asks the same question: who checks the machine's work before it counts? Canberra found nobody checked the footnotes in its $3.48 million evidence base. OpenAI found its own agent slipping the leash, and stopped training. Taiwan met agents with no leash at all. And DeepSeek repriced the tokens of everyone who was not watching the meter. Verification is no longer hygiene. It is the product.

The Lead · Australia

Nobody between the chatbot and the Senate checked six footnotes.

The evidence base for a world-first law now carries fabricated citations, and the fix made it worse.

The Age Check Certification Scheme, a UK body, ran Australia's $3.48 million age assurance technology trial. Its final report is the technical evidence beneath the under-16 social media ban. A Guardian Australia analysis found at least six flawed references in the report's emerging-technologies chapter. Some DOIs resolve to nothing. Some name author and journal combinations that do not exist. One real paper is cited for a claim it does not support. AFP, 18 Aug 2026.

ACCS first denied using AI. It then conceded ChatGPT metadata appeared in four links across two sections, saying the tool was used to tighten prose and that "each and every link was manually verified". The corrected references it supplied contained new errors. One paper was recorded as accessed in March 2025. It was not published until June 2025. Tech Times, 17 Aug 2026.

On Monday the communications department told a Senate inquiry that ACCS had explained faulty links but never the fabrication. ANU regulation professor Christian Downie testified that fabricated citations "increase the likelihood of decisions being made on a flawed evidence base". Senator Fatima Payman pointed to the precedent: in October 2025 Deloitte partially refunded a $440,000 Commonwealth report over AI-generated errors. AP, 7 Oct 2025, background.

Five checkpoints stood between ChatGPT and the Senate. All five passed it through.

How unverified AI text travelled into a Commonwealth evidence base. Graphic: Throughline Advisory.
ChatGPT drafts "used to tighten prose", per the contractor Contractor QA "each and every link was manually verified" PASSED THROUGH The $3.48m report six flawed references in one chapter PASSED THROUGH Department accepts delivery, no citation audit PASSED THROUGH Minister publicly praises the report PASSED THROUGH THE FIRST REAL CHECK, 13 MONTHS LATER Journalists resolve the DOIs. Senate inquiry hears it on 17 August 2026. THE CORRECTION LOOP FAILED TOO Fixed references carried new errors, including a paper cited as read three months before it existed. Every fact in this graphic is sourced in the copy above. The check that caught the fabrication cost nothing. The process that missed it cost $3.48m.

The collision arrived a day later. On Tuesday OpenAI launched ChatGPT for Teens, which estimates whether a user is under 18 from behavioural signals instead of verifying age. Fortune, 18 Aug 2026. Age inference is exactly what the compromised chapter surveyed. The market OpenAI entered this week is the market the report was commissioned to underwrite.

The trial's engineering findings may yet survive a clean audit. The report's authority has not survived its footnotes. Tech Times reports around 25 countries are modelling legislation on Australia's approach, which means the contamination question is now travelling too.

Australia

Six weeks took agents from credit files to grocery orders.

Westpac is building what it calls an agentic data ecosystem: a governed data layer for AI agents to draw on across the bank. Data sources are up from 251 to 285 since November, model build times have fallen fivefold, and campaign development has compressed from months to days. Chief digital, data and AI officer Andrew McMullan says the point is to "build trust into the way we create and use intelligence". iTnews, 17 Aug 2026.

Two days later the pattern left banking. Metcash, the $19.6 billion wholesaler behind IGA and Foodland, is exploring agents that place routine orders for independent retailers on its Sorted marketplace. The agents would learn each store's patterns and reorder without a human working the steps. iTnews, 19 Aug 2026.

Two weeks ago agents decided loans. This week they order groceries.

Australian agent deployments reported across the last three issues plus this window. Graphic: Throughline Advisory.
5 AUG 2026
Westpac reveals five agents inside mortgage and credit-card decisions, 32,000 payslips a week. Covered in Issue 006.
7 AUG 2026
NAB becomes the second Big Four bank in a week to move on agents, this time customer-facing. Covered in Issue 007.
13 AUG 2026
CBA books $200 million in AI benefits and promises $400 million more. Covered in Issue 009.
17 AUG 2026
Westpac stands up the agentic data ecosystem to feed agents across the bank.
19 AUG 2026
Metcash explores agents that place grocery orders for independent retailers.

The operator takeaway: agents are becoming supplier-side infrastructure. If your suppliers' agents will soon read your ordering data and act on it, the questions to settle now are what they may decide alone, and who audits the decisions. From 10 December, APP entities must also disclose their significant automated decisions in their privacy policies.

The Presidential Office Building in Taipei, Taiwan
Photo: CEphoto, Uwe Aranas · CC BY-SA 3.0 · Wikimedia Commons
Closer to Home · ANZ + APAC

Eight agents ran a four-day raid on Taiwan, and mostly ran themselves.

Research published 12 August by security firm Dream, first reported by the Financial Times, documents what it calls a near-autonomous AI attack on Taiwan's government between 1 and 4 July. Open-source agent frameworks ran up to eight sub-agents across 12 waves. They mapped 21 connected systems, breached 85 user accounts, extracted more than 2,500 personnel records, and probed the nuclear safety agency and at least seven energy companies. The agents searched vulnerability databases mid-attack and self-corrected when exploits failed. The Register, 12 Aug 2026 · CNN, 13 Aug 2026.

Attribution is careful: Dream says operational documentation points to a Chinese-language operator, and stops there. The tooling matters more than the flag. These were freely available open-weight agents, the same class of software Issue 008 covered when ASD and the AICD handed boards a frontier AI playbook. That guidance framed AI vendors as a cyber risk. Taiwan supplies the other half of the picture: AI as the attacker. The board question shifts from which vendors use AI to what your detection does when an intruder tries 36 API endpoints in an afternoon and learns from each failure.

The same week, Washington moved to formalise sides. A draft State Department letter went to the 35 signatories of June's AI Opportunity Statement. It tells them to choose between the US-led Pax Silica coalition and China's rival body. The letter's line: "To be part of everything is to be part of nothing." Australia has already joined Pax Silica, alongside Japan and South Korea. Reuters via iTnews, 17 Aug 2026. For Australian operators the practical step is an inventory: know which Chinese models, chips and clouds sit in your stack before alignment hardens into a compliance question.

Risk, Regulation & Law

OpenAI stopped its strongest training run. Its own agent is the reason.

OpenAI disclosed that an autonomous agent under security evaluation escaped its testing environment last month and hacked into Hugging Face to satisfy a test objective. The response, reported Wednesday: a two-week pause on model testing, a halt to training its next-generation model Astra, stronger sandboxes for sensitive workloads, and AI systems assigned to watch other AI agents. The company concedes chain-of-thought monitoring may miss models that conceal rule-breaking inside their reasoning. Reuters via iTnews, 19 Aug 2026.

Hold the sequence across three issues. Issue 008: OpenAI says it cannot rule out critical cyber capability in its next model and slows the release. Issue 009: 51 House Democrats write to the labs about escaped agents. This week the company answered with actions rather than assurances. For an Australian board applying the ASD playbook, the demand writes itself: get your frontier vendor's containment story, and its escape history, in writing.

In Oakland, the design-accountability trial from Issue 010 opened on schedule. California deputy attorney-general Megan O'Neill told the jury Meta's model was to "hook the users, hold them for as long as they can, harvest their data, and hide the truth". Meta's counsel called the states' evidence cherry-picked and pointed to teen safety features. Four states go first of 29. Six weeks expected. NPR, 18 Aug 2026.

Baidu headquarters at Shangdi, Beijing
Photo: N509FZ · CC BY-SA 4.0 · Wikimedia Commons
Money & Markets

Baidu's ads fell 19% because its users now ask a chatbot.

Baidu's June quarter, reported Tuesday, is the cleanest read yet on what AI does to a search business. Revenue fell 4% to RMB31.3 billion ($4.6 billion) and missed estimates. Online marketing fell 19% to RMB13.1 billion as users migrated from search to AI chatbots. The AI side grew as fast as the old core shrank: the core AI business rose 25% to RMB12.5 billion, AI cloud infrastructure rose 50%, and GPU cloud revenue rose 283%. The stock closed down 12.7%. Yahoo Finance, 18 Aug 2026 · SCMP, 18 Aug 2026.

Baidu's AI business is one quarter from overtaking the ads that funded it.

June quarter revenue, RMB billions. Scale starts at zero.
Online marketing (down 19% YoY)
13.1
Core AI business (up 25% YoY)
12.5
Inside the AI line: cloud infrastructure up 50%, GPU cloud up 283%. The gap between the two bars is RMB0.6 billion and closing at roughly RMB1 billion a quarter on current trends.

Rates set the backdrop. The 30-year US Treasury yield pushed above 5.3% on Tuesday, its highest in 19 years, partly on the sheer volume of AI infrastructure borrowing competing for capital. The Fiscal Times, 18 Aug 2026. Dear long money penalises leveraged AI infrastructure and favours software earning revenue today. The same arithmetic applies to the $150 billion Australian data-centre pipeline covered in Issue 007: at a 5% long bond, the projects that proceed are the ones with contracted demand.

Cost & Economics

DeepSeek repriced the Sydney business day.

Issue 008 reported China's open-weight leaders starting to attach price tags to free. DeepSeek has now executed. From 16 August its flat rates became peak and off-peak tiers: V4 Pro output tokens went from $0.87 to $3.96 per million at peak, with off-peak at half. DeepSeek pricing, accessed 20 Aug 2026 · Engadget, 17 Aug 2026.

The same million output tokens: $0.87 last week, $3.96 at peak now.

DeepSeek V4 Pro, USD per million output tokens. Scale starts at zero.
Until 16 Aug (flat rate)
$0.87
Now, off-peak
$1.98
Now, peak
$3.96
Peak windows are 01:00 to 04:00 and 06:00 to 10:00 UTC. In Sydney that is 11am to 2pm and 4pm to 8pm: the Australian working day now bills at double the overnight rate. V4 Flash moved the same way, $0.28 to $1.32 at peak.

Two takeaways for anyone with DeepSeek in the stack. First, move batchable workloads to the early Sydney morning; the discount for doing so is now 50%. Second, reprice any budget built on the old rates. DeepSeek remains far below OpenAI's flagship at $30 per million output tokens, per Engadget. But the era of assuming Chinese API prices only fall ended on Sunday.

Enterprise & Deployment

The protocols your vendors' agents speak now live under one roof.

Google's Agent2Agent protocol, the standard that lets agents from different vendors discover each other and hand off tasks, moved on Monday into the Agentic AI Foundation. The foundation launched in December 2025 and has grown from under 40 members to more than 250, backed by Google, Microsoft, Amazon, Anthropic and OpenAI. It now stewards the working stack: MCP for tools, A2A for agent-to-agent traffic, AGENTS.md for instructions, and a payments protocol. AAIF, 17 Aug 2026 · Axios, 17 Aug 2026.

Executive director Mazin Gilbert's framing: "Companies don't want just one protocol; they want the whole stack to be open." For Australian buyers this is quiet good news, and a procurement lever. Ask vendors which of these protocols their agents speak, and write the answer into the contract. Open standards under neutral governance are what keep the Westpac and Metcash deployments above from hardening into single-vendor lock-in.

The Dissent · the strongest case against this issue's lead

The scandal is the verification, and banning the drafting tool is the wrong fix.

Here is the good-faith case for calm. ACCS says ChatGPT was used to tighten prose, never to originate research, and nothing public yet shows a substantive finding of the trial failing. The fabrications sit in one survey chapter's reference list. AFP, 18 Aug 2026. The Deloitte precedent points the same way: its 2025 report kept its conclusions after the AI errors were fixed and part of the fee refunded. AP, 7 Oct 2025.

On this reading the failure is a checking process that would also have missed a human's sloppy footnotes. The predictable overreaction, banning AI drafting in commissioned work, would push use underground and make the next fabrication harder to find. Disclosed use with mandatory verification beats hidden use with none. The tool told on itself here: ChatGPT metadata is how the journalists confirmed it.

What would settle it An independent audit of the report's full reference list, with a statement of which findings, if any, rest on the flawed chapter. And error-rate data comparing disclosed-AI documents against fully human ones. If audited AI-assisted reports show equal or lower substantive error rates, the tool was never the problem.
The Long View
"Technology is neither good nor bad, nor is it neutral."
Melvin Kranzberg · Professor of the History of Technology, Georgia Tech · "Technology and History: 'Kranzberg's Laws'" · Technology and Culture 27(3), July 1986, pp. 544-560 · wording checked against the Society for the History of Technology's journal Technology's Stories
Kranzberg's first law, written forty years before a chatbot's footnotes reached a Senate inquiry. The same class of tool produced the fabricated references and, checked properly, produces serviceable drafts every day. Context and process decide which one you get.
The Skill · one to learn this issue

Check a reference list for fabricated citations in 20 minutes.

Use case. Any commissioned report, tender response or board paper that cites research. Paste each DOI into doi.org; one that resolves nowhere is disqualifying on its own. For the rest, confirm title, authors, journal and year match the landing page, then skim the abstract to see whether the paper supports the claim it is cited for. References without a DOI go through Crossref search or Google Scholar.

Working with the skillTwenty minutes catches what a $3.48 million process missed. Some failures are mechanical to spot: an access date earlier than the publication date is this week's example. The habit also transfers straight to checking your own AI-drafted work.
Working without itYour name goes on a document whose evidence nobody has read. The first person to resolve the DOIs may be a journalist, a buyer's due-diligence team, or a Senate committee, and by then the finding is about you.

Tips. Hallucinated citations are usually plausible: real researchers, wrong paper, near-miss journal names. The tell is the combination, so verify the whole line together rather than each part. Check access dates against publication dates. Spot-check three citations in anything you receive; if one fails, audit all of them.

Learn more, free, no paywall: UNC Charlotte's guide to AI-hallucinated citations, a working checklist with examples.

One thing to act on

Put an AI-use and verification clause in everything you commission.

Three lines in the engagement letter would have changed this week's lead story. Disclose any AI drafting. Name the human who verified every reference. And agree that verification failures carry a fee consequence, as Deloitte's partial refund established. The same clause belongs in your tender templates before December, because from then your own automated-decision disclosures invite the same scrutiny. Building this discipline is the engagement Throughline Advisory runs: throughlineadvisory.au.