Verification status
Claim census by evidence tier. T1 is a primary source retrieved directly; T3 is secondary reporting held pending a primary source.
Every claim is at evidence tier one — a primary source retrieved directly and archived — with no claim resting on secondary reporting. D6.15 (Anthropic's statement on restoration of access) is sourced to S14, the provider's own statement, and sits at T1; the non-public Commerce letter of 26 June 2026 (S21) is recorded but not relied on for any claim.
Every claim, by section
All 118 claims, in document order, each with its tier and recorded status.
| ID | Claim | Tier | Status |
|---|---|---|---|
| A1 | CBA entered a five year strategic collaboration with AWS, continuing AWS as the bank's preferred cloud provider | T1 | Supported |
| A2 | CBA is rearchitecting a significant percentage of its workloads onto AWS | T1 | Supported |
| A3 | Core platforms and applications including Netbank, CommSec and MUREX have migrated to AWS from on premises environments | T1 | Supported |
| A4 | CBA's DevOps Hosting Platform is hosted on AWS, with native integration to Amazon Bedrock for model access and RAG | T1 | Supported |
| A5 | CBA's AI Factory, launched September 2024, is powered by Amazon EC2 P5 instances | T1 | Supported |
| A6 | CBA has completed migrating its data platform to AWS | T1 | Supported |
| A7 | CBA has migrated 100 per cent of its data to the cloud (statement of Terri Sutherland, CBA Lead for Data Platforms) | T1 | Supported |
| A8 | The migration involved over 61,000 data pipelines, commencing July 2024 | T1 | Supported |
| A9 | CBA operates over 2,000 AI models against approximately 157 billion data points, making around 55 million decisions daily | T1 | Supported |
| A10 | CBA states an intention to reduce its on premises data centre footprint as a consequence of the migration | T1 | Supported |
| A11 | The migration was delivered with HCLTech as partner | T1 | Supported (role limited to migration delivery on the face of the record) |
| ID | Claim | Tier | Status |
|---|---|---|---|
| B1 | Amazon Web Services, Inc. is a Delaware corporation, 100 per cent owned by Amazon.com, Inc. | T1 | Supported |
| B2 | Amazon Data Services, Inc. is a Delaware corporation, 100 per cent owned by Amazon.com, Inc. | T1 | Supported |
| B3 | Amazon Web Services Australia Pty Ltd is an Australian proprietary company limited by shares, ACN 605 345 891 / ABN 63 605 345 891, registered 22 April 2015, status Registered, registered office Level 37, 2-26 Park Street, Sydney NSW 2000 | T1 | Supported |
| B4 | The ultimate holding company of Amazon Web Services Australia Pty Ltd is AMAZON.COM, INC. (Org No. 624 502 263) | T1 | Supported |
| B5 | 18 USC 2713 obliges a provider of electronic communication service or remote computing service to preserve, backup or disclose contents and records within its possession, custody or control, regardless of whether located within or outside the United States | T1 | Supported |
| B6 | 18 USC 2711(2) defines "remote computing service" as the provision to the public of computer storage or processing services by means of an electronic communications system | T1 | Supported |
| B7 | The sole member of Amazon Web Services Australia Pty Ltd is AMAZON WEB SERVICES, INC. (Org No. 663 081 114), of 251 Little Falls Drive, Wilmington, Delaware, holding 231,800,001 ordinary shares beneficially and fully paid, being the entire issued capital | T1 | Supported |
| B8 | The Delaware entity identified at B7 as sole member of the Australian entity is the same entity identified at B1 in Amazon.com, Inc.'s SEC filing as a Delaware corporation 100 per cent owned by Amazon.com, Inc. | T1 | Supported. Two independent regulators concur |
| B9 | 18 USC 2711(1) provides that terms defined in 18 USC 2510 have, respectively, the definitions given in that section | T1 | Supported |
| B10 | 18 USC 2510(15) defines "electronic communication service" as any service which provides to users thereof the ability to send or receive wire or electronic communications. No "to the public" qualifier | T1 | Supported |
| B11 | 18 USC 2510(12) defines "electronic communication" but excludes at (D) electronic funds transfer information stored by a financial institution in a communications system used for the electronic storage and transfer of funds | T1 | Supported. Limits the claim. See CS8 |
| B12 | 18 USC 2510(14) defines "electronic communications system" to include any computer facilities or related electronic equipment for the electronic storage of such communications | T1 | Supported |
| B13 | 18 USC 2510(17) defines "electronic storage" to include any storage of such communication by an electronic communication service for purposes of backup protection | T1 | Supported |
| B14 | 18 USC 2713 reaches not only the contents of a wire or electronic communication but also "any record or other information pertaining to a customer or subscriber" within the provider's possession, custody or control | T1 | Supported. See CS8 |
| ID | Claim | Tier | Status |
|---|---|---|---|
| C1 | AWS's public assurance to CBA cites security, resilience, availability and regulatory obligations, and does not address foreign legal compellability (statement of Jamie Simon, Director of Financial Services, AWS ANZ) | T1 | Supported |
| C2 | AWS's second public assurance to CBA cites security, compliance and resilience at scale, and does not address foreign legal compellability (same spokesperson) | T1 | Supported |
| C3 | The absence identified at C1 and C2 appears in two separate announcements by the same vendor representative. Whether this reflects anything beyond the ordinary scope of a commercial announcement is not established by the record and is not claimed. | T1 | Supported as to repetition only |
| ID | Claim | Tier | Status |
|---|---|---|---|
| D1 | CBA holds an expanded strategic partnership with, and investment in, Anthropic. Gavin Munroe, Group CIO, named. Krishna Rao, Anthropic CFO, confirms strategic investment | T1 | Recorded |
| D2 | CommBiz Gen AI uses Claude 3 and Cohere via Amazon Bedrock Knowledge Bases, with Amazon OpenSearch as vector database | T1 | Recorded |
| D3 | CBA states it was the first Australian company to enter a strategic partnership with OpenAI | T1 | Recorded |
| D4 | Anthropic, PBC is a Delaware public benefit corporation, Delaware entity ID 4860621, LEI 984500B6DEB8CEBC4Z70, created 26 January 2021 | T1 | Recorded |
| ID | Claim | Tier | Status |
|---|---|---|---|
| D4.1 | ANTHROPIC, PBC is registered with the Delaware Division of Corporations, File Number 4860621, Entity Kind Corporation, Entity Type Benefit Corporation, Residency Domestic, State Delaware, incorporation date 26 January 2021. Registered agent Corporation Service Company, 251 Little Falls Drive, Wilmington | T1 | Recorded |
| D4.2 | GLEIF records ANTHROPIC, PBC, LEI 984500B6DEB8CEBC4Z70, jurisdiction of formation US-DE, entity status ACTIVE, corroboration level FULLY_CORROBORATED, validated against the Delaware Division of Corporations under registration 4860621 | T1 | Recorded |
| D4.3 | The GLEIF record reports no direct parent and no ultimate parent (NO_KNOWN_PERSON exception reported for both), and no direct or ultimate children | T1 | Recorded |
| D4.4 | OPENAI GROUP PBC is registered with the Delaware Division of Corporations, File Number 10381551, Entity Kind Corporation, Entity Type Benefit Corporation, Residency Domestic, State Delaware, incorporation date 28 October 2025. Registered agent The Corporation Trust Company | T1 | Recorded |
| D4.5 | OpenAI states that under its updated structure announced 28 October 2025, the nonprofit is the OpenAI Foundation and the for-profit is a public benefit corporation called OpenAI Group PBC, which the Foundation continues to control | T1 | Recorded |
| D4.6 | OpenAI states that as of the closing of the recapitalisation the OpenAI Foundation holds a 26 per cent equity stake in OpenAI Group, Microsoft holds roughly 27 per cent, and the remaining 47 per cent is held by current and former employees and investors | T1 | Recorded |
| D4.7 | OpenAI states that through special voting and governance rights held solely by the Foundation, the Foundation appoints all members of the OpenAI Group board and can replace directors at any time | T1 | Recorded |
| ID | Claim | Tier | Status |
|---|---|---|---|
| D5.1 | The Services are those made available through Amazon Bedrock, hosted and managed by Amazon Web Services, Inc. | T1 | Recorded |
| D5.2 | Anthropic may require that AWS suspend Customer's access to any portion or all of the Services if Anthropic reasonably believes or determines that Anthropic's provision of the Services to Customer is prohibited by applicable law | T1 | Recorded |
| D5.3 | Anthropic may terminate immediately with Notice if it reasonably believes or determines that provision of the Services to Customer is prohibited by applicable law | T1 | Recorded |
| D5.4 | Anthropic will have no liability for any damage, liabilities, losses (including any loss of data or profits), or any other consequences that Customer may incur because of a Service Suspension | T1 | Recorded |
| D5.5 | The Terms are governed by the laws of the State of California. All suits will be instituted exclusively in federal or state courts located in San Francisco, California, and each Party irrevocably submits to their exclusive jurisdiction | T1 | Recorded |
| D5.6 | Customer and its Users may only use the Services in the countries and regions Anthropic currently supports | T1 | Recorded |
| D5.7 | Confidential Information may be disclosed to the extent required by law, or court or administrative order, with notification to the discloser except where expressly prohibited | T1 | Recorded |
| D5.8 | The technology provided by Anthropic to AWS does not give Anthropic access to Customer's AWS instance, including Prompts or Outputs. Anthropic does not anticipate obtaining any rights in or access to Customer Content | T1 | Recorded |
| ID | Claim | Tier | Status |
|---|---|---|---|
| D6.1 | The US government, citing national security authorities, issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees | T1 | Recorded |
| D6.2 | The net effect of the order was that Anthropic abruptly disabled Fable 5 and Mythos 5 for all customers to ensure compliance | T1 | Recorded |
| D6.3 | Access to all other Anthropic models was not affected | T1 | Recorded |
| D6.4 | The directive was received at 5:21pm ET on 12 June 2026. The letter did not provide specific details of its national security concern | T1 | Recorded |
| D6.5 | Anthropic complied with the directive while disagreeing with its basis | T1 | Recorded |
| D6.6 | The order took effect immediately; Anthropic had no reliable way to verify nationality in real time and therefore suspended access for all users. Export controls were lifted 30 June 2026; Fable 5 access restored 1 July 2026 | T1 | Recorded |
| D6.7 | Koren, Kurland and Mehta state that the ECRA authority to establish interim controls on emerging and foundational technologies has no regulatory framework in the EAR, and that this is why it has never before been used as the basis for issuing a control. The statute does not explicitly allow a worldwide "is informed" control but does not exclude it either | T1 | Recorded |
| D6.8 | Koren, Kurland and Mehta state it is unclear how user access to models equates to a release of EAR software or technology to any foreign national except those working at Anthropic, and that the models or model weights are not being exported | T1 | Recorded |
| D6.9 | The directive reportedly cites Section 734.13 of the EAR as the basis on which model access is controlled. Koren, Kurland and Mehta state that this same section was used by Commerce in three previous Advisory Opinions as the reason why remote access transactions are not subject to the EAR | T1 | Recorded |
| D6.10 | Koren, Kurland and Mehta state that the House of Representatives passed the Remote Access Security Act because ECRA does not authorize regulating remote access | T1 | Recorded |
| D6.11 | The directive reportedly also cites Section 744.22 of the EAR. Koren, Kurland and Mehta state that this section only allows Commerce to impose licence requirements on a small group of adversarial countries, not a worldwide control | T1 | Recorded |
| D6.12 | Koren, Kurland and Mehta state that now that export controls have been used to control model access, every company must consider the possibility of such controls being used again | T1 | Recorded |
| D6.13 | Koren, Kurland and Mehta state that uncertainty over durable access to any specific US AI model is likely to drive potential foreign customers to consider options they deem more reliable, and that European politicians have cited the controls as further evidence of the need for sovereign AI, with dependency on US AI seen as a supply chain vulnerability | T1 | Recorded |
| D6.14 | Koren, Kurland and Mehta identify three regulatory paths to restoration: negotiated retraction by Commerce, legal action contesting the basis or country scope, or identity and citizenship verification of all users | T1 | Recorded |
| D6.15 | Anthropic states that, following the US government's approval on 26 June 2026, it restored access to Mythos 5 for a set of US organizations, and that it continues to coordinate with the government to expand access to the broader set of domestic and international partners in the Glasswing program | T1 | Recorded |
| D6.17 | Anthropic states that its understanding is that the government believes it has become aware of a method of bypassing, or "jailbreaking", Fable 5 | T1 | Recorded |
| D6.18 | Anthropic states that it reviewed a demonstration of the technique being used to identify a small number of previously known, minor vulnerabilities, that these appear relatively simple, and that other publicly available models are able to discover them without requiring a bypass | T1 | Recorded |
| D6.19 | Anthropic states that it reviewed a report it believes is the basis of the government's directive and validated that the level of capability displayed there is widely available from other models, including OpenAI's GPT-5.5, and is used every day by the defenders who keep systems safe | T1 | Recorded |
| D6.20 | Anthropic states that to the date of the statement the government had given it only verbal evidence of a potential narrow, non universal jailbreak, consisting of asking the model to read a specific codebase and fix any software flaws | T1 | Recorded |
| D6.21 | Anthropic states that it is complying with the directive while disagreeing that the finding of a narrow potential jailbreak should be cause for recalling a commercial model deployed to hundreds of millions of people | T1 | Recorded |
| D6.22 | Anthropic states that it believes the government should have the ability to block unsafe deployments as part of a statutory process that is transparent, fair, clear, and grounded in technical facts, and that this action does not adhere to those principles | T1 | Recorded |
| D6.23 | Anthropic states that it has required 30 day retention of customer data with Fable, described as a policy change that carries real costs with customers, to allow research into and mitigation of jailbreaks | T1 | Recorded |
| ID | Claim | Tier | Status |
|---|---|---|---|
| D7.1 | Legion LegalTech, Corp. v. United States of America was filed on 23 June 2026 in the United States District Court for the District of Columbia, Case No. 1:26-cv-02225-RJL, assigned to Judge Richard J. Leon. Cause: 28 U.S.C. § 2201 Declaratory Judgment | T1 | Recorded |
| D7.2 | Defendants are the United States of America, the Department of Commerce, Howard Lutnick in his official capacity as Secretary of Commerce, the Bureau of Industry and Security, Jeffrey Kessler in his official capacity as Under Secretary of Commerce for BIS, the Executive Office of the President, and Doe Defendants 1 to 10. Anthropic is not a party | T1 | Recorded |
| D7.3 | The complaint pleads three causes of action: (1) ultra vires, excess of export control authority; (2) ultra vires under IEEPA and violation of the Berman informational materials exemption; (3) APA, arbitrary and capricious agency action | T1 | Recorded |
| D7.4 | By minute order of 25 June 2026, the court directed defendants to respond to the motion for preliminary injunction by 14 July 2026, plaintiff to reply by 21 July 2026, with a hearing no earlier than the week of 27 July 2026 | T1 | Recorded |
| D7.5 | Legion pleads that it is a commercial customer of Anthropic, PBC under Anthropic's Commercial Terms of Service, maintains a Zero Data Retention agreement with Anthropic, and accesses Anthropic models both through business accounts and through Amazon Web Services' Amazon Bedrock platform for pre-production testing | T1 as to the pleading | Recorded |
| D7.6 | Legion pleads that the directive gave Anthropic ninety minutes to comply under threat of "prompt criminal and civil penalties", that the BIS letter was sent at approximately 5:30 pm Eastern on 12 June 2026, and that users lost access by approximately 10:00 pm | T1 as to the pleading | Recorded |
| D7.7 | Legion pleads that Anthropic publicly released Fable 5 on or about 9 June 2026, and that according to public reporting Anthropic had notified the Government multiple times in advance of the planned release and the Government did not object | T1 as to the pleading | Recorded |
| D7.8 | Legion pleads that access to all other Anthropic models was unaffected. Only Fable 5 and Mythos 5 were suspended | T1 as to the pleading | Recorded |
| D7.9 | Legion pleads that neither it nor, upon information and belief, any party inside or outside the United States had access to the underlying model weights, object code or source code | T1 as to the pleading | Recorded |
| D7.10 | Legion pleads that the code analysis capability identified as the basis for the directive remains available through competing products the directive did not restrict, including OpenAI's GPT-5.5 | T1 as to the pleading | Recorded |
| D7.12 | Legion pleads that ECCN 4E091, the only export control classification that ever directly covered advanced AI model weights, was rescinded in May 2025 with no replacement, and that no currently operative classification reaches access to a hosted AI model or its inferential text output | T1 as to the pleading | Recorded |
| D7.13 | Legion pleads that the directive is irreconcilable with Executive Order "Promoting Advanced Artificial Intelligence Innovation and Security", 91 FR 34565, signed 2 June 2026, Section 3(c) of which provided that nothing in that section authorises "a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models" | T1 as to the pleading | Recorded |
| D7.14 | Legion pleads, citing public reporting, that an administration official stated models at or above the capability of Mythos "would need to go through the administration", and that a person familiar with the Government's thinking described the result as a "de-facto licensing regime" | T1 as to the pleading | Recorded |
| D7.15 | Legion pleads that at the G7 summit on 18 June 2026 the Secretary of Commerce presided over discussions with AI executives regarding restoration of access, and that French President Macron publicly stated: "We won't buy any models made by these companies if overnight, you can just flip the switch" | T1 as to the pleading | Recorded |
| D7.16 | Legion pleads that its software development team includes Canadian nationals working remotely from Canada, a Five Eyes intelligence partner and a Country Group A:5 nation under the EAR, and that 15 C.F.R. § 734.20 expressly authorises releases to nationals of Country Group A:5 countries including Canada | T1 as to the pleading | Recorded |
| D7.17 | Legion pleads that the harm is immediate, irreparable, and existential, that competitive ground lost during a suspension cannot be regained, and that because its claims lie against the federal government its economic losses are unrecoverable as damages | T1 as to the pleading | Recorded |
| D7.18 | Legion pleads that a court in the Northern District of California found approximately ninety days before the directive that an earlier government action against Anthropic under a national security label was likely pretextual and that the real motive was unlawful retaliation, citing Anthropic PBC v. U.S. Dep't of War, No. 26-CV-01996-RFL, 2026 WL 836842, at \*17 (N.D. Cal. Mar. 26, 2026) | T1 as to the pleading | Recorded |
| D7.19 | Legion seeks a declaratory judgment that the directive is unlawful, vacatur, preliminary and permanent injunctive relief, and a stay under 5 U.S.C. § 705 | T1 | Recorded |
| ID | Claim | Tier | Status |
|---|---|---|---|
| E1 | The CPS 230 in force was determined by Banking, Insurance, Life Insurance, Health Insurance and Superannuation (prudential standard) determination No. 1 of 2026, made 23 April 2026 by Ian Beckett, Acting Executive Director, Policy and Advice Division | T1 | Supported |
| E2 | That determination revokes determination No. 2 of 2023 and the CPS 230 made under it, as varied by variation No. 1 of 2024. The 2026 instrument gives effect to targeted amendments finalised 30 April 2026 introducing limited exemptions for certain non traditional service providers | T1 | Supported |
| E3 | This Prudential Standard commences on 1 July 2026 | T1 | Supported |
| E4 | Offshoring does not include arrangements where the physical location of a service is performed within Australia, but the service provider is not incorporated in Australia | T1 | Supported. Central finding |
| E5 | Offshoring does include arrangements where the provider is incorporated in Australia but the service is physically performed outside Australia | T1 | Supported |
| E6 | For all APRA regulated entities, a provider of core technology services must be classified as a material service provider unless the entity can justify otherwise | T1 | Supported. Rebuttable classification, not a deeming provision |
| E7 | An entity must, at a minimum, classify as critical operations, unless it can justify otherwise: for an ADI, payments, deposit taking and management, custody, settlements and clearing; and for all APRA regulated entities, customer enquiries and the systems and infrastructure needed to support critical operations | T1 | Supported. Rebuttable classification, as with E6 |
| E8 | The Board is ultimately accountable for oversight of operational risk management, including business continuity and the management of service provider arrangements | T1 | Supported |
| E9 | Before entering or materially modifying a material arrangement, an entity must assess financial and non financial risks from reliance on the provider, including risks associated with geographic location or concentration | T1 | Supported |
| E10 | For each material arrangement an entity must ensure it can execute its BCP if needed and can conduct an orderly exit from the arrangement if needed | T1 | Supported |
| E11 | Tolerance levels must be set for maximum period of disruption tolerated, maximum extent of data loss accepted, and minimum service levels under alternative arrangements | T1 | Supported |
| E12 | The Attachment lists categories of exempt service providers. Cloud and technology infrastructure providers are not among them | T1 | Supported |
| E13 | The limited exemption at para 57 requires both Attachment membership and that the arrangement uses standardised terms or is not documented in a formal agreement | T1 | Supported |
| E14 | The phrase "unable to provide the service for an extended period of time" does not appear in CPS 230 | T1 | Supported. Attribute to guidance only |
| E15 | An entity must manage its full range of operational risks, including but not limited to legal risk, regulatory risk, compliance risk, conduct risk, technology risk, data risk and change management risk | T1 | Supported. Second central finding |
| E16 | An entity must not rely on a service provider unless it can ensure that in doing so it can continue to meet its prudential obligations in full and effectively manage the associated risks | T1 | Supported |
| E17 | Assessment of operational risk profile must include the impact of new products, services, geographies and technologies | T1 | Supported |
| E18 | A formal agreement for a material arrangement must set out ownership and control of data, and must include provisions to ensure the ability of the entity to meet its legal and compliance obligations | T1 | Supported |
| E19 | An entity must notify APRA prior to entering any material offshoring arrangement | T1 | Supported |
| E20 | BCP testing must include severe but plausible scenarios including disruptions to services provided by material service providers | T1 | Supported |
| E21 | An entity must maintain a comprehensive assessment of its operational risk profile, and as part of this must identify and document the processes and resources needed to deliver critical operations, including people, technology, information, facilities and service providers, the interdependencies across them, and the associated risks, obligations, key data and controls | T1 | Supported |
| E22 | An entity must identify and maintain a register of its material service providers and manage the material risks associated with using these providers. Material service providers are those on which the entity relies to undertake a critical operation or that expose it to material operational risk | T1 | Supported |
| E23 | An entity must submit its register of material service providers to APRA on an annual basis | T1 | Supported |
| ID | Claim | Tier | Status |
|---|---|---|---|
| F1 | A prudent entity would assess the risks of engaging a service provider in another jurisdiction to determine if it is within appetite | T1 | Supported |
| F2 | That assessment is directed to five considerations: (i) ability to continue operations and meet core obligations following a loss of service; (ii) maintenance of information security; (iii) ability to own and manage controls on its behalf; (iv) compliance with legislative and prudential requirements; and (v) impediments, legal and technical, to APRA being able to fulfil its duties, including timely access to information in a usable form | T1 | Supported |
| F3 | The only consideration directed at legal reach concerns impediments to APRA's access. No consideration is directed at the ability of a foreign government to compel disclosure from the provider | T1 | Supported as to the content of the five considerations and the absence of a sixth. |
| F4 | CPG 230 frames the jurisdiction question locationally, as engaging a provider "in another jurisdiction", consistent with CPS 230 footnote 16 | T1 | Supported |
| F5 | The phrase "where the service provider is unable to provide the service for an extended period of time" appears in CPG 230 as a matter a service provider management policy would usually include | T1 | Supported. Confirms E14 |
| F6 | APRA refers to the exempt categories as non traditional service providers, intended to capture providers typically market mandated or otherwise not engaged through standard procurement or contractual processes, where arrangements often lack a formal agreement or use standardised terms that cannot be negotiated | T1 | Supported |
| F7 | Where an entity uses a service provider, the entity still owns and is responsible for managing its risk | T1 | Supported |
| F8 | In identifying critical operations a prudent entity would consider operations that if disrupted would affect its ability to comply with legal or regulatory requirements | T1 | Supported |
Every source, with hash
Per-source hashes are published in full: reference, name, URL, retrieval timestamp (UTC), artefact type, and SHA-256 of the archived artefact. This is a deliberate divergence from the prior house pattern and becomes the standard. Hashes are verifiable against the archive with shasum -a 256.
| Ref | Name | URL | Retrieved (UTC) | Artefact type | SHA-256 |
|---|---|---|---|---|---|
| S1 | CBA Newsroom, 'CommBank and AWS expand collaboration to deliver global best cloud and AI capabilities', 4 Feb 2025 | https://www.commbank.com.au/articles/newsroom/2025/02/amazon-web-services-collaboration.html | 2026-07-18T08:36:07Z | Editable web page | 61d86d27f44a3e919d590004013bd801ed23ab0a2a50147612a0905cb3003016 |
| S2 | CBA Newsroom, 'CommBank accelerates AI integration with major data migration to cloud', 4 June 2025 | https://www.commbank.com.au/articles/newsroom/2025/06/cba-ai-migration-cloud.html | 2026-07-18T08:36:11Z | Editable web page | 4bd92e17f5a13dd9ac7cab3487d2860000b82c91a8e26859743f450213d2e33f |
| S3 | Amazon.com, Inc. FY2025 Form 10-K, Exhibit 21.1, filed 6 Feb 2026, period ended 31 Dec 2025 | https://www.sec.gov/Archives/edgar/data/1018724/000101872426000004/amzn-20251231xex211.htm | 2026-07-18T08:36:22Z | Fixed filing | 970ff45f7c9d86f2548306c5c6bdab03c43788db532348158484c471adb434af |
| S4 | ASIC Current Company Extract, AMAZON WEB SERVICES AUSTRALIA PTY LTD, ACN 605 345 891, s1274A Corporations Act 2001 | https://connectonline.asic.gov.au/ (purchased extract, held as PDF) | 2026-07-18T08:36:22Z | Fixed PDF, held | 69eda18e3696b3358db70013d20953749b36e81cc8e3611eb87bf2f589ea08a7 |
| S5 | 18 U.S.C. § 2713 Required preservation and disclosure of communications and records — U.S. Code 2024 Edition, Office of the Law Revision Counsel / GPO official (Cornell LII retained as secondary check) | https://www.govinfo.gov/content/pkg/USCODE-2024-title18/html/USCODE-2024-title18-partI-chap121-sec2713.htm | 2026-07-18T09:11:01Z | Archived HTML + text, SHA-256 (fixed edition) | 3a242ef2c1ee7a061f44bfb8daf7952839a4c4f2763d586e4af7ab1d6f5b4f42 |
| S6 | 18 U.S.C. § 2711 Definitions for chapter — U.S. Code 2024 Edition, OLRC / GPO official (Cornell LII retained as secondary check) | https://www.govinfo.gov/content/pkg/USCODE-2024-title18/html/USCODE-2024-title18-partI-chap121-sec2711.htm | 2026-07-18T09:11:01Z | Archived HTML + text, SHA-256 (fixed edition) | 8937cc8fd9c5b3e264379d0e852fa9e374d17645a569a83cc09a757f5d3aae82 |
| S7 | 18 U.S.C. § 2510 Definitions — U.S. Code 2024 Edition, OLRC / GPO official (Cornell LII retained as secondary check) | https://www.govinfo.gov/content/pkg/USCODE-2024-title18/html/USCODE-2024-title18-partI-chap119-sec2510.htm | 2026-07-18T09:11:01Z | Archived HTML + text, SHA-256 (fixed edition) | 1797f9f58adaff71652cd240177b5e95613a962f664f788cb45388310050734e |
| S8 | APRA, Prudential Standard CPS 230 Operational Risk Management, July 2026 clean text | https://www.apra.gov.au/system/files/2026-05/Prudential%20Standard%20-%20CPS%20230%20Operational%20Risk%20Management%20-%20clean.pdf | 2026-07-18T08:36:24Z | Fixed PDF | ed84ff3a62432559ba351aeb7cdd66bc62fb34d9366be67b3f7c5d11d1d968e9 |
| S9 | APRA, CPS 230 standard page including determination preamble | https://www.apra.gov.au/standards/cps-230 | 2026-07-18T08:36:13Z | Editable web page | b3acdba662856b23d67a7fe447a54e42e60f94f3cbc2deef1705343c8c5cc941 |
| S10 | APRA, CPG 230 Operational Risk Management, current version | https://www.apra.gov.au/practice-guides/cpg-230 | 2026-07-18T08:36:15Z | Editable web page | 8375417c1b059fc1d5af1792c3fd51d8cab18341e4357faa09422a0e417a1a86 |
| S11 | APRA media release, 'APRA finalises targeted amendments to CPS 230 Operational Risk Management', 30 Apr 2026 | https://www.apra.gov.au/news-and-publications/apra-finalises-targeted-amendments-to-cps-230-operational-risk-management | 2026-07-18T08:36:18Z | Editable web page | bff890d80bb6f9fd9c3a728b3495848883e42adaae7c533bc1839df804d5e878 |
| S12 | Anthropic on Bedrock Commercial Terms of Service, effective January 2024 | https://www-cdn.anthropic.com/6b68a6508f0210c5fe08f0199caa05c4ee6fb4dc/Anthropic-on-Bedrock-Commercial-Terms-of-Service_Dec_2023.pdf | 2026-07-18T08:36:25Z | Fixed PDF | 4b9b413733f10efbbfcd5521033d3bb60308a54f8bb6238d1245cb677e607b22 |
| S13 | Anthropic, 'Statement on the US government directive to suspend access to Fable 5 and Mythos 5', 12 June 2026 | https://www.anthropic.com/news/fable-mythos-access | 2026-07-18T08:36:19Z | Editable web page | 6b903d76c24e0e78f2666684eba98de0cdf16f442ae93ee52926980b26cc2576 |
| S14 | Anthropic, 'Redeploying Claude Fable 5', 30 June 2026 | https://www.anthropic.com/news/redeploying-fable-5 | 2026-07-18T08:36:25Z | Editable web page | 9362ea86ad32b7b49969e91c8578949699c077573951ca1f9f69b56ecd152354 |
| S15 | Legislative instrument F2026L00475 | https://www.legislation.gov.au/F2026L00475/asmade/text | 2026-07-18T08:36:26Z | Fixed instrument. Paragraph numbering confirmed via S8 | f735b5ec40bf4f5bdad7e4bc9dc1bb2a877ca365855649253d58f121d30f6561 |
| S16 | CBA Newsroom, 'CommBank expands strategic partnership with generative AI company, Anthropic', March 2025 | https://www.commbank.com.au/articles/newsroom/2025/03/anthropic.html | 2026-07-18T08:36:28Z | Editable web page | 367228b4775b6f2f6f90fc59d991c534dc084e42ce9addbb38afb98a8d5a0f83 |
| S17 | CBA Newsroom, 'CommBank ranks among world's best banks for AI maturity', Oct 2025 (OpenAI partnership) | https://www.commbank.com.au/articles/newsroom/2025/10/commbank-among-best-banks-ai-maturity1.html | 2026-07-18T08:36:29Z | Editable web page | 61db414ee94e8ccf8839a2d9f20cedb6441ddd58a0a0df776b48900dd6b87b44 |
| S18 | APRA, CPG 230 Operational Risk Management, June 2024 PDF (superseded numbering, do not cite) | https://www.apra.gov.au/sites/default/files/2024-06/Prudential%20Practice%20Guide%20CPG%20230%20Operational%20Risk%20Management.pdf | 2026-07-18 | Fixed PDF, superseded | — (superseded; no artefact) |
| S19 | Koren, Kurland and Mehta, 'The Department of Commerce Restricted Access to Anthropic's Latest Models. What Comes Next?', CSIS Critical Questions, 16 June 2026 | https://www.csis.org/analysis/department-commerce-restricted-access-anthropics-latest-models-what-comes-next | 2026-07-18T09:56:11Z | Editable web page. Archive required | 1293d84e3b7f0c2f428261bcfb56fa6f9f24b87ce480f3dcd4cae930e0f75b08 |
| S20 | Complaint, Legion LegalTech, Corp. v. United States of America, No. 1:26-cv-02225-RJL (D.D.C. filed 23 June 2026), 43pp | https://storage.courtlistener.com/recap/gov.uscourts.dcd.293776/gov.uscourts.dcd.293776.1.0.pdf | 2026-07-18T09:56:11Z | Fixed court filing. Archive required | fa38bd28607b933957adcabec678b405d10532ca98ee3a6e28991422d031f156 |
| S21 | Commerce Department letter, 26 June 2026. Not public. D6.15 is sourced to S14, Anthropic's own statement. | — | — | Not public | — (not public) |
| S22 | Delaware Division of Corporations, entity search, ANTHROPIC, PBC, File No. 4860621 | https://icis.corp.delaware.gov/ecorp/entitysearch/namesearch.aspx | 2026-07-18T10:17:44Z | State register. Held PDF, archived and hashed | 08253947d7d7103187423ef94550cdb0ee4f3634e66f684b297e0048268003a2 |
| S23 | GLEIF LEI record, ANTHROPIC, PBC, LEI 984500B6DEB8CEBC4Z70 | https://search.gleif.org/#/record/984500B6DEB8CEBC4Z70 | 2026-07-18T09:56:11Z | Editable web page. Archive required | a40fab8fd14c8b0c2e04ddbed479835f8a3691c842cf111394b757de6a23d574 |
| S24 | Delaware Division of Corporations, entity search, OPENAI GROUP PBC, File No. 10381551 | https://icis.corp.delaware.gov/ecorp/entitysearch/namesearch.aspx | 2026-07-18T10:17:44Z | State register. Held PDF, archived and hashed | 5ad3a6a2420240af8b8ec72130d002a6121a23d395755a6e82e164c7f7a24b39 |
| S25 | OpenAI, 'Our structure' | https://openai.com/our-structure/ | 2026-07-18T10:13:42Z | Editable web page. Browser save archived and hashed (current structure). See warning below | 33ecee0cfd9028e48c261ee831e63c13f368e6855c7cb534977fcf4e97173514 |
| S26 | CourtListener docket, Legion LegalTech, Corp. v. United States of America, 1:26-cv-02225 (D.D.C.) | https://www.courtlistener.com/docket/73520460/legion-legaltech-corp-v-united-states-of-america/ | 2026-07-18T09:56:11Z | Editable web page. Archive required | 5670c63d8a77d584874b6f135b6d91801de51765c853a85393193b50fbba3cfa |
Contestable steps
Each names a step at which a reasonable reader could disagree. They are load-bearing and are not softened.
The corporate structure is established from two regulators. What is not established by structure alone is whether a parent's ownership of a wholly owned foreign subsidiary places that subsidiary's customer data within the parent's possession, custody or control for the purposes of § 2713. That is a question of US law, unsettled, and not determined by this assessment.
Nothing in the record establishes that any US legal process has been directed at CBA data. The claim is structural reachability, not demonstrated access.
Sutherland's statement refers to the data platform. Whether it extends to all bank data in every system is not established.
Reduction of on premises footprint raises a continuity question distinct from the CLOUD Act question, and the two must not be merged. Continuity was identified, but the public record does not permit a finding: the bank's business continuity plan, exit arrangements and tolerance levels are internal documents that are not public and will not become public. It is therefore not assessed. It is not reserved or pending; there is no future date at which the public evidence would support a finding.
Named as migration partner only. No claim of ongoing data processing is supported.
Section 2713 attaches to a provider of either electronic communication service or remote computing service. Remote computing service carries a "to the public" qualifier at 2711(2) [B6]; a single tenant negotiated arrangement with one institution is not obviously provision to the public, and that objection is well taken. Electronic communication service at 2510(15) carries no such qualifier [B10], but its application here is strained in two respects that the assessment concedes rather than resolves. First, the definition is the provision to users of the ability to send or receive wire or electronic communications; passive storage and compute are a poor fit for that description, and the characterisation is strongest for communication carrying services in the estate and weakest for the remainder. Second, a respondent may argue that the entity providing users the ability to send or receive communications is the bank itself, and that the provider supplies infrastructure to the bank one step removed. Whether the electronic communication service is the provider or the bank is unresolved and material.
The silence at C1 to C3 is a silence in the public assurance record, not in the executed agreement, which has not been seen. No inference may be drawn about contractual terms.
18 USC 2510(12)(D) excludes from the definition of "electronic communication" electronic funds transfer information stored by a financial institution in a communications system used for the electronic storage and transfer of funds [B11]. The exclusion is narrow: it reaches only EFT information, and only such information held in a funds transfer system. It does not remove personal information, identity records, documents, analytics or model inputs and outputs from the chapter. Further, section 2713 reaches "any record or other information pertaining to a customer or subscriber" as well as the contents of communications [B14], and EFT information excluded from the communication limb may be recaptured by that limb. The assessment therefore cannot claim that all bank data is within reach, and equally cannot concede that a substantial proportion falls outside the chapter. Contestable and unresolved: a respondent may argue the existence of the (D) carve out signals an intention to keep funds transfer data outside the scheme notwithstanding the catch all.
Only Fable 5 and Mythos 5 were controlled in June 2026; access to all other Anthropic models was unaffected [D6.3]. CommBiz Gen AI runs on Claude 3 [D2] and was not disrupted. Any Exposure Two claim must state this before advancing the structural finding.
Anthropic does not have access to Customer Content under the Bedrock terms [D5.8]. The exposure at 2.6 is availability, not disclosure. It must not be merged with the § 2713 analysis.
The lawfulness of the June 2026 directive is the subject of undetermined litigation in the United States District Court for the District of Columbia. A hearing on preliminary relief was listed for no earlier than the week of 27 July 2026. Claims in the D7 series record allegations made in a pleading, not findings. The legal position may change, and any assessment relying on these claims should state the date to which it speaks.
The bank states that it has made an investment in a model provider [D1]. Whether that investment is equity or another instrument is not publicly established, and the source states only investment and strategic investment. Whether the bank holds any direct contractual relationship with that provider, distinct from the terms applicable to access through the intermediary, is also not established. No inference is drawn from the existence of the investment.
This assessment does not construe the terms. It records what they say. Whether an Australian customer would in practice have any remedy under a contract governed by California law, and whether the exclusion of liability at D5.4 would be effective in any given forum, are questions of law and of contract construction that this assessment does not reach and is not qualified to reach.
D6.2 states that the models were disabled for all customers. It does not name the intermediary. The proposition that Bedrock customers were among those affected follows from the terms at D5.1, under which a party accessing models through that platform is a customer of the provider. A reasonable reader may contest that step. The pleaded instance at D7.5 and D7.6 corroborates it but is an allegation in undetermined litigation and is not relied on as proof.
D6.7 to D6.11 are statements by named authors published by an institution that records that it does not take specific policy positions and that views expressed are those of the authors. They establish that the basis is contested by credible analysts. They do not establish that it is invalid, and this assessment does not assert that it is.
What is and is not assessed
This assessment publishes on Exposure One, compellability, and Exposure Two, availability.
Exposure One · Compellability. Whether data held for the bank is within reach of United States legal process by reason of the provider's incorporation. Assessed.
Exposure Two · Availability. Whether the bank's dependency on providers of artificial intelligence models is subject to interruption by decision of a foreign government, by reason of the providers' incorporation. Assessed. Held at Section D and the D7 series. See CS9, CS10, CS11 and CS12.
Continuity. Whether concentration on a single provider, combined with a stated reduction in on premises capability, creates a continuity risk under CPS 230. Identified and not assessable on the public record. Not numbered, not reserved. The bank's business continuity plan, exit arrangements and tolerance levels are internal documents that are not public and will not become public. Claims bearing on it are retained at A1, A3, A6, A7, A10, E10, E11, E16, E20, where they are load-bearing for Exposure One or stand as legitimate context. See CS4.
The assessment alleges no wrongdoing by Amazon Web Services, Amazon.com, Anthropic, OpenAI, or any provider named; it alleges no compulsion, disclosure or breach; and it determines no question of law. AustraliaOS is not qualified to give legal advice and does not do so.
Assessment PDF
The attested assessment is the signed PDF. Its SHA-256 is published below; the verification status set out on this page is reflected in the document footer.