Verification Record
AOS-CBA-2026-001 · v1.0

Jurisdictional Exposure of Commonwealth Bank Cloud and Model Dependencies

Whether data held for the Commonwealth Bank of Australia is within reach of United States legal process by reason of the provider's incorporation. Exposure One (compellability) and Exposure Two (availability). Every claim is recorded against a primary source a reader can open; where a step is inference it is named as a contestable step. This record lists every claim, its tier, and its status, and every source with its URL, retrieval timestamp, artefact type and SHA-256.

Reference
AOS-CBA-2026-001
Subject
Commonwealth Bank of Australia · AWS dependency · Exposure One (compellability) and Exposure Two (availability)
Date
18 July 2026
Classification
Released
Version
1.0
Signed by
Brunel Al-Bijwaie, Director, AustraliaOS Pty Ltd
Status

Verification status

Claim census by evidence tier. T1 is a primary source retrieved directly; T3 is secondary reporting held pending a primary source.

Total claims
118
T1
118
T3
0
T2 / T4
0

Every claim is at evidence tier one — a primary source retrieved directly and archived — with no claim resting on secondary reporting. D6.15 (Anthropic's statement on restoration of access) is sourced to S14, the provider's own statement, and sits at T1; the non-public Commerce letter of 26 June 2026 (S21) is recorded but not relied on for any claim.

Claims

Every claim, by section

All 118 claims, in document order, each with its tier and recorded status.

Section A · The dependency (CBA first party admissions)
IDClaimTierStatus
A1CBA entered a five year strategic collaboration with AWS, continuing AWS as the bank's preferred cloud providerT1Supported
A2CBA is rearchitecting a significant percentage of its workloads onto AWST1Supported
A3Core platforms and applications including Netbank, CommSec and MUREX have migrated to AWS from on premises environmentsT1Supported
A4CBA's DevOps Hosting Platform is hosted on AWS, with native integration to Amazon Bedrock for model access and RAGT1Supported
A5CBA's AI Factory, launched September 2024, is powered by Amazon EC2 P5 instancesT1Supported
A6CBA has completed migrating its data platform to AWST1Supported
A7CBA has migrated 100 per cent of its data to the cloud (statement of Terri Sutherland, CBA Lead for Data Platforms)T1Supported
A8The migration involved over 61,000 data pipelines, commencing July 2024T1Supported
A9CBA operates over 2,000 AI models against approximately 157 billion data points, making around 55 million decisions dailyT1Supported
A10CBA states an intention to reduce its on premises data centre footprint as a consequence of the migrationT1Supported
A11The migration was delivered with HCLTech as partnerT1Supported (role limited to migration delivery on the face of the record)
Section B · The corporate chain and the statute
IDClaimTierStatus
B1Amazon Web Services, Inc. is a Delaware corporation, 100 per cent owned by Amazon.com, Inc.T1Supported
B2Amazon Data Services, Inc. is a Delaware corporation, 100 per cent owned by Amazon.com, Inc.T1Supported
B3Amazon Web Services Australia Pty Ltd is an Australian proprietary company limited by shares, ACN 605 345 891 / ABN 63 605 345 891, registered 22 April 2015, status Registered, registered office Level 37, 2-26 Park Street, Sydney NSW 2000T1Supported
B4The ultimate holding company of Amazon Web Services Australia Pty Ltd is AMAZON.COM, INC. (Org No. 624 502 263)T1Supported
B518 USC 2713 obliges a provider of electronic communication service or remote computing service to preserve, backup or disclose contents and records within its possession, custody or control, regardless of whether located within or outside the United StatesT1Supported
B618 USC 2711(2) defines "remote computing service" as the provision to the public of computer storage or processing services by means of an electronic communications systemT1Supported
B7The sole member of Amazon Web Services Australia Pty Ltd is AMAZON WEB SERVICES, INC. (Org No. 663 081 114), of 251 Little Falls Drive, Wilmington, Delaware, holding 231,800,001 ordinary shares beneficially and fully paid, being the entire issued capitalT1Supported
B8The Delaware entity identified at B7 as sole member of the Australian entity is the same entity identified at B1 in Amazon.com, Inc.'s SEC filing as a Delaware corporation 100 per cent owned by Amazon.com, Inc.T1Supported. Two independent regulators concur
B918 USC 2711(1) provides that terms defined in 18 USC 2510 have, respectively, the definitions given in that sectionT1Supported
B1018 USC 2510(15) defines "electronic communication service" as any service which provides to users thereof the ability to send or receive wire or electronic communications. No "to the public" qualifierT1Supported
B1118 USC 2510(12) defines "electronic communication" but excludes at (D) electronic funds transfer information stored by a financial institution in a communications system used for the electronic storage and transfer of fundsT1Supported. Limits the claim. See CS8
B1218 USC 2510(14) defines "electronic communications system" to include any computer facilities or related electronic equipment for the electronic storage of such communicationsT1Supported
B1318 USC 2510(17) defines "electronic storage" to include any storage of such communication by an electronic communication service for purposes of backup protectionT1Supported
B1418 USC 2713 reaches not only the contents of a wire or electronic communication but also "any record or other information pertaining to a customer or subscriber" within the provider's possession, custody or controlT1Supported. See CS8
Section C · The assurance silence
IDClaimTierStatus
C1AWS's public assurance to CBA cites security, resilience, availability and regulatory obligations, and does not address foreign legal compellability (statement of Jamie Simon, Director of Financial Services, AWS ANZ)T1Supported
C2AWS's second public assurance to CBA cites security, compliance and resilience at scale, and does not address foreign legal compellability (same spokesperson)T1Supported
C3The absence identified at C1 and C2 appears in two separate announcements by the same vendor representative. Whether this reflects anything beyond the ordinary scope of a commercial announcement is not established by the record and is not claimed.T1Supported as to repetition only
Section D · Exposure Two · Availability (assessed)
IDClaimTierStatus
D1CBA holds an expanded strategic partnership with, and investment in, Anthropic. Gavin Munroe, Group CIO, named. Krishna Rao, Anthropic CFO, confirms strategic investmentT1Recorded
D2CommBiz Gen AI uses Claude 3 and Cohere via Amazon Bedrock Knowledge Bases, with Amazon OpenSearch as vector databaseT1Recorded
D3CBA states it was the first Australian company to enter a strategic partnership with OpenAIT1Recorded
D4Anthropic, PBC is a Delaware public benefit corporation, Delaware entity ID 4860621, LEI 984500B6DEB8CEBC4Z70, created 26 January 2021T1Recorded
D4 series · Provider incorporation
IDClaimTierStatus
D4.1ANTHROPIC, PBC is registered with the Delaware Division of Corporations, File Number 4860621, Entity Kind Corporation, Entity Type Benefit Corporation, Residency Domestic, State Delaware, incorporation date 26 January 2021. Registered agent Corporation Service Company, 251 Little Falls Drive, WilmingtonT1Recorded
D4.2GLEIF records ANTHROPIC, PBC, LEI 984500B6DEB8CEBC4Z70, jurisdiction of formation US-DE, entity status ACTIVE, corroboration level FULLY_CORROBORATED, validated against the Delaware Division of Corporations under registration 4860621T1Recorded
D4.3The GLEIF record reports no direct parent and no ultimate parent (NO_KNOWN_PERSON exception reported for both), and no direct or ultimate childrenT1Recorded
D4.4OPENAI GROUP PBC is registered with the Delaware Division of Corporations, File Number 10381551, Entity Kind Corporation, Entity Type Benefit Corporation, Residency Domestic, State Delaware, incorporation date 28 October 2025. Registered agent The Corporation Trust CompanyT1Recorded
D4.5OpenAI states that under its updated structure announced 28 October 2025, the nonprofit is the OpenAI Foundation and the for-profit is a public benefit corporation called OpenAI Group PBC, which the Foundation continues to controlT1Recorded
D4.6OpenAI states that as of the closing of the recapitalisation the OpenAI Foundation holds a 26 per cent equity stake in OpenAI Group, Microsoft holds roughly 27 per cent, and the remaining 47 per cent is held by current and former employees and investorsT1Recorded
D4.7OpenAI states that through special voting and governance rights held solely by the Foundation, the Foundation appoints all members of the OpenAI Group board and can replace directors at any timeT1Recorded
D5 series · Anthropic on Bedrock Commercial Terms of Service
IDClaimTierStatus
D5.1The Services are those made available through Amazon Bedrock, hosted and managed by Amazon Web Services, Inc.T1Recorded
D5.2Anthropic may require that AWS suspend Customer's access to any portion or all of the Services if Anthropic reasonably believes or determines that Anthropic's provision of the Services to Customer is prohibited by applicable lawT1Recorded
D5.3Anthropic may terminate immediately with Notice if it reasonably believes or determines that provision of the Services to Customer is prohibited by applicable lawT1Recorded
D5.4Anthropic will have no liability for any damage, liabilities, losses (including any loss of data or profits), or any other consequences that Customer may incur because of a Service SuspensionT1Recorded
D5.5The Terms are governed by the laws of the State of California. All suits will be instituted exclusively in federal or state courts located in San Francisco, California, and each Party irrevocably submits to their exclusive jurisdictionT1Recorded
D5.6Customer and its Users may only use the Services in the countries and regions Anthropic currently supportsT1Recorded
D5.7Confidential Information may be disclosed to the extent required by law, or court or administrative order, with notification to the discloser except where expressly prohibitedT1Recorded
D5.8The technology provided by Anthropic to AWS does not give Anthropic access to Customer's AWS instance, including Prompts or Outputs. Anthropic does not anticipate obtaining any rights in or access to Customer ContentT1Recorded
D6 series · The June 2026 export control directive
IDClaimTierStatus
D6.1The US government, citing national security authorities, issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employeesT1Recorded
D6.2The net effect of the order was that Anthropic abruptly disabled Fable 5 and Mythos 5 for all customers to ensure complianceT1Recorded
D6.3Access to all other Anthropic models was not affectedT1Recorded
D6.4The directive was received at 5:21pm ET on 12 June 2026. The letter did not provide specific details of its national security concernT1Recorded
D6.5Anthropic complied with the directive while disagreeing with its basisT1Recorded
D6.6The order took effect immediately; Anthropic had no reliable way to verify nationality in real time and therefore suspended access for all users. Export controls were lifted 30 June 2026; Fable 5 access restored 1 July 2026T1Recorded
D6.7Koren, Kurland and Mehta state that the ECRA authority to establish interim controls on emerging and foundational technologies has no regulatory framework in the EAR, and that this is why it has never before been used as the basis for issuing a control. The statute does not explicitly allow a worldwide "is informed" control but does not exclude it eitherT1Recorded
D6.8Koren, Kurland and Mehta state it is unclear how user access to models equates to a release of EAR software or technology to any foreign national except those working at Anthropic, and that the models or model weights are not being exportedT1Recorded
D6.9The directive reportedly cites Section 734.13 of the EAR as the basis on which model access is controlled. Koren, Kurland and Mehta state that this same section was used by Commerce in three previous Advisory Opinions as the reason why remote access transactions are not subject to the EART1Recorded
D6.10Koren, Kurland and Mehta state that the House of Representatives passed the Remote Access Security Act because ECRA does not authorize regulating remote accessT1Recorded
D6.11The directive reportedly also cites Section 744.22 of the EAR. Koren, Kurland and Mehta state that this section only allows Commerce to impose licence requirements on a small group of adversarial countries, not a worldwide controlT1Recorded
D6.12Koren, Kurland and Mehta state that now that export controls have been used to control model access, every company must consider the possibility of such controls being used againT1Recorded
D6.13Koren, Kurland and Mehta state that uncertainty over durable access to any specific US AI model is likely to drive potential foreign customers to consider options they deem more reliable, and that European politicians have cited the controls as further evidence of the need for sovereign AI, with dependency on US AI seen as a supply chain vulnerabilityT1Recorded
D6.14Koren, Kurland and Mehta identify three regulatory paths to restoration: negotiated retraction by Commerce, legal action contesting the basis or country scope, or identity and citizenship verification of all usersT1Recorded
D6.15Anthropic states that, following the US government's approval on 26 June 2026, it restored access to Mythos 5 for a set of US organizations, and that it continues to coordinate with the government to expand access to the broader set of domestic and international partners in the Glasswing programT1Recorded
D6.17Anthropic states that its understanding is that the government believes it has become aware of a method of bypassing, or "jailbreaking", Fable 5T1Recorded
D6.18Anthropic states that it reviewed a demonstration of the technique being used to identify a small number of previously known, minor vulnerabilities, that these appear relatively simple, and that other publicly available models are able to discover them without requiring a bypassT1Recorded
D6.19Anthropic states that it reviewed a report it believes is the basis of the government's directive and validated that the level of capability displayed there is widely available from other models, including OpenAI's GPT-5.5, and is used every day by the defenders who keep systems safeT1Recorded
D6.20Anthropic states that to the date of the statement the government had given it only verbal evidence of a potential narrow, non universal jailbreak, consisting of asking the model to read a specific codebase and fix any software flawsT1Recorded
D6.21Anthropic states that it is complying with the directive while disagreeing that the finding of a narrow potential jailbreak should be cause for recalling a commercial model deployed to hundreds of millions of peopleT1Recorded
D6.22Anthropic states that it believes the government should have the ability to block unsafe deployments as part of a statutory process that is transparent, fair, clear, and grounded in technical facts, and that this action does not adhere to those principlesT1Recorded
D6.23Anthropic states that it has required 30 day retention of customer data with Fable, described as a policy change that carries real costs with customers, to allow research into and mitigation of jailbreaksT1Recorded
D7 series · Litigation (all T1 as to the pleading, source S20)
IDClaimTierStatus
D7.1Legion LegalTech, Corp. v. United States of America was filed on 23 June 2026 in the United States District Court for the District of Columbia, Case No. 1:26-cv-02225-RJL, assigned to Judge Richard J. Leon. Cause: 28 U.S.C. § 2201 Declaratory JudgmentT1Recorded
D7.2Defendants are the United States of America, the Department of Commerce, Howard Lutnick in his official capacity as Secretary of Commerce, the Bureau of Industry and Security, Jeffrey Kessler in his official capacity as Under Secretary of Commerce for BIS, the Executive Office of the President, and Doe Defendants 1 to 10. Anthropic is not a partyT1Recorded
D7.3The complaint pleads three causes of action: (1) ultra vires, excess of export control authority; (2) ultra vires under IEEPA and violation of the Berman informational materials exemption; (3) APA, arbitrary and capricious agency actionT1Recorded
D7.4By minute order of 25 June 2026, the court directed defendants to respond to the motion for preliminary injunction by 14 July 2026, plaintiff to reply by 21 July 2026, with a hearing no earlier than the week of 27 July 2026T1Recorded
D7.5Legion pleads that it is a commercial customer of Anthropic, PBC under Anthropic's Commercial Terms of Service, maintains a Zero Data Retention agreement with Anthropic, and accesses Anthropic models both through business accounts and through Amazon Web Services' Amazon Bedrock platform for pre-production testingT1 as to the pleadingRecorded
D7.6Legion pleads that the directive gave Anthropic ninety minutes to comply under threat of "prompt criminal and civil penalties", that the BIS letter was sent at approximately 5:30 pm Eastern on 12 June 2026, and that users lost access by approximately 10:00 pmT1 as to the pleadingRecorded
D7.7Legion pleads that Anthropic publicly released Fable 5 on or about 9 June 2026, and that according to public reporting Anthropic had notified the Government multiple times in advance of the planned release and the Government did not objectT1 as to the pleadingRecorded
D7.8Legion pleads that access to all other Anthropic models was unaffected. Only Fable 5 and Mythos 5 were suspendedT1 as to the pleadingRecorded
D7.9Legion pleads that neither it nor, upon information and belief, any party inside or outside the United States had access to the underlying model weights, object code or source codeT1 as to the pleadingRecorded
D7.10Legion pleads that the code analysis capability identified as the basis for the directive remains available through competing products the directive did not restrict, including OpenAI's GPT-5.5T1 as to the pleadingRecorded
D7.12Legion pleads that ECCN 4E091, the only export control classification that ever directly covered advanced AI model weights, was rescinded in May 2025 with no replacement, and that no currently operative classification reaches access to a hosted AI model or its inferential text outputT1 as to the pleadingRecorded
D7.13Legion pleads that the directive is irreconcilable with Executive Order "Promoting Advanced Artificial Intelligence Innovation and Security", 91 FR 34565, signed 2 June 2026, Section 3(c) of which provided that nothing in that section authorises "a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models"T1 as to the pleadingRecorded
D7.14Legion pleads, citing public reporting, that an administration official stated models at or above the capability of Mythos "would need to go through the administration", and that a person familiar with the Government's thinking described the result as a "de-facto licensing regime"T1 as to the pleadingRecorded
D7.15Legion pleads that at the G7 summit on 18 June 2026 the Secretary of Commerce presided over discussions with AI executives regarding restoration of access, and that French President Macron publicly stated: "We won't buy any models made by these companies if overnight, you can just flip the switch"T1 as to the pleadingRecorded
D7.16Legion pleads that its software development team includes Canadian nationals working remotely from Canada, a Five Eyes intelligence partner and a Country Group A:5 nation under the EAR, and that 15 C.F.R. § 734.20 expressly authorises releases to nationals of Country Group A:5 countries including CanadaT1 as to the pleadingRecorded
D7.17Legion pleads that the harm is immediate, irreparable, and existential, that competitive ground lost during a suspension cannot be regained, and that because its claims lie against the federal government its economic losses are unrecoverable as damagesT1 as to the pleadingRecorded
D7.18Legion pleads that a court in the Northern District of California found approximately ninety days before the directive that an earlier government action against Anthropic under a national security label was likely pretextual and that the real motive was unlawful retaliation, citing Anthropic PBC v. U.S. Dep't of War, No. 26-CV-01996-RFL, 2026 WL 836842, at \*17 (N.D. Cal. Mar. 26, 2026)T1 as to the pleadingRecorded
D7.19Legion seeks a declaratory judgment that the directive is unlawful, vacatur, preliminary and permanent injunctive relief, and a stay under 5 U.S.C. § 705T1Recorded
Section E · The prudential standard (CPS 230)
IDClaimTierStatus
E1The CPS 230 in force was determined by Banking, Insurance, Life Insurance, Health Insurance and Superannuation (prudential standard) determination No. 1 of 2026, made 23 April 2026 by Ian Beckett, Acting Executive Director, Policy and Advice DivisionT1Supported
E2That determination revokes determination No. 2 of 2023 and the CPS 230 made under it, as varied by variation No. 1 of 2024. The 2026 instrument gives effect to targeted amendments finalised 30 April 2026 introducing limited exemptions for certain non traditional service providersT1Supported
E3This Prudential Standard commences on 1 July 2026T1Supported
E4Offshoring does not include arrangements where the physical location of a service is performed within Australia, but the service provider is not incorporated in AustraliaT1Supported. Central finding
E5Offshoring does include arrangements where the provider is incorporated in Australia but the service is physically performed outside AustraliaT1Supported
E6For all APRA regulated entities, a provider of core technology services must be classified as a material service provider unless the entity can justify otherwiseT1Supported. Rebuttable classification, not a deeming provision
E7An entity must, at a minimum, classify as critical operations, unless it can justify otherwise: for an ADI, payments, deposit taking and management, custody, settlements and clearing; and for all APRA regulated entities, customer enquiries and the systems and infrastructure needed to support critical operationsT1Supported. Rebuttable classification, as with E6
E8The Board is ultimately accountable for oversight of operational risk management, including business continuity and the management of service provider arrangementsT1Supported
E9Before entering or materially modifying a material arrangement, an entity must assess financial and non financial risks from reliance on the provider, including risks associated with geographic location or concentrationT1Supported
E10For each material arrangement an entity must ensure it can execute its BCP if needed and can conduct an orderly exit from the arrangement if neededT1Supported
E11Tolerance levels must be set for maximum period of disruption tolerated, maximum extent of data loss accepted, and minimum service levels under alternative arrangementsT1Supported
E12The Attachment lists categories of exempt service providers. Cloud and technology infrastructure providers are not among themT1Supported
E13The limited exemption at para 57 requires both Attachment membership and that the arrangement uses standardised terms or is not documented in a formal agreementT1Supported
E14The phrase "unable to provide the service for an extended period of time" does not appear in CPS 230T1Supported. Attribute to guidance only
E15An entity must manage its full range of operational risks, including but not limited to legal risk, regulatory risk, compliance risk, conduct risk, technology risk, data risk and change management riskT1Supported. Second central finding
E16An entity must not rely on a service provider unless it can ensure that in doing so it can continue to meet its prudential obligations in full and effectively manage the associated risksT1Supported
E17Assessment of operational risk profile must include the impact of new products, services, geographies and technologiesT1Supported
E18A formal agreement for a material arrangement must set out ownership and control of data, and must include provisions to ensure the ability of the entity to meet its legal and compliance obligationsT1Supported
E19An entity must notify APRA prior to entering any material offshoring arrangementT1Supported
E20BCP testing must include severe but plausible scenarios including disruptions to services provided by material service providersT1Supported
E21An entity must maintain a comprehensive assessment of its operational risk profile, and as part of this must identify and document the processes and resources needed to deliver critical operations, including people, technology, information, facilities and service providers, the interdependencies across them, and the associated risks, obligations, key data and controlsT1Supported
E22An entity must identify and maintain a register of its material service providers and manage the material risks associated with using these providers. Material service providers are those on which the entity relies to undertake a critical operation or that expose it to material operational riskT1Supported
E23An entity must submit its register of material service providers to APRA on an annual basisT1Supported
Section F · The practice guide (CPG 230)
IDClaimTierStatus
F1A prudent entity would assess the risks of engaging a service provider in another jurisdiction to determine if it is within appetiteT1Supported
F2That assessment is directed to five considerations: (i) ability to continue operations and meet core obligations following a loss of service; (ii) maintenance of information security; (iii) ability to own and manage controls on its behalf; (iv) compliance with legislative and prudential requirements; and (v) impediments, legal and technical, to APRA being able to fulfil its duties, including timely access to information in a usable formT1Supported
F3The only consideration directed at legal reach concerns impediments to APRA's access. No consideration is directed at the ability of a foreign government to compel disclosure from the providerT1Supported as to the content of the five considerations and the absence of a sixth.
F4CPG 230 frames the jurisdiction question locationally, as engaging a provider "in another jurisdiction", consistent with CPS 230 footnote 16T1Supported
F5The phrase "where the service provider is unable to provide the service for an extended period of time" appears in CPG 230 as a matter a service provider management policy would usually includeT1Supported. Confirms E14
F6APRA refers to the exempt categories as non traditional service providers, intended to capture providers typically market mandated or otherwise not engaged through standard procurement or contractual processes, where arrangements often lack a formal agreement or use standardised terms that cannot be negotiatedT1Supported
F7Where an entity uses a service provider, the entity still owns and is responsible for managing its riskT1Supported
F8In identifying critical operations a prudent entity would consider operations that if disrupted would affect its ability to comply with legal or regulatory requirementsT1Supported
Sources

Every source, with hash

Per-source hashes are published in full: reference, name, URL, retrieval timestamp (UTC), artefact type, and SHA-256 of the archived artefact. This is a deliberate divergence from the prior house pattern and becomes the standard. Hashes are verifiable against the archive with shasum -a 256.

RefNameURLRetrieved (UTC)Artefact typeSHA-256
S1CBA Newsroom, 'CommBank and AWS expand collaboration to deliver global best cloud and AI capabilities', 4 Feb 2025https://www.commbank.com.au/articles/newsroom/2025/02/amazon-web-services-collaboration.html2026-07-18T08:36:07ZEditable web page61d86d27f44a3e919d590004013bd801ed23ab0a2a50147612a0905cb3003016
S2CBA Newsroom, 'CommBank accelerates AI integration with major data migration to cloud', 4 June 2025https://www.commbank.com.au/articles/newsroom/2025/06/cba-ai-migration-cloud.html2026-07-18T08:36:11ZEditable web page4bd92e17f5a13dd9ac7cab3487d2860000b82c91a8e26859743f450213d2e33f
S3Amazon.com, Inc. FY2025 Form 10-K, Exhibit 21.1, filed 6 Feb 2026, period ended 31 Dec 2025https://www.sec.gov/Archives/edgar/data/1018724/000101872426000004/amzn-20251231xex211.htm2026-07-18T08:36:22ZFixed filing970ff45f7c9d86f2548306c5c6bdab03c43788db532348158484c471adb434af
S4ASIC Current Company Extract, AMAZON WEB SERVICES AUSTRALIA PTY LTD, ACN 605 345 891, s1274A Corporations Act 2001https://connectonline.asic.gov.au/ (purchased extract, held as PDF)2026-07-18T08:36:22ZFixed PDF, held69eda18e3696b3358db70013d20953749b36e81cc8e3611eb87bf2f589ea08a7
S518 U.S.C. § 2713 Required preservation and disclosure of communications and records — U.S. Code 2024 Edition, Office of the Law Revision Counsel / GPO official (Cornell LII retained as secondary check)https://www.govinfo.gov/content/pkg/USCODE-2024-title18/html/USCODE-2024-title18-partI-chap121-sec2713.htm2026-07-18T09:11:01ZArchived HTML + text, SHA-256 (fixed edition)3a242ef2c1ee7a061f44bfb8daf7952839a4c4f2763d586e4af7ab1d6f5b4f42
S618 U.S.C. § 2711 Definitions for chapter — U.S. Code 2024 Edition, OLRC / GPO official (Cornell LII retained as secondary check)https://www.govinfo.gov/content/pkg/USCODE-2024-title18/html/USCODE-2024-title18-partI-chap121-sec2711.htm2026-07-18T09:11:01ZArchived HTML + text, SHA-256 (fixed edition)8937cc8fd9c5b3e264379d0e852fa9e374d17645a569a83cc09a757f5d3aae82
S718 U.S.C. § 2510 Definitions — U.S. Code 2024 Edition, OLRC / GPO official (Cornell LII retained as secondary check)https://www.govinfo.gov/content/pkg/USCODE-2024-title18/html/USCODE-2024-title18-partI-chap119-sec2510.htm2026-07-18T09:11:01ZArchived HTML + text, SHA-256 (fixed edition)1797f9f58adaff71652cd240177b5e95613a962f664f788cb45388310050734e
S8APRA, Prudential Standard CPS 230 Operational Risk Management, July 2026 clean texthttps://www.apra.gov.au/system/files/2026-05/Prudential%20Standard%20-%20CPS%20230%20Operational%20Risk%20Management%20-%20clean.pdf2026-07-18T08:36:24ZFixed PDFed84ff3a62432559ba351aeb7cdd66bc62fb34d9366be67b3f7c5d11d1d968e9
S9APRA, CPS 230 standard page including determination preamblehttps://www.apra.gov.au/standards/cps-2302026-07-18T08:36:13ZEditable web pageb3acdba662856b23d67a7fe447a54e42e60f94f3cbc2deef1705343c8c5cc941
S10APRA, CPG 230 Operational Risk Management, current versionhttps://www.apra.gov.au/practice-guides/cpg-2302026-07-18T08:36:15ZEditable web page8375417c1b059fc1d5af1792c3fd51d8cab18341e4357faa09422a0e417a1a86
S11APRA media release, 'APRA finalises targeted amendments to CPS 230 Operational Risk Management', 30 Apr 2026https://www.apra.gov.au/news-and-publications/apra-finalises-targeted-amendments-to-cps-230-operational-risk-management2026-07-18T08:36:18ZEditable web pagebff890d80bb6f9fd9c3a728b3495848883e42adaae7c533bc1839df804d5e878
S12Anthropic on Bedrock Commercial Terms of Service, effective January 2024https://www-cdn.anthropic.com/6b68a6508f0210c5fe08f0199caa05c4ee6fb4dc/Anthropic-on-Bedrock-Commercial-Terms-of-Service_Dec_2023.pdf2026-07-18T08:36:25ZFixed PDF4b9b413733f10efbbfcd5521033d3bb60308a54f8bb6238d1245cb677e607b22
S13Anthropic, 'Statement on the US government directive to suspend access to Fable 5 and Mythos 5', 12 June 2026https://www.anthropic.com/news/fable-mythos-access2026-07-18T08:36:19ZEditable web page6b903d76c24e0e78f2666684eba98de0cdf16f442ae93ee52926980b26cc2576
S14Anthropic, 'Redeploying Claude Fable 5', 30 June 2026https://www.anthropic.com/news/redeploying-fable-52026-07-18T08:36:25ZEditable web page9362ea86ad32b7b49969e91c8578949699c077573951ca1f9f69b56ecd152354
S15Legislative instrument F2026L00475https://www.legislation.gov.au/F2026L00475/asmade/text2026-07-18T08:36:26ZFixed instrument. Paragraph numbering confirmed via S8f735b5ec40bf4f5bdad7e4bc9dc1bb2a877ca365855649253d58f121d30f6561
S16CBA Newsroom, 'CommBank expands strategic partnership with generative AI company, Anthropic', March 2025https://www.commbank.com.au/articles/newsroom/2025/03/anthropic.html2026-07-18T08:36:28ZEditable web page367228b4775b6f2f6f90fc59d991c534dc084e42ce9addbb38afb98a8d5a0f83
S17CBA Newsroom, 'CommBank ranks among world's best banks for AI maturity', Oct 2025 (OpenAI partnership)https://www.commbank.com.au/articles/newsroom/2025/10/commbank-among-best-banks-ai-maturity1.html2026-07-18T08:36:29ZEditable web page61db414ee94e8ccf8839a2d9f20cedb6441ddd58a0a0df776b48900dd6b87b44
S18APRA, CPG 230 Operational Risk Management, June 2024 PDF (superseded numbering, do not cite)https://www.apra.gov.au/sites/default/files/2024-06/Prudential%20Practice%20Guide%20CPG%20230%20Operational%20Risk%20Management.pdf2026-07-18Fixed PDF, superseded— (superseded; no artefact)
S19Koren, Kurland and Mehta, 'The Department of Commerce Restricted Access to Anthropic's Latest Models. What Comes Next?', CSIS Critical Questions, 16 June 2026https://www.csis.org/analysis/department-commerce-restricted-access-anthropics-latest-models-what-comes-next2026-07-18T09:56:11ZEditable web page. Archive required1293d84e3b7f0c2f428261bcfb56fa6f9f24b87ce480f3dcd4cae930e0f75b08
S20Complaint, Legion LegalTech, Corp. v. United States of America, No. 1:26-cv-02225-RJL (D.D.C. filed 23 June 2026), 43pphttps://storage.courtlistener.com/recap/gov.uscourts.dcd.293776/gov.uscourts.dcd.293776.1.0.pdf2026-07-18T09:56:11ZFixed court filing. Archive requiredfa38bd28607b933957adcabec678b405d10532ca98ee3a6e28991422d031f156
S21Commerce Department letter, 26 June 2026. Not public. D6.15 is sourced to S14, Anthropic's own statement.Not public— (not public)
S22Delaware Division of Corporations, entity search, ANTHROPIC, PBC, File No. 4860621https://icis.corp.delaware.gov/ecorp/entitysearch/namesearch.aspx2026-07-18T10:17:44ZState register. Held PDF, archived and hashed08253947d7d7103187423ef94550cdb0ee4f3634e66f684b297e0048268003a2
S23GLEIF LEI record, ANTHROPIC, PBC, LEI 984500B6DEB8CEBC4Z70https://search.gleif.org/#/record/984500B6DEB8CEBC4Z702026-07-18T09:56:11ZEditable web page. Archive requireda40fab8fd14c8b0c2e04ddbed479835f8a3691c842cf111394b757de6a23d574
S24Delaware Division of Corporations, entity search, OPENAI GROUP PBC, File No. 10381551https://icis.corp.delaware.gov/ecorp/entitysearch/namesearch.aspx2026-07-18T10:17:44ZState register. Held PDF, archived and hashed5ad3a6a2420240af8b8ec72130d002a6121a23d395755a6e82e164c7f7a24b39
S25OpenAI, 'Our structure'https://openai.com/our-structure/2026-07-18T10:13:42ZEditable web page. Browser save archived and hashed (current structure). See warning below33ecee0cfd9028e48c261ee831e63c13f368e6855c7cb534977fcf4e97173514
S26CourtListener docket, Legion LegalTech, Corp. v. United States of America, 1:26-cv-02225 (D.D.C.)https://www.courtlistener.com/docket/73520460/legion-legaltech-corp-v-united-states-of-america/2026-07-18T09:56:11ZEditable web page. Archive required5670c63d8a77d584874b6f135b6d91801de51765c853a85393193b50fbba3cfa
Contestable

Contestable steps

Each names a step at which a reasonable reader could disagree. They are load-bearing and are not softened.

CS1 · Corporate control.

The corporate structure is established from two regulators. What is not established by structure alone is whether a parent's ownership of a wholly owned foreign subsidiary places that subsidiary's customer data within the parent's possession, custody or control for the purposes of § 2713. That is a question of US law, unsettled, and not determined by this assessment.

CS2 · No compulsion shown.

Nothing in the record establishes that any US legal process has been directed at CBA data. The claim is structural reachability, not demonstrated access.

CS3 · Scope of "100 per cent".

Sutherland's statement refers to the data platform. Whether it extends to all bank data in every system is not established.

CS4 · Continuity identified, not assessable.

Reduction of on premises footprint raises a continuity question distinct from the CLOUD Act question, and the two must not be merged. Continuity was identified, but the public record does not permit a finding: the bank's business continuity plan, exit arrangements and tolerance levels are internal documents that are not public and will not become public. It is therefore not assessed. It is not reserved or pending; there is no future date at which the public evidence would support a finding.

CS5 · HCLTech.

Named as migration partner only. No claim of ongoing data processing is supported.

CS6 · Statutory definition, and the strain in the alternative limb.

Section 2713 attaches to a provider of either electronic communication service or remote computing service. Remote computing service carries a "to the public" qualifier at 2711(2) [B6]; a single tenant negotiated arrangement with one institution is not obviously provision to the public, and that objection is well taken. Electronic communication service at 2510(15) carries no such qualifier [B10], but its application here is strained in two respects that the assessment concedes rather than resolves. First, the definition is the provision to users of the ability to send or receive wire or electronic communications; passive storage and compute are a poor fit for that description, and the characterisation is strongest for communication carrying services in the estate and weakest for the remainder. Second, a respondent may argue that the entity providing users the ability to send or receive communications is the bank itself, and that the provider supplies infrastructure to the bank one step removed. Whether the electronic communication service is the provider or the bank is unresolved and material.

CS7 · Contract not seen.

The silence at C1 to C3 is a silence in the public assurance record, not in the executed agreement, which has not been seen. No inference may be drawn about contractual terms.

CS8 · Financial institution exclusion, and its limit.

18 USC 2510(12)(D) excludes from the definition of "electronic communication" electronic funds transfer information stored by a financial institution in a communications system used for the electronic storage and transfer of funds [B11]. The exclusion is narrow: it reaches only EFT information, and only such information held in a funds transfer system. It does not remove personal information, identity records, documents, analytics or model inputs and outputs from the chapter. Further, section 2713 reaches "any record or other information pertaining to a customer or subscriber" as well as the contents of communications [B14], and EFT information excluded from the communication limb may be recaptured by that limb. The assessment therefore cannot claim that all bank data is within reach, and equally cannot concede that a substantial proportion falls outside the chapter. Contestable and unresolved: a respondent may argue the existence of the (D) carve out signals an intention to keep funds transfer data outside the scheme notwithstanding the catch all.

CS9 · Exposure Two, no disruption.

Only Fable 5 and Mythos 5 were controlled in June 2026; access to all other Anthropic models was unaffected [D6.3]. CommBiz Gen AI runs on Claude 3 [D2] and was not disrupted. Any Exposure Two claim must state this before advancing the structural finding.

CS10 · Exposure Two, availability not disclosure.

Anthropic does not have access to Customer Content under the Bedrock terms [D5.8]. The exposure at 2.6 is availability, not disclosure. It must not be merged with the § 2713 analysis.

CS11 · Live proceeding.

The lawfulness of the June 2026 directive is the subject of undetermined litigation in the United States District Court for the District of Columbia. A hearing on preliminary relief was listed for no earlier than the week of 27 July 2026. Claims in the D7 series record allegations made in a pleading, not findings. The legal position may change, and any assessment relying on these claims should state the date to which it speaks.

CS12 · Investment and contractual relationship not established.

The bank states that it has made an investment in a model provider [D1]. Whether that investment is equity or another instrument is not publicly established, and the source states only investment and strategic investment. Whether the bank holds any direct contractual relationship with that provider, distinct from the terms applicable to access through the intermediary, is also not established. No inference is drawn from the existence of the investment.

CS13 · Terms recorded, not construed.

This assessment does not construe the terms. It records what they say. Whether an Australian customer would in practice have any remedy under a contract governed by California law, and whether the exclusion of liability at D5.4 would be effective in any given forum, are questions of law and of contract construction that this assessment does not reach and is not qualified to reach.

CS14 · Intermediary not named in D6.2.

D6.2 states that the models were disabled for all customers. It does not name the intermediary. The proposition that Bedrock customers were among those affected follows from the terms at D5.1, under which a party accessing models through that platform is a customer of the provider. A reasonable reader may contest that step. The pleaded instance at D7.5 and D7.6 corroborates it but is an allegation in undetermined litigation and is not relied on as proof.

CS15 · Contest, not invalidity.

D6.7 to D6.11 are statements by named authors published by an institution that records that it does not take specific policy positions and that views expressed are those of the authors. They establish that the basis is contested by credible analysts. They do not establish that it is invalid, and this assessment does not assert that it is.

Scope

What is and is not assessed

This assessment publishes on Exposure One, compellability, and Exposure Two, availability.

Exposure One · Compellability. Whether data held for the bank is within reach of United States legal process by reason of the provider's incorporation. Assessed.

Exposure Two · Availability. Whether the bank's dependency on providers of artificial intelligence models is subject to interruption by decision of a foreign government, by reason of the providers' incorporation. Assessed. Held at Section D and the D7 series. See CS9, CS10, CS11 and CS12.

Continuity. Whether concentration on a single provider, combined with a stated reduction in on premises capability, creates a continuity risk under CPS 230. Identified and not assessable on the public record. Not numbered, not reserved. The bank's business continuity plan, exit arrangements and tolerance levels are internal documents that are not public and will not become public. Claims bearing on it are retained at A1, A3, A6, A7, A10, E10, E11, E16, E20, where they are load-bearing for Exposure One or stand as legitimate context. See CS4.

The assessment alleges no wrongdoing by Amazon Web Services, Amazon.com, Anthropic, OpenAI, or any provider named; it alleges no compulsion, disclosure or breach; and it determines no question of law. AustraliaOS is not qualified to give legal advice and does not do so.

Download

Assessment PDF

The attested assessment is the signed PDF. Its SHA-256 is published below; the verification status set out on this page is reflected in the document footer.

PDF · approximately 189 KB · signed by Brunel Al-Bijwaie, Director
SHA 256: 7d6f45cef39da00535106371b503807ee3dd1af307ccc1cfab7ae4c046b28dae
Recompute the SHA 256 with shasum -a 256 or sha256sum to confirm this file is unaltered since publication.
Brunel Al-Bijwaie
Director, AustraliaOS Pty Ltd