Verification status
The assessment is structured in three layers. Each layer carries a different kind of attestation. The counts below show what is in the document; the CLAIM verdicts below show the engine result for the verified layer.
CLAIMs are facts tested by the AustraliaOS verification engine against primary sources. ANALYSIS blocks are labelled AUTHOR REASONED: each is the director's reasoning over CLAIMs and names the step at which a reasonable reader could disagree. RECOMMENDATIONs are labelled AUTHOR PROPOSED: each is a recommended action motivated by named ANALYSIS blocks, not engine-verified.
CLAIM verdicts
SUPPORTED indicates the CLAIM is confirmed by at least one primary source. PARTIALLY SUPPORTED indicates the source pool confirms the substance of the CLAIM but a specific element in the evidence assembly diverges or rotates across runs. NOT SUPPORTED would indicate the source contradicts the CLAIM. UNVERIFIED would indicate the source was inaccessible at the time of publication. The 23 SUPPORTED, 5 PARTIALLY SUPPORTED, 0 NOT SUPPORTED, 0 UNVERIFIED census records publication-eligible verification of every CLAIM in the assessment; each PARTIALLY SUPPORTED CLAIM is named below with its grounds.
The five PARTIALLY SUPPORTED CLAIMs, by name:
- CLAIM A (PS/78) — the load-bearing SOCI Act s30EB statutory text source intermittently rotates out of the engine's five-source evidence window; the source pool answers the CLAIM, and the residue is the evidence selector's window class.
- CLAIM D (PS/78) — derivation residue on a compound CLAIM; each constituent leg is answered by the pool.
- CLAIM F (PS/48) — the Cornell LII 18 USC 2713 statutory text intermittently misses the evidence window; same class as CLAIM A.
- CLAIM H (PS/70) — selection variance on the 7 February 2024 disclosure-date primary; the date is double-primary attested in the source register.
- CLAIM I (PS/28) — borderline interpretive oscillation on identical CLAIM text and identical source pool; named editorial residue, not a documentary defect.
The CLAIMs split into the doctrine claims that establish the regulatory and statutory framework (attested by the administering agencies and statute texts, including SOCI Act s30EB, the Telecommunications Sector Security Reform Program Rules F2025L00325, and Cornell LII 18 USC 2713), the carrier licensee entity claims (attested by the ACMA register of licensed carriers), the Australia-US Data Access Agreement claims (attested by the agreement text, the AGD International Production Orders framework page, the Home Affairs signed PDF, and the Federal Register Section 2523(b) executive certification), the vendor incorporation and entity claims (attested by SEC EDGAR submissions and the Delaware Division of Corporations), the joint-venture structural claims for the Telstra-Accenture construction (attested by Telstra and Accenture primary releases, the Communications Workers Union notice, and ASIC Connect for Quantium Telstra), the disclosure dates and partner lists (attested by primary press releases from the named parties), and the US export-control framework attestation (attested by the Code of Federal Regulations).
The 5 ANALYSIS blocks carry the assessment's reasoning over those CLAIMs: how Section 2713 reach applies to Microsoft as an Azure OpenAI operator, whether the CLOUD Act Agreement narrows that obligation, the unresolved operational scope of the AWS VoLTE involvement, the network management layer characterisation of the Red Hat / Dell / Cisco proof of concept, and the contingent supply and operational continuity exposure created by US incorporation of those vendors. Each names the step at which a reasonable reader could disagree.
The 8 RECOMMENDATIONs are the assessment's proposed conditions: Conditional Continuation paired with a Mandatory Sovereign Migration Pathway, plus seven operationalising conditions covering Australian incorporated alternatives for protected workloads, quarterly TSRMP re-assessment, vendor access controls at the management layer, disclosure to Commonwealth customers, Azure expansion gating, a documented Section 2713 disclosure handling protocol, and a nominated sovereign migration target. Each cites the ANALYSIS blocks that motivate it.
Board provenance
The verdict census above was produced by a full engine board run on 10 June 2026 against the assessment source register at agentos commit 9981eb3. The run's per-claim entries were appended to a signed audit chain (HMAC-chained, operator-local custody). Each CLAIM verdict, including the five PARTIALLY SUPPORTED CLAIMs named above, is recorded in that chain.
Primary sources
Verification draws on three categories of primary source. Each category is named below with the entities and claims it attests.
- Security of Critical Infrastructure Act 2018 (Cth), section 30EB (responsible entity's obligation to protect critical telecommunications assets)
- Telecommunications Sector Security Reform Program Rules F2025L00325
- CISC Telecommunications page for ERP Act Royal Assent, Schedule 5 commencement, TSRMP Rules effective date
- ACMA Register of Licensed Carriers (carrier licensee entity attestation)
- Australian Business Register for Telstra Group Limited entity identity
- ASIC Connect for the Quantium Telstra entity record (joint-venture structural attestation)
- APRA Prudential Standard CPS 230 Operational Risk Management and the APRA supervisory letter, cited as a comparative benchmark
- Attorney-General's Department International Production Orders framework page
- US Department of Justice published agreement text (Australia and United States Agreement on Access to Electronic Data)
- Department of Home Affairs signed agreement PDF
- Federal Register Section 2523(b) executive certification of the Agreement
- Cross Border Data Forum FAQ on the Australia-US CLOUD Act Agreement (pinned document citation: hash-pinned snapshot held in the assessment assets)
- SEC EDGAR submissions JSON for Microsoft Corporation, Amazon.com Inc, Cisco Systems Inc, Dell Technologies Inc, Accenture plc
- Delaware Division of Corporations entity search for Red Hat, LLC
- Cornell Legal Information Institute text of 18 USC 2713
- Code of Federal Regulations Title 15 Part 730 (eCFR) for the US export-control and sanctions framework
- Telstra media releases and Telstra Exchange publications
- Microsoft News Centre Australia
- Accenture newsroom (Telstra-Accenture joint venture announcement)
- Communications Workers Union notice on the Telstra-Accenture joint venture
What this page is not
This verification record confirms that the claims in the Telstra CLOUD Act Assessment match what the named primary sources state at the time of publication. It is not a guarantee of fact about the third parties named in the assessment. Subsequent changes to those sources may not be reflected here. The assessment itself, not this verification page, is the decision support artefact.
For accountability, signing, and correction process, see the Accountability Statement.
Assessment PDF
The full assessment, signed by the director, is available below. The verification status set out on this page is reflected in the document footer.
Correction, 20 July 2026. This PDF was reissued to correct a rendering defect: a stray asterisk appeared above the Contents heading. The assessment content is unchanged.