Parliament House, Canberra

Adaca Report · September 2026

Breach reporting in the AI era

What 4,769 data breach notifications reveal about how Australian organisations detect and report data breaches in the AI era – 2022-present.

4,769
Notifications analysed
+69%
H1 2026 vs H1 2022
52
Sector categories
§07METHOD
REV 2026.09 · 07.00

Sources and method

This is a subset of a combined dataset built from two OAIC FOI disclosures covering consecutive, non-overlapping periods. Every extracted table reconciles to the total printed in its own source document.

  • FOIREQ24/00556 — Feb 2018 to Oct 2024 (6,406 notifications in total; Jan 2022 onward used here). Monthly aggregates with time-to-identify and time-to-notify already bucketed into day bands.
  • FOIREQ26/00195 — Nov 2024 to 2 Jul 2026, 2,063 notifications. Row-level records with exact dates, bucketed into the earlier release's bands for comparison.
  • The later release splits time-to-identify and time-to-notify into two tables of individual records; they were matched on breach date plus sector to reconstruct the discovery-to-notification interval. 19 of 2,063 pairs (0.9%) produced an impossible negative interval and are counted as unknown.
  • Cause of breach is broken down by sector, and information types recorded, only in the earlier release — so those cuts stop at October 2024. Numbers affected appear only in the later release, so the scale figures cover Nov 2024 – Jul 2026.
  • 2026 ends on 2 July and is not annualised. Where a like-for-like comparison matters, January-to-June figures are used.

Where to Next