Transparency is easy to promise and hard to operate.
Two things happened in the last few months that prove it: a government privacy regulator quietly audited its own sector’s disclosure practices and found the gaps hiding behind “broadly compliant,” and a global platform spent three years in court rather than answer a straightforward transparency notice — and lost.
The 30-Second Take
Transparency obligations are being tested as live operational controls, not annual paperwork.
The OAIC’s review of Freedom of Information disclosure logs across 30 Australian Government agencies found that “broadly compliant” still means missed timeframes, poor accessibility and no clear governance owner.
Meanwhile, the Federal Court fined X Corp $650,000 for refusing to properly answer a regulator’s transparency notice — a reminder that stonewalling a disclosure obligation is now a boardroom-level legal and financial risk, not a communications problem.
Organisations that treat transparency as a publishing task rather than a customer outcome, are not addressing the concerns of customers or regulators.
Two Transparency Tests, Two Very Different Outcomes
OAIC: Compliance on Paper, Gaps in Practice
Published on 7 August 2026, the Office of the Australian Information Commissioner’s review examined disclosure logs across 30 federal agencies against section 11C of the Freedom of Information Act 1982 — the requirement to publish released information within 10 working days.
The headline finding was reassuring: overall compliance was broadly strong. The detail was not.
The OAIC identified agencies that had not published all disclosure log entries within the legislated timeframe, logs that were hard to search or navigate, and — most tellingly for risk teams — no consistent evidence of who owned the control or how exceptions were reported to leadership.
The regulator’s message was clear: a disclosure log that technically exists but can’t be searched, isn’t kept current, or has no named owner meets the letter of the obligation while failing its intent.
Federal Court v X Corp: When “We’ll Get to It” Becomes a Judgment
In May 2026, Federal Court Justice Michael Wheelahan fined X Corp AU$650,000 and ordered it to pay AU$100,000 of the eSafety Commissioner’s legal costs, closing a three-year legal battle over a single transparency notice.
eSafety had asked X, back in February 2023, how it was handling child sexual exploitation content on the platform. X argued it wasn’t obliged to answer in full. It was wrong. X ultimately admitted it had contravened the Online Safety Act by failing to properly respond — and the court’s judgment turned a disputed compliance question into a public, costly, and reputationally damaging precedent.
The lesson for any organisation that receives a regulator information request: contesting the request is a legitimate legal option, but treating it as optional is not.
What These Two Cases Have in Common
Neither case is about whether transparency rules and regulations exist — everyone already knows they do from the needs of the very customers they serve. In fact, every person who interacts with any company puts trust high up in their requirements.
Both are about whether an organisation naturally focuses on transparency, sees it as a true value differentiator and places importance on all employees valuing this in their interactions and work.
Then this extends into being able to provide evidence, on demand, that disclosure and information-response processes work: who owns them, how they’re monitored, and what happens when they’re tested.
The OAIC review shows what happens when nobody clearly owns a routine obligation. The X Corp judgment shows what happens when an organisation decides a live regulator request isn’t a priority.
Different sectors, different stakes, same root cause.
Questions to Ask Your Organisation
- Do we have a named owner for every recurring disclosure or transparency obligation — not just a team, but a person?
- Can we evidence that information is published or provided within the required timeframe, not just “eventually”?
- If a regulator issued an information or transparency notice tomorrow, do we know who is authorised to respond, and by when?
- Are our public-facing disclosure logs, registers or reporting channels actually usable — searchable, current, and accessible?
- What escalation happens when a disclosure deadline is at risk of being missed, and does the board ever see that signal before it becomes a finding?
- Have we ever treated a regulator request as something to negotiate away rather than answer — and would that decision hold up in court?
Turning Regulatory Signal Into Readiness
The Innovation of Risk Reading Room tracks OAIC, eSafety, APRA, ASIC and other regulatory developments as they move from publication to practical expectation.
If your board or risk team wants a structured way to test whether your transparency and disclosure controls would survive scrutiny — before a regulator or a court asks — that’s where we help.

