It’s not just the delayed response to the Medicare hack; Australia lags the world in measures to safeguard your personal data. Claudia Weisenberger reports.
When police extract data from your phone using Cellebrite AI technology, that data can now legally move to cloud servers owned by an Israeli company, governed by Israeli law, and accessible to the Israeli government.
The Albanese Government approved that clearance on 2nd September 2026. This week, the PM announced that Medicare data was accessed by a “rouge AI agent” back in June, yet the company responsible – tech bro Sam Altman’s Open AI – took their sweet time to tell him about it.
Once again, our Government appears to be scrambling for answers as laws and regulations governing data privacy are not up to the task, while other comparable democracies appear to do much better.
World’s ‘better’ practices
The United Kingdom has a statutory code of practice governing digital extraction that requires investigators to log every incident, review data for relevance, delete information unrelated to the investigation and notify the device owner of what was taken. Australia has none of that.
In Europe, Cellebrite technology is subject to the EU’s Dual Use Regulation — a binding export control framework that France, Germany, the Netherlands and Italy all operate under. Australia has no equivalent framework. The chart below documents every oversight provision that comparable democracies require. Australia fails all seven.

Not just about organised crime
The Government’s stock standard answer to why they need such extraordinary powers is always about combating organised crime and terrorism. Yet, that’s not always the case.
Journalist Antony Loewenstein documented the case of a woman receiving single parent payments whose phone was accessed by Services Australia — not to investigate organised crime or terrorism, but to determine whether she was in a relationship. No charges were ever laid. She was nonetheless pursued for debt repayments.
Services Australia — the agency that used Cellebrite against her — administers welfare payments for millions of Australians and co-leads the Fraud Fusion Taskforce alongside the Australian Federal Police and Palantir. This is what Cellebrite is already used for in Australia.
Is Cellebrite above the law?
Senator David Shoebridge has uncovered 128 active contracts between Cellebrite and Commonwealth government agencies worth more than $15m. That figure does not include state and territory police contracts — and every state and territory holds them. Shoebridge has called for a full audit of every government contract with Cellebrite and Palantir. The government has not responded.
Your phone data can now legally sit on servers owned by an Israeli company, governed by Israeli law, accessible to the Israeli government. Seven oversight provisions exist in comparable democracies. Australia has none of them. The government approved the clearance. It has not explained why.
Claudia Weisenberger is a management consultant with deep experience in pharmaceuticals, hospital transformations, and strategic due diligence across four continents. She combines sharp analysis with hands-on execution.

