An unsteady stack of closed incident files

S³ Brief September 2026

September 14, 2026•6 min read

On 11 September 2026, the Optus network failed for the second time in twelve months, with calls dropping across Victoria, South Australia, Tasmania and the Northern Territory for 76 minutes, including some to emergency services.

The outage before it, in September 2025, saw around 600 Triple Zero calls fail, and links to harm have been confirmed in instances where some calls did not connect. Thankfully, that doesn't appear to be the case this time.

For leaders overseeing essential service delivery, recurrence is a real accountability issue. Closed investigations and confirmed fixes don't always hold. 

Signal Scan

What's forming: early indicators, weak signals, shifts worth watching.

Australia: For Optus, this is the third time in three years. Optus was fined $12 million in 2024, for failing to provide emergency call services during a 2023 outage. A similar failure has now happened twice more since. 

The Federal Government wants to change how this kind of failure is governed. Earlier this year it proposed 21 reforms to the Security of Critical Infrastructure (SoCI) Act, the biggest overhaul since the law began. Public consultation closed at the end of July, and the reforms are now pending. Right now, a board can meet its obligations by simply approving an annual risk report. Under the proposed reforms, members of the board become personally accountable for whether that risk program actually works, not just for signing off on it. The reforms would also catch outside vendors and service providers for the first time. If they exercise real control over a critical asset, the reforms treat them as what the law calls a "relevant operator", held to the same standard as the organisation itself.

Separately, Australian Security Intelligence Organisation (ASIO) Director-General Mike Burgess revealed in June that nation-state hackers had already mapped their way inside an Australian infrastructure provider's network. They were not attacking. They were watching and waiting, with access already in place. No incident had occurred, but the potential was real.

APAC: No distinct APAC signal.

Global: Within three weeks in July and August, OpenAI, Anthropic, and Meta each admitted the same problem. In each case, an AI agent built to act on its own during cybersecurity testing broke out of the environment meant to contain it and reached a real organisation's production systems.

Separately, a report published on 4 September by AI safety group Nightingale Collective revealed an earlier, unrelated incident. Between May and July, OpenAI's agents had quietly turned a German developer's wiki into a hidden coordination board, making more than 15,000 changes. Nobody caught it until the report came out, three months later. Gartner expects 40% of companies will pull back their autonomous AI agents by 2027 for this very same reason: the gap in oversight only shows up once something has already gone wrong.

Shock Watch

What could break: disruptions with cascade potential.

Picture the same telecommunications outage happening during a bushfire or a super cell storm, when emergency call volumes are already stretched. That combination would test the network far harder than any outage has so far, and it's unclear what's in place to stress test such a scenario. 

Once the SoCI reforms take effect, many organisations may find the protections they assumed were written into outsourcing contracts are simply not robust enough, or perhaps even there. The time to look into it is now. 

Sensemaking

What these developments mean together.

On the surface these stories might appear unrelated. Optus's latest Triple Zero failure shows that systems will continue to fail, even with fixes and sign off. The AI agent escapes show a pattern in a completely different arena. Testing assumed a human would always be watching before an AI agent acted: once agents started acting first and being reviewed afterwards, that safeguard slipped away. The SoCI reforms are catching up to all of this by shifting oversight and accountability from an annual report sign-off onto the actual living program managing the risk and pulling outside vendors into that same accountability circle for the first time.

What's evident

  • applying a fix and closing an incident may not fully address the risk

  • recurrence is possible, and it may look the same next time, or nothing like it.

  • the driver of future disruption might be quietly waiting in the wings, currently undetected.

  • humans need to be in the mix, proactively.

Interdependencies

A telecommunications fault doesn't stay a telecommunications problem. A call that doesn't get through to Triple Zero doesn't easily register as missing on the other end. What follows is a capacity problem downstream: police and other services end up conducting welfare checks in person, absorbing load nobody planned for.

SoCI reforms will lean harder into dependency. An organisation's risk program will be as strong as its ability to prove vendors are also capable of meeting the mark. Accountability can't be outsourced. Those relationships, in some cases, will need review.

AI agents are increasingly live in sectors with dependency chains. An accountability gap in one will not stay contained. A binary approach to governance, locked down or fully trusted, is not getting the right outcomes and needs to be resolved fast.

Questions for Leaders

Three executive questions to take into leadership discussions.

  1. Which of your closed incidents have since been tested for potential recurrence?

  2. What proof do you have that your service provider or vendor can meet the standards your organisation will be held to?

  3. How are you managing AI agents and are you confident the approach would pass the pub test?

What Matters Next

30 days: Check whether your business continuity testing includes a genuine recurrence test, not only a sign-off after the initial fix, for your highest-consequence single points of failure.

90 days: Check your outsourcing and managed service contracts against the SoCI reforms, in particular the new "relevant operator" definition. And if you're a provider that's fallen into that definition, prioritise meeting that intent for competitive advantage.

12 months: Get clear on the use of AI Agents - yours and use by those you rely on. Don't let your organisation be the next case study. 


Sources


This post is the full S³ Brief. A snapshot runs as a LinkedIn Newsletter. Subscribe to receive the full S³ Brief direct to your inbox. [subscribe here]

Working through complexity in your organisation? Reach out [enquiry form]

Leanne Simpson

Leanne Simpson

Author of S³ Brief and Founder of Critical Connections

LinkedIn logo icon
Instagram logo icon
Back to Blog