All field notes

AI in Schools

Budget eve and Canvas ransom deadline, OAIC weighs in

By Brodie McGee ·

The Monday read is the day before two deadlines. Tomorrow night the Treasurer hands down the 2026-27 Budget. Tomorrow's end-of-day is the Canvas ransom clock. Both will land on Australian education leaders in the same 24 hours, and the rest of the week's planning depends on how each one resolves.

Tuesday is double-deadline day, and the pre-positioning work happens today

Treasurer Jim Chalmers delivers the budget at 7.30pm AEST tomorrow. End of business tomorrow is also the ShinyHunters "leak everything" deadline on the Instructure data. The two events are unconnected, but they land on the same desks. The budget lines worth watching for the sector are the cyber-resilience envelope (the Canvas incident has made the ask politically live, not notional), any named allocation against the Teaching and Learning Commission working-group recommendations, the next tranche of the Better and Fairer Schools Agreement profile, and ATEC's 2027 Managed Growth dollar terms. The Canvas question is whether Instructure has paid (no public confirmation as of this morning) and, if not, what gets published.

Why this matters: For SBMs and pro-vice-chancellors, today is the day to have two communication drafts ready for Wednesday morning, not Wednesday morning the day to start writing them. One responds to a budget that either does or does not name an education cyber line. The other responds to either a quiet Canvas resolution or a loud one, with parent and student notifications pre-cleared by legal and communications. The work that buys back time on Wednesday is the work done by close of business today. Bloomberg on Chalmers's pre-budget housing signals, and TechRepublic on the Canvas ransom deadline and the scale of the affected list.

The OAIC has now formally weighed in on the Canvas incident, and the statement quietly redraws the jurisdiction map

The Information Commissioner issued a public statement on Friday 8 May confirming awareness of the Instructure incident and confirming that the National Office of Cyber Security is coordinating the federal response. The technically interesting part is in the jurisdictional clarification. The OAIC notes that state and territory government schools usually sit under state privacy laws, not the federal Privacy Act, and that public universities and TAFEs are generally exempt unless operating as private entities. Affected individuals are directed to complain first to Instructure or to their institution, with a minimum thirty-day response window before the matter can be escalated to the Commissioner.

Why this matters: This is the first time in this incident that a regulator has publicly clarified who actually polices the vendor that just leaked, and the answer is uncomfortable. Roughly nine in ten Australian schoolchildren attend institutions where the OAIC has limited or no direct authority over the contractor sitting underneath their learning platform. For independent and Catholic schools, where the federal Privacy Act does apply, the read is that the regulator is now actively watching this case and the complaint pipeline will be open. For state-system SBMs, the read is the opposite: the formal recourse runs through the state privacy commissioner, not the federal one, and the question of who actually enforces a vendor breach is genuinely contested. The Children's Online Privacy Code, when it lands in December, is part of how this gets fixed. The OAIC's statement on the Instructure (Canvas) cyber incident.

The OAIC's Children's Online Privacy Code webinar is Wednesday at 1pm AEST, and edtech vendors should be in the room

The Commissioner is hosting an open webinar on the exposure draft of the Children's Online Privacy Code from 1pm to 2pm AEST this Wednesday 13 May. The session covers the background to the Code, the findings from earlier consultation rounds, an overview of the draft text, and how interested parties can participate in the formal consultation that closes 5 June. The Code will be registered by 10 December 2026 and applies to services "likely to be accessed by children", which by the OAIC's own scoping note covers childhood-development apps, parent-photo-sharing tools, and platforms that "support schools to monitor student performance".

Why this matters: The Canvas incident has done more to sharpen interest in this Code than any consultation paper could. School IT leaders and procurement teams running tenders this year should have someone in the webinar, because the Code is the framework every ed-tech contract from December onwards will need to be measured against. For vendors selling into Australian schools, the same logic applies in reverse: the suppliers that cannot demonstrate Code-readiness by August will lose deals in the September and October procurement rounds. The webinar is the cheapest way to read the regulator's intent on age assurance, default-off geolocation, and the new statutory deletion right. Registration and webinar detail via the OAIC's industry consultation page.

Adelaide has pulled its Canvas tenant offline, and online learning today is rescheduled

Adelaide University disabled access to Canvas (known on campus as myLearning) on Friday 8 May as a precautionary measure while investigations continue. Students received automatic assignment extensions to 15 May, were told not to log into the platform, and were warned that online learning on Monday 11 May would be unavailable and rescheduled. Flinders University has separately confirmed that student and staff data held within the Canvas platform may have been impacted. Together with the University of Sydney, Melbourne, RMIT, UTS, Western Sydney, Canberra, TasTAFE, ACU and Newcastle confirmations earlier in the week, the Australian institutional list is now well into the twenties.

Why this matters: This is the operational answer to the regulatory question one story up. With the Privacy Act covering only part of the picture, the more decisive response right now is at the institution level: pull the tenant, extend the deadlines, and notify the cohort. Adelaide and Flinders have both moved in that direction, and the question for other vice-chancellors today is whether their default posture is "wait for vendor advice" or "act on the precaution and back-fill later." The cost of the cautious move is one week of disrupted assessment and a tighter Term 2 schedule. The cost of waiting is the parent and student trust line, which has a much longer half-life. Adelaide University's Canvas incident notice, and the cross-institution picture via ACS Information Age.


The Monday picture is a regulator finally on the record, a vendor running out of time, and a Treasurer about to put a number against the rest of it. Wednesday morning will be either the cleanest read on Australian ed-tech policy in twelve months or the messiest. The work that determines which one happens today. More on the operational landscape at digitalattitudes.com.au.

More field notes