Submission 634 — The Pepperpot Collective (634

‹ PrevPage 1 of 22 · Source p. 1Next ›

Supplementary Submission — NDIS

Amendment Bill Inquiry

Safeguarding, Automation, and

Human Verification in NDIS

Decision‑Making

Submitted by:

Neil

Founder — The Pepperpot Collective™ (TPC™)

Date: July 2026 Submitted to:

Senate Community Affairs Legislation Committee

Contents

Executive Summary

Availability to Give Evidence

Statement of Expertise & Relevance

Why This Submission Matters

Key Concerns Summary

Recommendations to the Committee

  1. Purpose of This Supplementary Submission
  2. Relevant Provisions of the Bill
  3. Technical Risks of Automated Decision-Making Without Human Verification
  4. Evidence: When Automation Failed (Australia and Internationally)

4.1 Summary Table of Major Automation Failures

4.2 Key Statistics from Robodebt (Cautionary Precedent)

  1. Evidence: When Automation Succeeded — and Why 5.1 Summary Table of Successful Automation with Safeguards

  2. Systems Analysis: Reliability, Outages, and Participant Fear

6.1 Current NDIA System Reliability

6.2 Why Full Automation Amplifies Existing Risks

6.3 Trust, Consultation, and the Credibility Gap

  1. Recommendations to the Committee
  2. Closing Statement

Technical Annex

Safeguarded Hybrid Workflow (Foundational Requirements Model)

Proposed NDIS Automated Workflow (Bill-Based Model)

1

Executive Summary

This supplementary submission provides a detailed technical, safeguarding, and systems-engineering analysis of the automation and decision-making provisions contained within the NDIS Amendment Bill. Drawing on domestic and international evidence, lived experience, and ND-led system design principles, it demonstrates that the Bill’s current automation model lacks the mandatory safeguards required to ensure safety, legality, and public trust. Automation in disability support systems carries uniquely high stakes. When deployed without human verification, transparent audit trails, and participant-centred oversight, automated systems have repeatedly produced unlawful, harmful, and in some cases fatal outcomes. The submission highlights major automation failures — including Robodebt, UK disability assessments, and the Netherlands childcare algorithm — all of which collapsed because human oversight was removed and vulnerable communities were not consulted. These failures were systemic, not marginal, and resulted in large-scale harm, ministerial resignations, and billions of dollars in remediation. The submission further demonstrates that the NDIA’s current technology environment is not stable enough to support safety-critical automation. Participants already experience portal outages, data errors, inconsistent communication, and system unreliability. Introducing fully automated decision-making into an unstable system amplifies existing risks, increases the likelihood of catastrophic error, and creates a chronic state of fear for disabled Australians whose supports are life-sustaining. Through ND-led safeguarding work undertaken at The Pepperpot Collective™, and through the development of the hybrid automation-and-human safeguarding system Althing™, this submission shows that safe automation is possible — but only when automation is limited to early-signal detection, and when human verification is mandatory for all decisions affecting supports or safety. International examples of successful automation (Estonia’s digital government, clinical decision support systems, and banking fraud detection) confirm that automation only succeeds when strong human-in-the-loop safeguards are embedded from the outset. The submission concludes that the fully automated decision-making model proposed in the Bill is not defensible in its current form. Without mandatory human verification, transparent audit trails, independent oversight, and ND-led consultation, the NDIS risks replicating the failures seen in Australia and overseas — failures that have caused profound harm, eroded public trust, and destabilised national systems. To prevent foreseeable harm and ensure the NDIS becomes a world leader in safe, participant-centred automation, this submission provides seven core recommendations: mandating human verification, prohibiting fully automated adverse decisions, requiring transparent audit trails, establishing independent oversight, embedding ND-led consultation, guaranteeing participant challenge rights, and adopting safeguarding-first design principles. With these safeguards in place, automation can strengthen the NDIS. Without them, it risks irreparable systemic collapse.

2

Availability to Give Evidence

Iwish toadvise the Committeethat I am available to give evidence at a public hearing via video link. As a UK-based independent expert and the founder of The Pepperpot Collective™, I am unable to attend in person, but I would welcome the opportunity to expand on the technical, systems-engineering, and lived-experience insights provided in this supplementary submission. I am able to respond to detailed questions, clarify the risks associated with fully automated decision-making, and offer ND-led safeguarding

perspectivesthat mayassist the Committeeinits deliberations. Statement of Expertise & Relevance Iamthe founderofThePepperpotCollective™ (TPC™), a neurodivergent-led safeguarding organisation dedicated to building clarity-first, emotionally safe, and defensible systems for people who experience overwhelm, communication barriers, or vulnerability within complex administrative environments. My work is shaped by lived experience, including masking, shutdowns, and navigating systems that were not designed for neurodivergent people. These experiences have informed my professional focus: designing hybrid automation-and-human workflows that reduce cognitive load, prevent coercive control, and protect disabled people from administrative harm. My expertise is grounded in three intersecting domains:

  1. ND-led safeguarding design Through TPC™, I have spent years developing ND-friendly safeguarding frameworks that prioritise clarity, human verification, and participant-centred control. Our flagship safeguarding system, Althing™, currently in active development, uses automation only for early-signal detection and relies on mandatory human verification for all safety-critical decisions. This work gives me direct, practical insight into how automation can be deployed safely — and what safeguards are essential to prevent harm.

  2. Systems analysis and automation risk assessment My professional background includes designing and analysing complex systems, with a focus on reliability, failure modes, and human-in-the-loop verification. I have lived through a major automation failure myself: the 2009 collapse of the UK Disabled Students’ Allowance processing system, which left thousands of disabled students — including me — without essential equipment. This experience provides me with firsthand understanding of how unsafe automation can destabilise a support system, erode trust, and cause widespread harm.

  3. Independent, outsider perspective I have no contact with the Minister, the NDIA, or the NDIS. My assessment of the Bill is based solely on safeguarding principles, systems engineering logic, lived experience, and international precedent. This independence is critical: it ensures that my evidence is not influenced by political, organisational, or institutional pressures. My only interest is the safety and wellbeing of disabled Australians. Across my work, I have become deeply familiar with the fears, vulnerabilities, and communication barriers experienced by disabled people when interacting with opaque or unreliable systems. Through TPC™’s ND-led design ethos, I have built tools and frameworks that help people navigate complexity safely, communicate without fear, and remain protected from administrative or technological harm. This submission is therefore offered not only as a technical analysis, but as a safeguarding perspective informed by lived experience, professional expertise, and the development of a real-world hybrid automation system. It is my considered view — and the position of The Pepperpot Collective™ — that fully automated decision-making within the NDIS, without mandatory human verification, transparent audit trails, and ND-led oversight, poses a foreseeable and preventable risk to the safety, wellbeing, and trust of disabled Australians.

3

For these reasons, I respectfully submit that my expertise is directly relevant to the Committee’s examination of the NDIS Amendment Bill, and that my evidence may assist the Senate in assessing the safety, legality, and long-term consequences of the proposed automation model.

Key Concerns Summary

The following key concerns arise directly from the evidence, systems analysis, lived experience, and safeguarding principles outlined in this supplementary submission. They reflect the most critical and immediate risks posed by the automation and decision-making provisions of the NDIS Amendment Bill. Each concern highlights a structural vulnerability that, if unaddressed, has the potential to cause significant harm to disabled Australians, undermine public trust, and destabilise the integrity of the NDIS itself. These concerns are presented to assist the Committee in assessing the safety, legality, and long-term consequences of the proposed automation model.

1.RemovalofHumanVerificationCreates High-Risk, Unsafe Automation

The submission documents that automation failures in Australia and internationally occurred because human oversight was removed , leading to unlawful, harmful, and in some cases fatal outcomes. As stated in the document: “Removing human oversight creates unlawful and harmful systems.”

  1. NDIASystem Instability Makes Automation Dangerous The NDIA’s current technology environment is described as unreliable,opaque, and prone to outages, making it unsuitable as the foundation for safety-critical automated decision-making. “The system is perceived as unreliable, opaque, and difficult to trust.”

  2. Full Automation Amplifies Existing Failures The submission explains that combining an unstable system with fully automated decisions will amplify harm, create chronic fear, and increase the likelihood of catastrophic error. “An unreliable base system + full automation of safety-critical decisions = amplified harm.”

  3. Lack of ND-Led Consultation Undermines Credibility The Bill proposes automation without structured ND-led consultation, without mandatory human verification, and without transparent audit trails — a combination the submission identifies as not credible and not defensible. “No structured ND-led consultation has occurred… no mandatory human verification is proposed… no transparent audit trails are described.”

  4. International Evidence Shows Automation Fails Without Safeguards Robodebt, UK disability assessments, and the Netherlands childcare algorithm demonstrate that automation without human verification leads to systemic harm, ministerial resignations, and unlawful outcomes. “Automation failures are systemic, not marginal.”

4

  1. Full Automation Risks Replicating the DSA Collapse This submission provides the Committee with lived-experience evidence of the UK Disabled Students’ Allowance automation failure, demonstrating how unsafe automation can produce widespread delays, incorrect rejections, and severe distress. Based on that precedent, and on the risks identified throughout this submission, the fully automated systems proposed by the NDIA and NDIS carry an unacceptable likelihood of replicating similar failures — with far more serious consequences for disabled Australians. “The result was widespread delays, incorrect rejections, and thousands of disabled students… left without essential equipment.”

  2. Proposed NDIS Automation Lacks Defensibility The submission concludes that the Bill’s automation model cannot be defended due to missing safeguards, missing oversight, and missing participant-centred controls. “I cannot in good conscience say that any comparable defensibility could be mounted.” Recommendations to the Committee The following recommendations arise directly from the technical evidence, lived experience, international precedents, and systems analysis presented in this supplementary submission. They are designed to address the structural vulnerabilities identified throughout the document and to ensure that any automation deployed within the NDIS is safe, lawful, transparent, and defensible. Each recommendation reflects a safeguard that is essential for protecting disabled Australians from foreseeable harm and for preserving the integrity, stability, and public trust of the NDIS. Together, they form a practical, implementable framework that would allow the NDIS to benefit from automation without repeating the failures seen in Australia and overseas.

  3. Mandate Human Verification for All Automated Decisions All automated assessments affecting supports, eligibility, or safety must undergo mandatory human verification before any decision is enacted.

“Mandate human verification for all automated decisions affecting supports or safety.”

  1. Prohibit Fully Automated Adverse Decisions No adverse decision — including rejection, reduction, suspension, or debt creation — should ever be made without human oversight. “Prohibit fully automated adverse decisions.”

  2. Require Transparent Audit Trails All automated processes must generate clear,accessibleaudit trails that participants, reviewers, and oversight bodies can examine. “Require transparent audit trails for all automated processes.”

  3. Establish Independent Oversight of Automated Decision-Making A fully independent oversight body must be legislated, with powers to review automated decisions, investigate failures, and receive participant appeals. “Establish independent oversight of automated decision-making.”

5

  1. Embed ND-Led Consultation in Design, Testing, and Deployment Disabled people — especially neurodivergent people — must be involved in every stage of automation design, testing, and deployment. “Embed ND-led consultation in design, testing, and deployment.”

  2. Guarantee Participant Rights to Challenge Automated Decisions Participants must have clear, accessible rights to challenge any automated decision, with guaranteed human review and transparent reasoning. “Guarantee participant rights to challenge automated decisions.”

  3. Adopt Safeguarding-First Design Principles Automation must be built around safeguarding, not efficiency — including human-in-the-loop verification, override powers, and participant-centred controls. “Adopt safeguarding-first design principles.”

  4. Purpose of This Supplementary Submission This supplementary submission expands on my earlier evidence to the Committee. It addresses the automation and decision-making provisions within the NDIS Amendment Bill, providing:

  • Technical analysis of automated decision-making risks

  • Evidence from domestic and international automation failures

  • Examples of successful automation and the safeguards that made them safe

  • Systems analysis of current NDIA technology reliability and outages

  • ND-led safeguarding insights drawn from the development of Althing™, a hybrid automation-and-human safeguarding workflow

  • Recommendations to the Senate Committee for mandatory human verification, transparent audit trails, and participant-centred controls, which if implemented would ensure that the NDIS not only meets current Commonwealth guidelines on safeguarding, but exceeds them.

This submission is made in accordance with the Committee’s guidance that supplementary submissions may be lodged when new information or reflections arise that directly relate to the bill.

6

  1. Relevant Provisions of the Bill Thefollowing provisionsoftheNDISAmendment Bill are directly relevant to automation and safeguarding:
  • Decision-making powers of the NDIA, including the ability to use automated systems to assess, approve, or deny supports

  • Integrity and compliance mechanisms, including automated risk scoring or anomaly detection

  • Review and reconsideration processes, which may be influenced by automated triage or automated evidence weighting

  • Data use and information-sharing provisions, enabling automated decision- making pipelines These provisions create the legislative conditions under which automated systems may be deployed within the NDIS. They therefore require explicit safeguarding controls to prevent harm.

  1. Technical Risks of Automated Decision-Making Without Human

Verification

Automationindisability supportsystemscarries uniquely highstakes. Risksinclude:

  • False positives — legitimate supports flagged as suspicious

  • False negatives — genuine risk or fraud missed

  • Model drift — automated systems becoming less accurate over time

  • Data bias — training data not reflecting disabled Australians

  • Opaque decision pathways — participants unable to understand or challenge decisions

  • Automation escalation — compounding errors across multiple automated processes In a system where decisions directly affect safety, independence, and wellbeing, these risks are not theoretical — they are documented realities in other jurisdictions.

7

  1. Evidence: When Automation Failed (Australia and Internationally)

4.1 Summary Table of Major Automation Failures

System /     Context     Key Failure       Scale of Harm     Core Lesson

Country

Welfare debt                                      Removing  Robodebt –

recovery      Automated                        human    Australia

income        ~470,000 people       oversight

averaging         affected; ~$1.2B        creates

without human  refunded/compensated   unlawful and

verification harmful systems

NDIS                                                           Automation                   Planning,       Algorithmic   automation                                     Scale unclear;        deployed                           eligibility,    decision-making   concerns –                                   widespread fear         without                     debt           without    Australia                             among participants     consultation                 processes     transparency

or safeguards

Work     UK                                                                 Automated                      capability     Misclassification    disability                                         Linked to          triage cannot               assessments      of disabled    benefits                                  homelessness and       replace                              people as “fit for

automation                                     preventable deaths      human                                   work”

understanding

Netherlands     Fraud                                                                                           Integrity

childcare      detection        Biased          Thousands                                                                  systems can

benefits                    algorithm falsely  bankrupted; ministerial                                                                    cause

algorithm                   flagged families        resignations                                                                              catastrophic

false positives

Across all examples, the pattern is identical: Automation failed because human verification was removed, mechanisms surrounding systems and controls which ensure full accountability of the system and its operators were weak, and vulnerable communities were not consulted.

8

4.2 Key Statistics from Robodebt (Cautionary Precedent)

  • ~470,000 people affected
  • ~$720 millionrefunded
  • ~$400 million in unlawful debts scrapped
  • $112 million compensation paid • RoyalCommission found thesystem unlawful, unsafe, and indefensible

These figuresdemonstrate that automation failures are systemic, not marginal.

Both as the founder of The Pepperpot Collective™, as a human being, and—most importantly—as an outsider with lived experience of neurodiversity and professional experience in building complex systems, I find it deeply concerning that, despite the Royal Commission’s findings into Robodebt, the NDIA and the Minister have proposed a model of fully automated decision-making. The Australian Government’s own recent history demonstrates that removing human verification from high-stakes social support systems can produce unlawful, unsafe and, in some cases, fatal outcomes. Families affected by Robodebt reported losing loved ones to suicide following the distress caused by incorrect automated debts. Given this history, it is difficult to understand why a fully automated decision-making system is being pursued for the NDIS—particularly when the consequences of error in disability support are even more immediate, more personal, and more dangerous.

  1. Evidence: When Automation Succeeded — and Why 5.1 Summary Table of Successful Automation with Safeguards

Safeguards in

Domain        Automation Role                       Outcome

Place                             Routine                                   Efficiency without

administrative       Humanreview;          removing

Estonia digital                           automation          transparentlogs;        accountability

government participantaccess

Algorithmic Improved decisions

recommendations       Cliniciansretain       while protecting    Clinical decision

support                                  authority;override           safety

powers Reduced fraud with

Humanverification    Banking fraud    Automated anomaly                         minimal wrongful                                                    beforeaction;       detection             detection                                    freezes                                           appealpathways

Safe automation requires:

  • Human-in-the-loop verification
  • Override powers
  • Transparent audit trails
  • Accessible challenge pathways
  • Continuous consultation with affected communities These features are not yet visible in NDIS automation planning. Automation—and its sister innovation, artificial intelligence—hasproven to be one of the defining technological advances of the twenty-first century. However, in every instance where automation or AI has been deployed successfully in high-stakes environments, strong human-verification safeguards have been in place. These safeguards ensure not only that

9

automated decisions are correct, but also that any decision that appears suspect can be reviewed, challenged, and traced through a clear chain of accountability. This is what makes such systems defensible. At present, having reviewed the Bill, I cannot in good conscience say that any comparable defensibility could be mounted for the fully automated decision-making model proposed for the NDIS. The absence of mandatory human verification, transparent audit trails, and participant-centred oversight means that the system, as drafted, lacks the fundamental safeguards that make automation safe, lawful, and ethically acceptable.

  1. Systems Analysis: Reliability, Outages, and Participant Fear

6.1 Current NDIA System Reliability

The NDIA technology environment has experienced:

  • Portal outages affecting plan access and claims
  • Delays in plan updates linked to system issues
  • Inconsistent communication about system status
  • Errors in data synchronisation between systems While outage statistics are not centrally published, lived experience across the disability community is clear: the system is perceived as unreliable, opaque, and difficult to trust. Surely, given the well-documented lack of trust in the NDIA’s current system reliability, it would be reasonable to expect that improving the stability, transparency, and performance of the existing infrastructure would be a higher priority for both the NDIA and the Minister than introducing fully automated decision-making. Asking an already stretched, outdated, and frequently unreliable system to assess a disabled Australian’s eligibility for the NDIS is not simply premature — it is unsafe. As an independent party, and as someone with no contact with the Minister, the NDIA, or the NDIS, my assessment of the system is based solely on its observable performance. Even on its best days, the current system appears to operate on the edge of collapse; on its worst days, it presents as a system approaching the point of no return. Cutting funding or increasing reliance on automation will not resolve these foundational issues. Instead, such changes risk exacerbating existing failures into a full systemic collapse — one that would cause irreparable harm not only to disabled Australians and their trust in government, but to the broader Australian public who rely on the integrity and stability of national systems.

10

6.2 Why Full Automation Amplifies Existing Risks

From a systems engineering perspective:

  • An unreliable base system

    • full automation of safety-critical decisions
  • = amplifiedharm Participants cannot distinguish between:

  • atechnicalfailure

  • anautomatedadversedecision

  • anintentionalpolicychange Thiscreatesachronic state of fear,especiallyforpeople whose supports are life sustaining.

I amaneurodivergentmanwithminimalsupportneeds; however, I recognise that many neurodivergentpeople,aswellaspeoplewithphysical disabilities or a combination of both, relyontheNDISsimplytoexist.Itisontheirbehalfthat I express my concerns to the SenateCommittee.IntheUnitedKingdom,achronicstate of fear became deeply embedded in thedisabledcommunityfollowingasevereautomation and processing failure in 2009 involvingtheDisabledStudents’Allowance(DSA).The DSA is a government-funded support schemethatprovidesessentialequipment,assistivetechnology, and non-medical support to disabledstudentssotheycanparticipateinhighereducation on an equal footing. When the UK StudentLoansCompanyattemptedtoautomatesignificant parts of the DSA assessment and processingworkflow,theresultwaswidespreaddelays, incorrect rejections, and thousandsofdisabledstudents—myselfincluded—being left without the essential equipment we reliedupontocompleteourstudies. The subsequentHopkinReviewattributedthefailureto “management indecision and overoptimism.”Itispreciselythisoveroptimismthatboth I, as founder, and The Pepperpot Collective™ seereflectedintheAustralianGovernment’s proposal to introduce fully automated decision-makingforsafety-criticalNDISassessments—a category which, I hope, both myself, The Pepperpot Collective™,andtheHonourable Members of the Senate Committee agree encompasseseveryNDISapplication. Based on my personal experience of the DSA automation failure,itismyconsideredopinion—and the position of The Pepperpot Collective™—thatfullyautomatingsafety-critical decisions within the NDIS risks creating a similar scandal, onlywithfarmoreseriousand far-reaching consequences for the safety, wellbeing, and trust oftheAustralianDisabledCommunity.

6.3 Trust, Consultation, and the Credibility Gap A fully automated NDIS asks disabled people to believe that the same system that currently

produces outages and  instability  will somehow become safer once human oversight  is

removed. This is not credible to the disabled community both in Australia and at large when no structured Disability-led consultation has occurred, no mandatory human verification is proposed and, most concerning of all no transparent audit trails have been described. By contrast, in Althing™’s design, developed by The Pepperpot Collective™ automation is used only for early-signal detection, never for final decisions. We have designed the Althing™ system so that human verification is considered to be mandatory at every safety-critical stage with disabled people shape the system’s logic, risk signals, and escalation pathways. This demonstrates that trustworthy automation is possible — but only when disabled people are at the beating heart of design.

11

When we compare the proposed NDIS safeguards for fully automated decision-making with our safeguarding system currently in active development — Althing™, named after the Icelandic “assembly field” because it gathers information from all stakeholders, especially the disabled individual — the contrast is stark. Althing™ assesses early safeguarding signals, interprets risk in context, and recommends appropriate human-verified actions. The NDIS proposal, by comparison, lacks these foundational safeguards. It is not merely incomplete; it is fundamentally flawed to the point of being beyond dangerous.

  1. Recommendations to the Committee
  • Mandatehumanverificationforallautomated decisions affecting supports or safety.

Individuals responsible for this verification must be protected under all Australian state, territory, and federal laws from any form of key performance indicator (KPI) or target-based pressure — regardless of the terminology used, and regardless of the seniority or position of the person setting such targets within the Australian Public Service or Government, including the Minister. Without these protections, the integrity of the system is placed at risk, and disabled people are exposed to unnecessary, unethical, and potentially dangerous forms of administrative control that, even from an external observational standpoint, could only be interpreted as serving political or organisational interests rather than safeguarding the community. Prohibit fully automated adverse decisions. A fully automated system that removes essential safeguardshasthepotentialto •

collapse under the volume of appeals it will generate. Fromanoperational standpoint, I understand that the Minister has expressed theviewthattheNDIS requires tighter budgetary controls. However, the combinationofproposedfunding reductions, stricter financial constraints, and a fully automateddecision-making model with no human verification has the economic potentialtocosttheAustralian Government — and, by extension, the Australian taxpayer—significantlymorethan the savings repeatedly announced. Increased appeals,systemfailures,and corrective actions are all foreseeable consequences ofunsafeautomation.

In addition, a fully automated decision-making processintroducesheightenedrisksof fraud, corruption, and rorting within the NDIS. Based onmyreadingoftheBill,itis unclear whether this same automated process may laterbeappliedtofraud-related determinations. If so, this would represent a policy directionthatnoglobal private-sector financial institution currently uses, nor —tothebestofmyknowledge — do they intend to adopt. The absence of human oversightinsafety-criticalor fraud-sensitive decisions is not considered acceptablepracticeinanycomparable sector. Require transparent audit trails for all automatedprocesses

  • . It is essential that the NDIS and the participant can understand notjustwhythe automated process made the decision it has suggested but also,mostcruciallyhowit made the decision. Automated systems can be a brilliant additiontothedecision matrix, however, and this is the most important aspect to both myownandThe Pepperpot Collective’s concerns regarding a fully automated system,thesystem requires human input of the information which it is using to establishitsdecision,a single missed piece of supporting evidence, which may have accidentlyslippedthe input process could be the difference between and NDIS participantreceivingthe essential supports they require or not receiving despite all availableevidenceboth

12

documented and physical exceeding the requirements for the participant to have their supports funded via an NDIS plan. Establish independent oversight of automated decision-making.

  • At school a teacher marks your homework and the NDIS and NDIA being the only organisations to lodge an NDIS application, but also appeal the proposed fully automated systems decision amounts to this. An independent oversight body which NDIS applicants can appeal their decision will mean that the minster is serious about reforming the NDIS. This independent oversight body would require the NDIS and NDIA to justify the decision that has been made with regards to the applicants NDIS, likewise the applicant must be able to justify their belief that they are entitled to the NDIS. Afterall, both sides must be in agreement for an NDIS plan to be drawn up and the participant to access the vital supports which enable them to have access to a full and fulfilling life. Embed disabled-led consultation throughout the design, testing, and deployment of any automated NDIS system.

It is clear that the systems proposed in the current Bill have not undergone the level of rigorous, ND-led design and testing that should be expected of technology being deployed across a multi-billion-dollar federal scheme affecting millions of disabled Australians.

By contrast, at The Pepperpot Collective™, the safeguarding system we are developing — Althing™ — has already undergone an intensive, structured, and year-long design phase. Every element of Althing™’s logic, risk signalling, and escalation pathways has been shaped through ND-led principles and subjected to rigorous scrutiny. We expect the next phases of Althing™’s development to be equally, if not more, exacting. This level of rigour is not optional for safety-critical systems. It is the minimum standard required to ensure that automation supports disabled people rather than placing them at risk. Guarantee participant rights to challenge automated decisions. • As previously stated, a fully independent oversight body should be established, and participants must have the right to appeal any automated or human decision directly to that body. This safeguard must be formally enshrined within the NDIS legislative framework. Without an independent avenue for appeal, disabled people are left vulnerable to administrative error, unsafe automation, and decisions that cannot be meaningfully challenged. Embedding this oversight mechanism in the legislation is essential to ensuring accountability, transparency, and the long-term integrity of the

NDIS

Adopt safeguarding-first design principles. • Human verification and clear audit trails for all automated decisions are not optional features; they are fundamental safeguards required to ensure fairness, accountability, and system integrity. These protections do not only safeguard disabled applicants — they also safeguard the NDIS itself from systemic failure, unsafe automation, and unintended consequences. Without mandatory human oversight and transparent decision-making records, the system becomes vulnerable to error, exploitation, and loss of public trust. This, in turn, risks triggering an irreparable systemic collapse of the NDIS — a collapse that is entirely preventable. It is my hope that, through this supplementary submission, both as an individual and as founder of

13

The Pepperpot Collective™, I have established within the Committee’s conscience that such an outcome must never be allowed to occur.

These recommendations align with international best practice and lessons learned from automation failures.

  1. Closing Statement As the neurodivergent founder of The Pepperpot Collective™, I want to close by expressing a sentiment held deeply across the disabled community, not just in Australia but globally. There is a line from the Assassin’s Creed series that says, “We live in the dark to serve the light.” For many disabled people, this reflects a lived reality: we are often pushed to the outer edges of society, expected to navigate systems that are opaque, overwhelming, or unsafe. Yet the light we serve is the truth — and the truth in this case is that fully automating safety-critical NDIS decisions carries a real and foreseeable risk of causing preventable

    harm, including loss of life. This is not rhetoric; it is a warning grounded in international

precedent, lived experience, and the lessons of Robodebt and, with reference to the UK the Disabled Student Allowance. A second quote, one from my school days, has stayed with me throughout my life: “Nothing is certain, everything is possible.” It is a reminder that our actions — direct or indirect — have consequences that extend far beyond what we can immediately see. In the context of this Bill, it is a call for caution. The decisions made by the Australian Government and the Senate regarding automation will shape the safety, wellbeing, and trust of disabled Australians for generations. The possibility of harm is real, and the uncertainty surrounding the proposed system’s reliability must be taken seriously. For these reasons, I respectfully urge the Committee to consider the evidence presented in this supplementary submission, and to ensure that any future automation within the NDIS is grounded in safeguarding, human verification, and the lived experience of disabled people. I firmly believe that automation can strengthen the NDIS and have the positive impact not only on its growth rates which are key focus of the minister, but also the outcomes of NDIS participants — but only if it is built with disabled people, not imposed upon them. Without robust safeguards, mandatory human verification, and ND-led oversight, the NDIS risks replicating the failures seen in Australia and overseas: systems that are unethical, indefensible, harmful, in some cases illegal and, potentially fatal. With the right controls, it is my personal belief and, by extension the belief of The Pepperpot Collective™, that the NDIS can become a world leader in safe, participant-centred automation.

14

TECHNICAL ANNEX

Hybrid Automation Safeguarding Workflow (Non-Althing Example) Thisexample is not theAlthing workflow.Itisageneric hybridsafeguarding model illustrating how automation and human verification can work together safely.

15

Hybrid Safeguarding Workflow (Developed Using Established ND‑

Led Safeguarding Principles)

Application Received (Human + Automation) 1. The participant submits an application or evidence update. Automation performs basic intake

checks (completeness, formatting, missing documents).No decisions are made at this stage.

Automated Early Signal Detection (Automation)

The system scans for early indicators such as: 2.

  • unusual spending patterns
  • missed supports
  • sudden changes in provider behaviour
  • environmental or contextual risk signals
  • participant reported concerns Automation flags signals, not outcomes.

Automated Risk Categorisation (Automation)

  1. Signals are grouped into:
  • Low risk → monitor only
  • Medium risk → requires human review
  • High risk → requires immediate human verification No automated action is taken.

16

  1. Mandatory Human Verification (Human) A trained safeguarding officer reviews:
  • participant context

  • history and previous decisions

  • communication needs

  • cultural and ND specific considerations

  • environmental factors

  • any flagged signals The human verifier can:

  • confirm the signal

  • dismiss it

  • request more information

  • escalate to specialist safeguarding teams

  1. Draft Decision Prepared (Human) The human verifier prepares a draft decision or recommendation. Automation may assist

with documentation, but cannot issue a final decision.

Participant Review & Response (Human + Participant)

  1. The participant receives the draft decision and is invited to:
  • agree
  • disagree
  • request clarification
  • provide additional evidence This step is essential — it ensures the participant is not excluded from the decision making

process.

  1. Transparent Notification & Audit Logging (Human + Automation) The participant receives a clear explanation of the decision. All steps — automated and

human — are logged in a transparent audit trail accessible to oversight bodies.

17

  1. Challenge Pathway (Participant + Human) The participant receives the draft decision and is invited to:
  • agree
  • disagree
  • request clarification
  • provide additional evidence This step is essential — it ensures the participant is not excluded from the decision making

process.

  1. Continuous Feedback Loop (Human + Automation) The participant receives the draft decision and is invited to:
  • agree
  • disagree
  • request clarification
  • provide additional evidence This step is essential — it ensures the participant is not excluded from the decision making

process.

  1. Final Human Decision (Human) A human decision maker reviews the participants response and finalises the decision.

Automation cannot override or issue adverse decisions.

18

Proposed NDIS Fully Automated Workflow (Bill‑ Based Model)

19

Proposed NDIS Fully Automated Workflow (Bill‑ Based Model)

This workflow reflects what the Bill enables, not what would be safe or best practice.

  1. Application Received (Automation) Participant submits an application, evidence update, or plan variation request. The system

automatically ingests the data and assigns it to an automated processing pipeline. No

human review is required at intake.

  1. Automated Evidence Processing (Automation) The system evaluates: participant submitted documents, provider reports, historical plan

data spending patterns, compliance indicators, risk scores. Algorithms determine what

evidence is relevant and how much weight it should carry. No human verification is

mandated.

  1. Automated Eligibility or Support Assessment (Automation) The system performs automated assessment of: eligibility reasonable and necessary

supports plan budgets compliance or integrity concerns, potential debts or overpayments. This is the core automation power granted by the Bill. No human decision ‑ maker is required.

  1. Automated Decision Issued (Automation) The system generates a final decision, which may include: approval, reduction, rejection,

suspension, debt creation or compliance flags. The Bill does not require human verification

before issuing an adverse decision.

  1. Automated Notification to Participant (Automation) The participant receives an automated notice explaining:thedecision the outcome, any

changes to their supports, any compliance actions. TheBilldoes not require: a human explanation a human contact, a human review, a human‑accessible audit trail

  1. Participant Reaction (Participant) The participant may: accept the decision, disagree, request clarification, or lodge a review.

However, all of these actions occur after the automated decision has already taken effect.

This is a reactive model, not a safeguarding model.

20

  1. Optional Human Review (Human, but only if requested) Ifthe participant challenges the decision: a human reviewermay examine the automated

output the reviewer may overturn or uphold the decision thereviewer may request additional

evidence However: the Bill does not require human reviewfor every automated decision the

burden is on the participant to initiate review harm may already have occurred before review

begins

Final Outcome (Automation + Human) 8.

The system updates the participants planorcompliance status based on: the automated

decision any human review outcome Audittrails may exist internally, but the Bill does not

require: transparent audit logs participantaccess independent oversight of automated logic

System Learning (Automation)

Automated decisions feed backintothe system to: refine risk scoring adjust evidence

weighting modify eligibility patternsupdate compliance algorithms. This occurs without any

mandatory human oversight.

21