When looking at the definition of “systemic vulnerability”.... There might be amendments that speak to this as we move along. The minister has spoken about this publicly. The term “systemic vulnerability” is understood to mean, from a government perspective.... It is not targeting end-to-end encryption. As such, the answer to your question will depend on a specific situation. If the regulation or a ministerial order mandates something, the core provider, person or company subject to the order would not have to do anything if it creates a vulnerability in their system.
That's how the legislation in part 2 is constructed. There's a process for developing regulation that everybody is familiar with. Ministerial orders have a very specific process that involves electronic service providers, law enforcement, the minister and the intelligence commissioner. There's a process there. At any point during that process, if an electronic service provider says to us—because they know their system best—that introducing a capability would create a systemic vulnerability, there's an opportunity to address this and make sure it doesn't.
