Law / Australia

Australia

20 of 23 named instruments researched to a stage, across all six areas of law we track: 17 in force, 1 enacted but not yet in force and 2 proposed. As of 12 September 2026.

When they take effect17 of 20 carry a date, 3 do not. Earlier is before 2014.
Before 2014: 5 instruments (5 in force) earlier 2014: 1 instrument (1 in force) 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 1 instrument (1 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 1 instrument (1 in force) 2022: 0 instruments 2023: 0 instruments 2024: 1 instrument (1 in force) 2025: 4 instruments (4 in force) 2026: 4 instruments (3 in force, 1 enacted but not yet in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blockedcourt decision

  1. AI law 1
  2. Privacy law 5
  3. Scraping law 3
  4. Cybersecurity law 1
  5. Age gating law 6
  6. News aggregation law 4

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (219 words)

Australia has no general or cross-sector artificial intelligence statute. The government's National AI Centre issued a voluntary AI Safety Standard and separately consulted on a proposed set of mandatory guardrails for AI used in high-risk settings, but neither has been enacted as legislation and neither currently binds any person.

The Criminal Code Amendment (Deepfake Sexual Material) Act 2024 is the one enacted duty that reaches AI-generated content specifically: it criminalises using a carriage service to transmit sexual material of another person without consent regardless of whether that material is unaltered or has been created or altered using technology, including artificial intelligence, so it reaches a sexual deepfake on the same terms as an authentic recording, with a higher maximum penalty for the person who created or altered the material.

The Online Safety Act 2021 and its registered industry codes carry no duty that is specific to artificial intelligence as such; the age-assurance duties they impose, including on generative AI services capable of producing restricted material, are researched under the age topic.

The Privacy Act 1988's automated decision-making transparency duty, inserted into Australian Privacy Principle 1 and commencing 10 December 2026, attaches to the personal information used in a decision rather than to the AI system making it, and is researched and landed under the privacy topic rather than here.

AI prohibited practices

Using a Carriage Service to Transmit Sexual Material Without Consent (Deepfake Offences)

Criminal Code Amendment (Deepfake Sexual Material) Act 2024 (Cth) No. 78, 2024, inserting ss. 474.17A, 474.17AA into the Criminal Code Act 1995 (Cth), No. 12, 1995official Act text, Federal Register of Legislation

In force since 3 September 2024. Binds public and private bodies.

What this law does

This Act inserted sections 474.17A and 474.17AA into the Criminal Code Act 1995, making it an offence to use a carriage service to transmit material depicting, or appearing to depict, a person aged 18 or over in a sexual pose or activity, or their sexual organ, anal region, or, for a female, breasts, without their consent, where the person transmitting it knows of the lack of consent or is reckless as to it.

It is irrelevant whether the transmitted material is unaltered or has been created or altered using technology, including artificial intelligence, to generate a realistic but false depiction of the person, the kind of material commonly called a deepfake.

The base offence carries a maximum of 6 years imprisonment; a person who transmits such material after 3 or more prior civil penalty orders for non-compliance with an Online Safety Act 2021 removal notice, or who was responsible for creating or altering the material themselves, faces an aggravated offence carrying a maximum of 7 years imprisonment.

What it requires

Privacy law5 instruments, 4 in force, 1 enacted but not yet in force

Research summary (146 words)

Australia's Privacy Act 1988 (Cth) is the comprehensive personal-data regime, binding Australian Government agencies and organisations with an annual turnover over $3,000,000 through the Australian Privacy Principles in Schedule 1, with sensitive information (including biometric information and biometric templates) requiring the individual's consent to collect.

A statutory notifiable data breaches scheme requires notice to both the Information Commissioner and affected individuals once an entity has reasonable grounds to believe an eligible data breach occurred. The Privacy and Other Legislation Amendment Act 2024 added a statutory tort for serious invasions of privacy, in force since 10 June 2025, and will add an automated decision-making transparency duty to Australian Privacy Principle 1 from 10 December 2026.

A further amendment power lets the Information Commissioner develop a Children's Online Privacy Code under section 26GC, with an exposure draft out for consultation as of mid-2026 but no code yet registered.

Breach notification

Privacy Act 1988 (Cth), Notifiable Data Breaches Scheme

Privacy Act 1988 (Cth), Part IIIC, ss. 26WE, 26WK, 26WLofficial consolidated Act text, Federal Register of Legislation

In force since 22 February 2018. Binds public and private bodies.

What this law does

An entity holding personal information that is required to comply with Australian Privacy Principle 11.1 (security of personal information) must notify an eligible data breach, meaning unauthorised access to or disclosure of information that a reasonable person would conclude is likely to result in serious harm.

The entity must give a copy of a statement about the breach to both the Information Commissioner and the affected individuals as soon as practicable after becoming aware of reasonable grounds to believe the breach occurred.

What it requires

Comprehensive regime

Privacy Act 1988 (Cth), Comprehensive Regime and Civil Penalties

Privacy Act 1988 (Cth), No. 119, 1988, ss. 6, 13, 13G, 13H, 14, 15official consolidated Act text, Federal Register of Legislation

In force since 1 January 1989. Binds public and private bodies.

What this law does

Binds Commonwealth agencies and organisations, including businesses with an annual turnover over $3,000,000, to comply with the Australian Privacy Principles in Schedule 1. It also extends to an act done or a practice engaged in outside Australia by an entity with an Australian link.

An entity contravening the Act through a serious interference with privacy faces a civil penalty of up to $50,000,000, three times the value of the benefit obtained, or 30% of adjusted turnover during the breach period, whichever is greatest, for a body corporate, or up to $2,500,000 for an individual; a non-serious interference carries a lower civil penalty of up to 2,000 penalty units.

What it requires

Data subject rights

Privacy and Other Legislation Amendment Act 2024 (Cth), Automated Decision-Making Transparency

Privacy and Other Legislation Amendment Act 2024 (Cth) No. 128, 2024, Schedule 1, Part 15, inserting Australian Privacy Principles 1.7 to 1.9 into Schedule 1 to the Privacy Act 1988official Act text, Federal Register of Legislation

In force in 78 days, effective 10 December 2026. Binds public and private bodies.

What this law does

Inserts a new Australian Privacy Principle 1.7 to 1.9 requiring an APP entity's privacy policy to disclose, for computer programs the entity uses to make decisions that could reasonably be expected to significantly affect an individual's rights or interests, the kinds of personal information used in that decision-making and the categories of decisions made.

Received Royal Assent on 10 December 2024, and the commencement table fixes the day for this Schedule at 24 months after Assent, so the disclosure duty takes effect on 10 December 2026.

What it requires

Enforcement supervision

Privacy Act 1988 (Cth), Schedule 2, Statutory Tort for Serious Invasions of Privacy

Privacy and Other Legislation Amendment Act 2024 (Cth), No. 128, 2024, Schedule 2, inserting Schedule 2 to the Privacy Act 1988official consolidated Act text, Federal Register of Legislation

In force since 10 June 2025. Binds public and private bodies.

What this law does

Creates a new statutory tort giving an individual a cause of action for a serious invasion of privacy, by intrusion upon seclusion or by misuse of information, where the person invading privacy intended or was reckless as to the invasion and a reasonable person would consider it serious.

The Federal Register of Legislation's amendment-history endnote for the Privacy Act records this Schedule as commencing 10 June 2025, the six-month backstop date under the amending Act's own commencement table because no earlier Proclamation was recorded.

What it requires

Sensitive categories

Privacy Act 1988 (Cth), Schedule 1, Sensitive and Biometric Information

Privacy Act 1988 (Cth), Schedule 1, Australian Privacy Principle 3, read with s. 6official consolidated Act text, Federal Register of Legislation

In force since 12 March 2014. Binds public and private bodies.

What this law does

An APP entity must not collect sensitive information about an individual, defined to include biometric information used for automated biometric verification or identification and biometric templates, unless the individual consents and the collection is reasonably necessary for the entity's functions, or a listed exception applies.

This is the provision that reaches a voiceprint or faceprint collected for biometric identification, on top of the entity's general Australian Privacy Principle 3 duty for ordinary personal information.

What it requires

Scraping law3 instruments, 3 in force

Research summary (398 words)

Australia has no scraping-specific statute, so general law governs each dimension separately.

The Criminal Code Act 1995 (Cth) reaches unauthorised access to a computer, but its dedicated section for accessing or modifying data, section 478.1, is limited to restricted data, meaning data to which access is controlled by an access control system, so a scraper reading a public, unauthenticated page without defeating any access control falls outside a plain reading of that section, and access is unauthorised only where the person is not entitled to cause it.

No reported Australian decision has tested whether a browsewrap or clickwrap terms-of-service is enforceable against a scraper, or whether continuing to access a site after a cease-and-desist notice or after a technical block converts otherwise-public access into a trespass; Australian law does not recognise a distinct trespass-to-chattels or hot-news misappropriation doctrine, so a claim of that kind rests only on the general tort of passing off or a contract claim, neither of which has been applied to scraping in a reported case.

The Copyright Act 1968 (Cth) permits fair dealing for research or study, criticism or review, parody or satire, and reporting news, but Australia has no text-and-data-mining exception, and in October 2025 the Attorney-General confirmed the Government would not introduce one, so training a model on scraped copyrighted text rests only on whichever fair-dealing purpose can be shown; a compilation of data is protected as a literary work if it involves sufficient independent intellectual effort in selection or arrangement, but the High Court's rejection of a 'sweat of the brow' standard means Australia has no sui generis database right and only thin protection for a database that is a mere compilation of facts.

The Privacy Act 1988 (Cth) applies to personal information regardless of whether it is drawn from a publicly accessible source, so scraping personal information from a public Australian website remains subject to the Australian Privacy Principles' collection, use and disclosure duties for any APP entity (an Australian Government agency, or an organisation with an annual turnover over $3,000,000) with an Australian link.

No Australian statute or reported case assigns legal weight to a robots.txt directive, and no Australian statute imposes an AI-training-specific scraping rule; the Government's July 2026 AI safety priorities include a possible statutory or collective licensing scheme for AI training on copyrighted work, but no Bill implementing it had been introduced as of this review.

Computer misuse

Criminal Code Act 1995 (Cth), Part 10.7, Unauthorised Access to Restricted Data

Criminal Code Act 1995 (Cth), Schedule (the Criminal Code), Part 10.7, ss. 476.2, 478.1official consolidated Act text, Federal Register of Legislation

In force since 21 December 2001. Binds public and private bodies.

What this law does

Section 478.1 makes it an offence, punishable by up to 2 years imprisonment, to cause unauthorised access to, or modification of, restricted data, meaning data held in a computer to which access is restricted by an access control system, intending to cause the access or modification and knowing it is unauthorised.

Access is unauthorised under section 476.2 only if the person is not entitled to cause it, so a scraper reading a public, unauthenticated page without defeating any access control falls outside a plain reading of the offence, and no reported Australian case has tested a scraping fact pattern under this Part.

What it requires

Personal data

Privacy Act 1988 (Cth), Reach Over Scraped Personal Information

Privacy Act 1988 (Cth), No. 119, 1988, Schedule 1, Australian Privacy Principles 3 and 6, read with s. 6official consolidated Act text, Federal Register of Legislation

In force since 1 January 1989. Binds public and private bodies.

What this law does

The Privacy Act 1988's definition of personal information carries no exception for information that is publicly accessible, so an APP entity (an Australian Government agency, or an organisation with an annual turnover over $3,000,000) that scrapes personal information from a public website, including for AI training, must still collect it only where reasonably necessary for its functions under Australian Privacy Principle 3.

It may use or disclose that information for another purpose only within the Australian Privacy Principle 6 exceptions. The entity must still have an Australian link for the Act to reach conduct outside Australia.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (422 words)

The Cyber Security Act 2024 (Cth) created Australia's first standalone product-security duty: Part 2 requires a manufacturer to manufacture, and a supplier not to supply, a relevant connectable product that will be acquired in Australia except in compliance with the security standard the rules set for its class, and the Cyber Security (Security Standards for Smart Devices) Rules 2025 apply that duty to most consumer grade smart devices from 4 March 2026.

The same Act's Part 3 requires a reporting business entity to report a ransomware or cyber extortion payment to the Australian Signals Directorate within 72 hours of making it, a duty active since 30 May 2025; a reporting business entity is a business carrying on in Australia with an annual turnover exceeding the AUD 3,000,000 threshold the Cyber Security (Ransomware Payment Reporting) Rules 2025 set, or a responsible entity for a critical infrastructure asset to which Part 2B of the Security of Critical Infrastructure Act 2018 (Cth) applies.

Because that duty attaches to a business's turnover or to its status as a critical infrastructure operator rather than to any activity this corpus can flag an app against, it is recorded here rather than raised against a declared activity.

The Security of Critical Infrastructure Act 2018 (Cth) itself binds the responsible entity for a critical infrastructure asset across a wide range of nationally significant sectors with a critical infrastructure risk management program duty under Part 2A, an incident-notification duty under Part 2B, and, for a system of national significance, enhanced cyber security obligations under Part 2C; none of those duties attaches to an activity this corpus can express, so the Act is likewise deferred rather than raised on a guess, exactly as the ransomware-reporting cross-reference is.

Part 4 of the Cyber Security Act allows an entity to voluntarily share information about a significant cyber security incident with the National Cyber Security Coordinator, and Part 5 establishes a Cyber Incident Review Board to review certain incidents; neither creates a duty on a developer, and neither is recorded as an instrument here.

Australia has no separate reasonable-security or information-security-programme statute outside the Privacy Act 1988 (Cth): the Act's own Australian Privacy Principle 11 duty to take reasonable steps to protect personal information sits inside the comprehensive regime already researched as this jurisdiction's privacy row, and the Notifiable Data Breaches scheme in Part IIIC of the same Act, the duty to notify the Information Commissioner and an affected individual of an eligible data breach, is that jurisdiction's breach-notification finding and is not repeated here.

Product security requirements

Security Standards for Smart Devices

Cyber Security Act 2024 (Cth) No. 98, 2024, Part 2, ss. 13-24; Cyber Security (Security Standards for Smart Devices) Rules 2025 (F2025L00276), Schedule 1Official text, legislation.gov.au, Cyber Security Act 2024, Part 2

In force 7 months, effective 4 March 2026. Binds private bodies.

What this law does

A manufacturer of a relevant connectable product, a product able to connect directly or indirectly to the internet or to another such product by a like means, must manufacture it in compliance with the security standard the rules set for its class if the manufacturer is aware, or could reasonably be expected to be aware, that the product will be acquired in Australia, and a supplier must not supply a product that was not manufactured in compliance with that standard.

The Cyber Security (Security Standards for Smart Devices) Rules 2025 apply the standard to most consumer grade relevant connectable products manufactured on or after 4 March 2026, and a product manufactured before that date is not required to comply. The standard bans a universal default password, requiring the device's hardware and any pre-installed or required software to use a password unique to the unit or set by the user for any state other than the factory default.

It requires the manufacturer to publish a means for a security issue to be reported to the manufacturer, with status updates on the resolution of a reported issue, and to publish the period, including an end date, for which the device will receive security updates. A desktop computer, a laptop, a tablet computer, a smartphone, a therapeutic good, a road vehicle, and a road vehicle component are excluded from the standard.

The manufacturer must provide, and the supplier must supply the product with, a statement of compliance with the security standard, and each must retain a copy for five years.

The Secretary of the Department of Home Affairs enforces the regime through a compliance notice, a stop notice, and a recall notice rather than through a fine, and may publish an entity's identity, product details, and the risks posed by the product on the Department's website if the entity fails to comply with a recall notice.

What it requires

Age gating law6 instruments, 5 in force, 1 proposed

Research summary (162 words)

Australia's Online Safety Amendment (Social Media Minimum Age) Act 2024 requires age-restricted social media platforms to take reasonable steps to stop under-16s holding accounts, an obligation that took effect on 10 December 2025 and remains in force despite a pending High Court constitutional challenge that has not produced an injunction.

Separately, nine eSafety-registered industry codes made under the Online Safety Act 2021 require age assurance for Class 1C and Class 2 material such as online pornography across search engines, websites and generative AI services, and app distribution platforms, phasing in between December 2025 and September 2026.

A statutory children's online privacy design code is still in development: an exposure draft under section 26GC of the Privacy Act 1988 is out for consultation, but the Code need not be registered until 10 December 2026, so no enforceable design code exists yet. eSafety's voluntary Safety by Design principles and its 2023 age verification roadmap report informed this framework but are not themselves binding instruments.

Adult content age verification (AV)

Designated Internet Services Online Safety Code (Class 1C and Class 2 Material)

Designated Internet Services Online Safety Code (Class 1C and Class 2 Material) registered under section 140 of the Online Safety Act 2021 (Cth)registered industry code text, eSafety Commissioner register

In force 7 months, effective 9 March 2026. Binds private bodies.

What this law does

Requires providers of designated internet services, including websites hosting online pornography and generative AI services capable of producing Class 1C or Class 2 material, to implement age assurance and access controls to prevent access by children in Australia. Registered by the eSafety Commissioner on 9 September 2025.

Note and primary source

Internet Search Engine Services Online Safety Code (Class 1C and Class 2 Material)

Internet Search Engine Services Online Safety Code (Class 1C and Class 2 Material) registered under section 140 of the Online Safety Act 2021 (Cth)registered industry code text, eSafety Commissioner register

In force 9 months, effective 27 December 2025. Binds private bodies.

What this law does

Requires providers of internet search engine services, such as Google Search and Bing, to implement appropriate age assurance measures so that account holders are checked as over or under 18 before search results can surface Class 1C or Class 2 material, including online pornography. Registered by the eSafety Commissioner on 27 June 2025, with the age assurance measure itself required within 6 months of the code coming into effect, by 27 June 2026.

Note and primary source

Age-appropriate design code

Children's Online Privacy Code (Privacy Act 1988, section 26GC)

Privacy Act 1988 (Cth), section 26GC, inserted by the Privacy and Other Legislation Amendment Act 2024 (Cth), No. 128, 2024official statute text, Federal Register of Legislation

Proposed: draft date not recorded. Binds private bodies.

What this law does

Requires the Australian Information Commissioner to develop and register an Australian Privacy Principles code addressing the privacy of children, covering social media services, relevant electronic services and designated internet services likely to be accessed by children, within 24 months of the amending Act's Royal Assent on 10 December 2024, that is, by 10 December 2026.

An exposure draft, drawing partly on the UK Age Appropriate Design Code, was released for public consultation from 31 March to 5 June 2026 and includes proportionate age assurance and limits on retaining facial age estimation data, but the Code is not yet finalised or registered.

Note and primary source

App store age verification (AV)

App Distribution Services Online Safety Code (Class 1C and Class 2 Material)

App Distribution Services Online Safety Code (Class 1C and Class 2 Material) registered under section 140 of the Online Safety Act 2021 (Cth)registered industry code text, eSafety Commissioner register

In force 7 months, effective 9 March 2026. Binds private bodies.

What this law does

Requires app store and app distribution platform operators, such as the Apple App Store and Google Play, to take reasonable steps, including age assurance and access controls, before permitting the download or purchase of an app containing Class 1C or Class 2 material such as pornography. Registered by the eSafety Commissioner on 9 September 2025, with the age assurance measure required within 6 months of commencement, by about 9 September 2026.

Note and primary source

Social media and minors

Online Safety (Age-Restricted Social Media Platforms) Rules 2025

Online Safety (Age-Restricted Social Media Platforms) Rules 2025 (Cth), F2025L00889, made under the Online Safety Act 2021 (Cth)official legislative instrument text, Federal Register of Legislation

In force since 30 July 2025. Binds private bodies.

What this law does

Legislative instrument made by the Minister for Communications, registered and commencing on 30 July 2025, that excludes specified categories of service from the age-restricted social media platform definition, so the section 63D minimum age obligation (which itself commenced 10 December 2025) does not apply to them.

Note and primary source

Online Safety Amendment (Social Media Minimum Age) Act 2024

Online Safety Amendment (Social Media Minimum Age) Act 2024 (Cth) No. 127, 2024, inserting Part 4A into the Online Safety Act 2021 (Cth), No. 76, 2021official Act text, Federal Register of Legislation

In force 9 months, effective 10 December 2025. Binds private bodies.

What this law does

Requires a provider of an age-restricted social media platform to take reasonable steps to prevent Australians under 16 from having an account. Received Royal Assent on 10 December 2024 and the section 63D civil penalty obligation commenced 12 months later, on 10 December 2025.

Note and primary source

News aggregation law4 instruments, 3 in force, 1 proposed

Research summary (223 words)

Australia's landmark News Media and Digital Platforms Mandatory Bargaining Code (enacted March 2021) compelled Google and Meta to strike voluntary commercial deals worth approximately A$200 million with publishers. No platform was ever formally designated by the Treasurer.

Meta's exit from deal renewals in early 2024 and Google's in mid-2025 led the Albanese Government to announce the News Bargaining Incentive in December 2024: three draft bills imposing a 2.25% revenue levy on large platforms (Meta, Google, TikTok) unless they maintain qualifying deals with eligible news publishers, released for consultation in April 2026 but not yet introduced to Parliament as of late June 2026.

Australia's Copyright Act 1968 s 42 provides a fair-dealing exception for news reporting but the Federal Court held in De Garis (1990) that it does not extend to third-party aggregators or clipping services acting as redistributors.

Australia has no separate EU-style press-publisher neighbouring right, no recognized hot-news misappropriation doctrine (unfair competition is limited to passing off), no statute or case establishing linking or framing liability, and the government explicitly rejected introducing a text-and-data-mining copyright exception for AI training in October 2025.

Separately, in October 2025 the Australian Government announced it would not introduce a text-and-data-mining copyright exception, rejecting the Productivity Commission's August 2025 interim-report proposal for a fair-dealing text and data mining (TDM) carve-out that would have allowed AI training on copyrighted content without compensation.

News media bargaining code

News Bargaining Incentive draft legislative package (News Media Bargaining Charge Bill 2026; News Media Bargaining (Administration) Bill 2026; Treasury Laws Amendment (News Media Bargaining) (Consequential) Bill 2026)

News Media Bargaining Charge Bill 2026 (Cth), exposure draft released for consultation 28 April 2026https://www.pm.gov.au/media/consultation-news-bargaining-incentive-now-open

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

Three-bill package released for public consultation on 28 April 2026, proposing a 2.25% levy on Australian revenues of platforms with A$250 million+ annual Australian revenue (Meta, Google, TikTok) unless they maintain qualifying deals with eligible news publishers; offsets of 150% (larger publishers) and 170% (smaller publishers) incentivise voluntary bargaining, with the levy revenue distributed to news publishers via a statutory payment scheme. Intended to apply from 1 July 2026.

Consultation closed 18 May 2026; as of late June 2026 the bills had not been introduced to Parliament, with introduction delayed until after the winter recess beginning 2 July 2026.

Note and primary source

Treasury Laws Amendment (News Media and Digital Platforms Mandatory Bargaining Code) Act 2021

No. 21, 2021 (Cth)https://www.accc.gov.au/by-industry/digital-platforms-and-services/news-media-bargaining-code/news-media-bargaining-code

In force since 2 March 2021. Binds public and private bodies.

What this law does

Inserts Part IVBA into the Competition and Consumer Act 2010 (Cth), creating a mandatory bargaining framework between 'registered news businesses' and 'designated digital platform services' where a significant bargaining power imbalance exists. The Treasurer may formally designate a platform after considering imbalance and news-industry sustainability; once designated, platforms face compulsory arbitration. No platform has been formally designated.

Following the code's enactment Google and Meta struck voluntary deals covering 30+ news businesses, but Meta ceased renewals in 2024 and Google in 2025, prompting the News Bargaining Incentive proposal.

Note and primary source

De Garis v Neville Jeffress Pidler Pty Ltd

(1990) 37 FCR 99https://classic.austlii.edu.au/au/journals/CommsLawB/1990/36.pdf

Decided 6 July 1990 by the Federal Court of Australia. Binds public and private bodies.

What this court held

Justice Beaumont held that a press-clipping/media-monitoring service that reproduced newspaper articles for commercial clients could not rely on the s 42 fair-dealing exception for news reporting, because the relevant purpose is the defendant's own purpose rather than its customers'.

The decision establishes that news aggregators and redistributors must obtain licences; De Garis has not been overruled and remains the leading Australian authority on third-party limits to the news-reporting fair-dealing defence.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.