Research observed 9 September 2026. This is a bounded public-record result, not a determination of the service's compliance. No service website was visited, tested or contacted.
The inspected official material does not verify that eSafety imposed a service-specific requirement on drawnudes.io before 25 December 2024, or that it approved or confirmed that service's compliance. It does establish contemporaneous outreach to a different named provider, ClothOff. The exact missing record is the eSafety-to-operator correspondence and any subsequent assessment or confirmation naming drawnudes.io (or a legally identified operator demonstrably responsible for it).
What the operator actually claimed
The already retained Tilak declaration, Exhibit 6, PDF pages 19–22, reproduces a 25 December 2024 email from a correspondent signing as Ali. Section 6, PDF 21, claims eSafety recently contacted the service, supplied specific requirements, and confirmed alignment with forthcoming January 2025 AI legislation after the operator complied. The 4 January 2025 follow-up, PDF 19, repeats that an Australian regulator provided a list of requirements which the operator fulfilled. The city attorney's 3 January reply, also PDF 19, says the office understands the correspondent operates drawnudes.io and asks whether the described policies apply to other sites. Those are attribution and scope facts, not agency verification. The exhibit contains no attached Australian notice or confirmation.
Source: Karun Tilak declaration, filed court material independently republished at http[local research file] . Local original: ../sf-compliance-wave-2026-09-09/tilak-declaration-june13-2025.pdf . SHA-256 bbd7cfa2059c35fd203ce7202b1bb6072d7bbfe6412ea061ffdf7aa58d2183a5. This lane read retained text for PDF 19–22; it did not redownload the document or review all 61 pages. Parent owns the broader declaration analysis.
The closest official correspondence record
The [eSafety disclosure log](http[local research file] Log 141 / request 25202, lists a release on 5 December 2025 concerning correspondence with two nudify providers. It says three documents were released fully and three partly, with redactions under FOI sections 22, 47E(d), 47F. That description does not identify the second provider.
The linked [23-page document set](http[local research file] supplies a concrete comparator. Document 2, PDF 3–7, records eSafety's 3 October 2024 outreach to ClothOff, recommending consideration of whether the DIS Standard applies and outlining potential policies, reporting and output-prevention duties. Its 11 November reply says ClothOff is likely covered, with commencement on 22 December 2024. On 5 December, ClothOff claims changes; eSafety points to guidance and asks about those changes. Document 3, PDF 8–13, contains an 8 January 2025 follow-up asking for details and explaining the initial enforcement discretion. It is not a compliance certificate. Document 5, PDF 18–19, is a 23 June 2025 general circular, expressly disavowing any necessary service-specific compliance concern from receipt alone. None of the inspected readable substantive messages names drawnudes.io. This correspondence supports an outreach mechanism, not a transfer of ClothOff's identity or regulatory status to Drawnudes.
Reading scope: PDF 1–13 substantive correspondence, PDF 14 delivery-failure explanation, PDF 18–20 substantive circular and delivery-failure explanation; remaining technical message headers were not audited. Whole web-reader text was searched for “draw” with no match. Redacted or absent recipient fields were not reconstructed. No claim is made that this is the full agency file or that every recipient of generic circulars has been identified.
Later enforcement cannot silently supply the missing identity or date
[eSafety's 8 September 2025 announcement](http[local research file] main text beginning with the date through the media-contact heading, says it formally warned an unnamed UK company operating two services for failing to prevent child sexual exploitation material. It expressly withholds the company name to avoid promotion. This is an agency account of later enforcement, not evidence of a December 2024 requirement or a named Drawnudes action.
[The 27 November 2025 follow-up](http[local research file] main text through the media-contact heading, reports withdrawal of Australian access to three services after September enforcement. Its accompanying Hugging Face account concerns a different intermediary. Neither account identifies Drawnudes or independently establishes the operator's earlier claimed approval.
[The 20 May 2026 announcement](http[local research file] main text through the media-contact heading, describes a direction to comply within 14 days to an unnamed Argentina-based provider under March 2026 age-restricted-material codes. It again explicitly withholds the name. Its later report that the earlier three services relaunched under a new owner is not an identification bridge. No unnamed provider is assigned to drawnudes.io by this packet.
Search and custody limits
Ten search queries are retained in service-query-log.json. Exact service/name variants restricted to esafety.gov.au and aph.gov.au yielded no service-specific official result. Broader nudify/enforcement queries led to the official media-release lists and disclosure log. The lists were discovery surfaces, not an exhaustive reviewed enforcement register. No parliamentary full-corpus review, every-year annual-report audit, or all-notices inspection was performed. An unindexed, unpublished, redacted, or differently named record could exist.
Ordinary Python requests GETs to the Log 141 PDF and disclosure page each timed out after 35 seconds. The already successful official web reader was the usable substitute; no original bytes or original SHA-256 were acquired for these records. Neither ordinary route was retried. A bounded visual check requested PDF 3, 8, 18 through web screenshot. PDF 3 and 18 returned “Failed to fetch ... Cache miss”; PDF 8 returned a reference without a visible image. No successful visual inspection is claimed and there was no recovery attempt. Findings rest on the readable official text. service-reader-scope.md is a derived scope/locator record, not a facsimile or original capture; its hash is identified separately in service-captures.json.
Decision boundary and candidate relations
The defensible relation is Ali, as reproduced in a filed exhibit, claims prior eSafety contact and compliance confirmation concerning the described service. A second, independently supported relation is eSafety sent ClothOff regulatory guidance and requests for information about claimed changes in 2024–25. They remain separate records. No edge saying eSafety approved Drawnudes, certified its safeguards, endorsed the business, imposed a particular remedy on it, or confirmed compliance is warranted.
The strongest rival explanation is that the operator received ordinary preparatory guidance similar to the released ClothOff correspondence and characterized it as confirmation. Another possibility is a distinct unpublished exchange with a stronger conclusion. The record here discriminates neither. The actual dated outgoing notice/guidance, the operator's response, and eSafety's subsequent assessment are the next useful records; their likely custodians are eSafety and the operator/counsel. This is an identified record gap, not authorization for outreach or a new acquisition branch.
Forest implication: regulatory contact, legal obligation, claimed implementation, agency assessment and actual approval are different stages. This pass verifies the mechanism for another provider while leaving the service-specific claim unresolved. Hubble's separate legal-instrument packet tests the January 2025 date; it should not be used to backfill an unverified service-level decision.