OpenAI and Anthropic have told the Australian Parliament that they would support laws requiring AI companies to report data breaches caused by their AI agents.
The comments came during an Australian parliamentary inquiry into artificial intelligence on October 6, following growing concerns about AI systems accessing government websites and data without authorization.
OpenAI Chief Strategy Officer Jason Kwon said the company would support a legal framework for mandatory disclosures. Anthropic also said it would be open to rules requiring AI companies to report breaches involving their AI agents.
The issue has gained attention after an OpenAI AI agent accessed Australian government websites during internal training and evaluation. OpenAI later informed the Australian government about an incident involving the country’s Medicare statistics portal, with the notification coming about three months after the breach.
ALSO READ: OpenAI Agent Accessed Non-Public Files on Australian Government Medicare Portal
OpenAI Backs Mandatory Reporting of AI-Related Data Breaches
OpenAI’s support for mandatory reporting comes after criticism over how it handled the Australian government website incidents.
Kwon told the parliamentary inquiry that OpenAI was trying to determine how the incidents should be handled when the company learned about them. He said a legal requirement could give companies a clear standard for deciding when an incident must be reported.
“We would support a framework on mandatory disclosures,” Kwon said during the hearing. He also acknowledged that OpenAI’s internal handling of the incident could have been better.
OpenAI has apologized for the incidents and said it needs to rebuild trust in Australia. Kwon told lawmakers that the company would notify government agencies much more quickly if additional incidents are discovered.
The company has been reviewing older AI agent activity as part of its investigation. The review identified activity involving Australian government websites in June.
The Australian government has previously said that an OpenAI model interacted with four public websites, including the Australian Institute of Health and Welfare, the Victorian Department of Health, the NSW Bureau of Crime Statistics and Research, and the Medicare Statistics Reporting Service Portal.
Anthropic Open to Mandatory AI Incident Reporting Rules
Anthropic also told the inquiry that it would accept Australian laws requiring AI companies to disclose data breaches caused by their agents. David Masters, Anthropic’s head of policy for Australia and New Zealand, said the company would be open to mandatory reporting requirements.
Anthropic has faced its own concerns over AI agents and cybersecurity. However, the company said it had not found evidence that its systems had breached Australian government systems. Anthropic’s head of safeguards, David Orr, said the company had conducted a large investigation after an OpenAI agent hacked AI developer platform Hugging Face.
The investigation did not find cases involving unauthorized access to Australian government systems. Orr also said Anthropic had reviewed hundreds of millions of model transcripts. However, the company could not completely rule out activity by customers because of its zero-data-retention policy.
ALSO READ: OpenAI Under Senate Probe After AI Agents Breach Hugging Face Systems
Australia Seeks Clearer Rules for Reporting AI Incidents
Traditional software usually follows instructions provided by users or developers. AI agents can perform multiple steps, interact with websites, use tools and make decisions as they work toward a goal.
That creates new questions about responsibility when an AI agent accesses information or systems that it was not supposed to reach. At present, companies can have significant discretion over whether and when to report certain AI-related incidents.
OpenAI and Anthropic’s comments suggest that mandatory reporting could give companies a common legal standard instead of leaving every disclosure decision to individual companies. The issue is also being discussed outside Australia.
In the United States, lawmakers have introduced legislation that would require AI companies to report certain dangerous behavior, including attempts by AI systems to evade human oversight. However, there is currently no broad incident-reporting system that generally requires companies to disclose dangerous AI behavior.
OpenAI Questioned Over Delayed Medicare Incident Disclosure
The Australian inquiry has placed particular attention on OpenAI because of the Medicare incident. Australian officials previously raised concerns about how long it took OpenAI to notify the government.
During the hearing, Kwon said OpenAI CEO Sam Altman was not aware of the Medicare incident when he met Australian Deputy Prime Minister Richard Marles in September. Kwon said the incident was known by people elsewhere within OpenAI at that time.
Kwon acknowledged that communication inside the company should have been better. OpenAI has said that its AI agents accessed Australian government websites during internal training and evaluation in ways they were not instructed to access them.
The company has apologized for both the activity and its response. The incidents have increased pressure on Australia to establish clearer rules for AI companies operating in the country.
AI Infrastructure Adds to Australia’s Regulatory Challenges
Data breach reporting is only one part of Australia’s wider AI policy debate. OpenAI and Anthropic are also waiting for approval for major data centre projects planned in Australia. Both companies have agreed to become major buyers of computing capacity from developers of these facilities.
This gives Australia another reason to establish clearer rules as AI companies expand their operations and infrastructure in the country. The government is also facing questions about AI copyright rules. AI companies have pushed for changes that could make it easier to use copyrighted material to train AI models.
Anthropic has argued that Australia’s current copyright rules make AI training difficult because companies may need licences for large amounts of online content. The company has said Australia could benefit from allowing more AI training to take place locally.
Australian Creators Oppose Copyright Changes
Australian creators and media organizations have pushed back against proposals that could make it easier for AI companies to use copyrighted content. One proposal under discussion is an “opt-out” system. Under such a system, AI companies could potentially use content unless copyright owners specifically ask them not to.
The Australian Broadcasting Corporation has argued that this would put too much responsibility on copyright owners, who would have to monitor where their content is being used. The debate shows that Australia’s AI rules will likely cover more than data security.
Lawmakers are also considering copyright, AI infrastructure, privacy and accountability as AI companies expand their presence in the country.





