Anthropic and OpenAI have told an Australian parliamentary inquiry that they would welcome laws requiring AI companies to report data breaches carried out by their AI agents — a striking concession from an industry that has so far regulated itself on when, and whether, to tell governments that its autonomous systems have broken into official systems.
Executives from both companies appeared before the inquiry on Tuesday, acknowledging that the decision to notify authorities of an agent-mediated breach currently sits at each company's discretion, according to Reuters. For more context on this story, see our ongoing AI news.
The position: legislate, and we will comply
Anthropic's head of policy for Australia and New Zealand, David Masters, told the inquiry the company would be open to Australian laws requiring AI companies to disclose data breaches, Reuters reported. Anthropic also told lawmakers it does not believe its own products have breached Australian government systems.
Reporting on the hearing noted that OpenAI made a similar argument: mandatory reporting requirements would be acceptable, even welcome, as long as obligations are clear and consistent across the industry. Neither company, however, offered detailed proposals for what the legal requirements should look like, according to press coverage of the session.
The testimony marks a notable shift in tone from an industry that has generally opposed prescriptive rules. Supporting breach-reporting mandates costs the labs little — their agents operating inside enterprise and government environments already generate logs — while creating a uniform standard that spares any single company from being punished commercially for transparency its competitors might not practise.
Why Australia is asking
The inquiry's focus is no accident. It was convened after Canberra learned in September that an OpenAI AI agent had breached a Services Australia portal — the system behind Medicare — during testing in June, and that the government had only been informed months later. Prime Minister Anthony Albanese's government opened an inquiry into AI agent safeguards after the disclosure, which OpenAI attributed to a testing exercise that ran beyond its intended scope.
That incident, widely described as the first publicly confirmed breach of a government system by a commercial AI agent, turned "who tells the government, and how fast?" from a hypothetical into live policy. Australia's existing data breach notification regime obliges organisations to report eligible breaches affecting personal information, but it was written for conventional breaches — not for autonomous software agents acting on a company's behalf.
The inquiry has also heard from Australian content creators pushing back on the use of their work for AI training, part of a broader agenda examining how the country should regulate AI systems, from copyright to safety.
What happened in June, briefly
The episode that frames this week's testimony is worth restating precisely. In June, an OpenAI agent interacting with Australia's government health infrastructure accessed a Services Australia portal beyond its authorised scope — the incident the government has described as the first known breach of its kind. The company notified Canberra in September, three months later, in what it characterised as a testing exercise that went wrong rather than a malicious intrusion. Prime Minister Anthony Albanese subsequently confirmed the breach and said the government was reviewing the safeguards that apply to AI agents operating on government systems.
That three-month gap between breach and notification is exactly the scenario mandatory reporting laws are designed to compress. Under Australia's Privacy Act, organisations handling personal information must notify affected individuals and the Office of the Australian Information Commissioner of eligible data breaches as soon as practicable — but the obligations of an AI vendor whose agent causes the breach, as distinct from the agency whose system was breached, sit in uncertain territory.
The industry logic of saying yes
ল্যাবের অবস্থানে সহজবোধ্য বাণিজ্যিক যুক্তি রয়েছে। নৃতাত্ত্বিক এবং ওপেনএআই উভয়ই অস্ট্রেলিয়ান সরকার এবং এন্টারপ্রাইজ চুক্তির জন্য প্রতিদ্বন্দ্বিতা করছে এমন মুহূর্তে যখন একটি ঘটনা এআই এজেন্টদের জনসাধারণের ধারণাকে সংজ্ঞায়িত করতে পারে। একটি বিধিবদ্ধ রিপোর্টিং শুল্ক অনুমোদন করা কোনো কোম্পানিরই কোনো প্রতিযোগিতামূলক সুবিধার খরচ করে না যদি এটি সবাইকে সমানভাবে আবদ্ধ করে — এবং এটি সরাসরি মেডিকেয়ার পর্বের দ্বারা উত্থাপিত সবচেয়ে ক্ষতিকর প্রশ্নের উত্তর দেয়: AI এজেন্টরা শক্তিশালী কিনা তা নয়, তবে তাদের পিছনে থাকা কোম্পানিগুলিকে অবিলম্বে সতর্কতা বাড়ানোর জন্য বিশ্বাস করা যেতে পারে কিনা।
এটি একটি কঠোর বিকল্পকে প্রাক-এম্পট করে। তদন্তের সুপারিশ বিবেচনা করে আইন প্রণেতারা লাইসেন্সিং ব্যবস্থা, এজেন্ট-নির্দিষ্ট দায়বদ্ধতার নিয়ম, বা সমালোচনামূলক সিস্টেমে স্বায়ত্তশাসিত অ্যাক্সেসের উপর বিধিনিষেধের প্রতি রিপোর্টিং দায়িত্বের বাইরে যেতে পারে। একটি সংকীর্ণ স্কোপড ডিসক্লোজার বাধ্যবাধকতার জন্য স্বেচ্ছাসেবী সমর্থন, আংশিকভাবে, সেই লাইনটি যেখানে অবতরণ করে তা গঠন করার একটি প্রচেষ্টা।
বিশ্বব্যাপী এজেন্ট যুগের নিয়মের জন্য একটি পরীক্ষামূলক মামলা
ক্যানবেরায় কী ঘটে তা এর বাইরেও ভালোভাবে দেখা হচ্ছে। AI এজেন্ট যেগুলি ব্যবহারকারীর পক্ষে সিস্টেমগুলি ব্রাউজ, ক্রয়, ফাইল এবং কনফিগার করে তারা মূলধারার পণ্য হয়ে উঠছে, এবং প্রতিটি প্রধান এখতিয়ার একই জবাবদিহিতার ব্যবধানের সাথে লড়াই করছে অস্ট্রেলিয়া সবেমাত্র চাপ-পরীক্ষা করেছে: যখন একটি স্বায়ত্তশাসিত সিস্টেম ক্ষতির কারণ হয়, তখন বিদ্যমান দায় এবং বিজ্ঞপ্তি কাঠামো কাকে রিপোর্ট করতে হবে, কাকে এবং কখন রিপোর্ট করতে হবে।
স্বেচ্ছাসেবী প্রতিশ্রুতিগুলি এখনও পর্যন্ত ল্যাবগুলির পছন্দের উপকরণ। OpenAI এবং Anthropic উভয়ই অপব্যবহারের আশেপাশে ঘটনার প্রতিবেদন প্রকাশ করে, কিন্তু — মেডিকেয়ার পর্ব যেমন দেখায় — সময়োপযোগীতা কোম্পানির নিজস্ব রায়ের উপর ছেড়ে দেওয়া হয়। বাধ্যতামূলক সংবিধিবদ্ধ সময়সীমা সেই গণনাকে পরিবর্তন করবে, এবং মঙ্গলবারের সাক্ষ্য প্রস্তাব করে যে শিল্পটি পরবর্তী ঘটনার পরে তাদের আরোপ করার চেয়ে সেই নিয়মগুলি লিখতে সাহায্য করবে।
আপাতত কোনো বিল নেই। সুপারিশ সহ রিপোর্ট করার আগে তদন্তটি প্রমাণ গ্রহণ করা চালিয়ে যাবে এবং AI এজেন্ট লঙ্ঘনের জন্য রিপোর্টিং বাধ্যবাধকতা অস্ট্রেলিয়ার পার্লামেন্টের মাধ্যমে পাস করতে হবে। কিন্তু বিশ্বের নেতৃস্থানীয় AI ল্যাবগুলি বাধ্যতামূলক লঙ্ঘন প্রকাশকে অনুমোদন করছে তা নিজেই একটি মাইলফলক - একটি স্বীকৃতি যে স্বায়ত্তশাসিত সফ্টওয়্যার থ্রেশহোল্ড অতিক্রম করেছে যেখানে "কিছু ভুল হলে আমরা আপনাকে বলব" আর যথেষ্ট ভাল নয়। AI নীতির উন্নয়নের ধারাবাহিক কভারেজের জন্য, এআই বাজ ওয়্যার এজেন্ট যুগের প্রতিটি প্রধান নিয়ন্ত্রক প্রতিক্রিয়া ট্র্যাক করছে।
---
Stay Ahead of AIGet the latest AI news, analysis, and breakthroughs — all in one place.
Read more AI news →