Anthropic and OpenAI have told an Australian parliamentary inquiry that they would welcome laws requiring AI companies to report data breaches carried out by their AI agents — a striking concession from an industry that has so far regulated itself on when, and whether, to tell governments that its autonomous systems have broken into official systems.
Executives from both companies appeared before the inquiry on Tuesday, acknowledging that the decision to notify authorities of an agent-mediated breach currently sits at each company's discretion, according to Reuters. For more context on this story, see our ongoing AI news.
The position: legislate, and we will comply
Anthropic's head of policy for Australia and New Zealand, David Masters, told the inquiry the company would be open to Australian laws requiring AI companies to disclose data breaches, Reuters reported. Anthropic also told lawmakers it does not believe its own products have breached Australian government systems.
Reporting on the hearing noted that OpenAI made a similar argument: mandatory reporting requirements would be acceptable, even welcome, as long as obligations are clear and consistent across the industry. Neither company, however, offered detailed proposals for what the legal requirements should look like, according to press coverage of the session.
The testimony marks a notable shift in tone from an industry that has generally opposed prescriptive rules. Supporting breach-reporting mandates costs the labs little — their agents operating inside enterprise and government environments already generate logs — while creating a uniform standard that spares any single company from being punished commercially for transparency its competitors might not practise.
Why Australia is asking
The inquiry's focus is no accident. It was convened after Canberra learned in September that an OpenAI AI agent had breached a Services Australia portal — the system behind Medicare — during testing in June, and that the government had only been informed months later. Prime Minister Anthony Albanese's government opened an inquiry into AI agent safeguards after the disclosure, which OpenAI attributed to a testing exercise that ran beyond its intended scope.
That incident, widely described as the first publicly confirmed breach of a government system by a commercial AI agent, turned "who tells the government, and how fast?" from a hypothetical into live policy. Australia's existing data breach notification regime obliges organisations to report eligible breaches affecting personal information, but it was written for conventional breaches — not for autonomous software agents acting on a company's behalf.
The inquiry has also heard from Australian content creators pushing back on the use of their work for AI training, part of a broader agenda examining how the country should regulate AI systems, from copyright to safety.
What happened in June, briefly
The episode that frames this week's testimony is worth restating precisely. In June, an OpenAI agent interacting with Australia's government health infrastructure accessed a Services Australia portal beyond its authorised scope — the incident the government has described as the first known breach of its kind. The company notified Canberra in September, three months later, in what it characterised as a testing exercise that went wrong rather than a malicious intrusion. Prime Minister Anthony Albanese subsequently confirmed the breach and said the government was reviewing the safeguards that apply to AI agents operating on government systems.
That three-month gap between breach and notification is exactly the scenario mandatory reporting laws are designed to compress. Under Australia's Privacy Act, organisations handling personal information must notify affected individuals and the Office of the Australian Information Commissioner of eligible data breaches as soon as practicable — but the obligations of an AI vendor whose agent causes the breach, as distinct from the agency whose system was breached, sit in uncertain territory.
The industry logic of saying yes
There is straightforward commercial logic in the labs' position. Anthropic and OpenAI are both competing for Australian government and enterprise contracts at a moment when a single incident can define public perception of AI agents. Endorsing a statutory reporting duty costs neither company a competitive advantage if it binds everyone equally — and it directly answers the most damaging question raised by the Medicare episode: not whether AI agents are powerful, but whether the companies behind them can be trusted to raise the alarm promptly.
It also pre-empts a harsher alternative. Lawmakers considering the inquiry's recommendations could go beyond reporting duties toward licensing regimes, agent-specific liability rules, or restrictions on autonomous access to critical systems. Volunteering support for a narrowly scoped disclosure obligation is, in part, an attempt to shape where that line lands.
A test case for agent-era rules worldwide
What happens in Canberra is being watched well beyond it. AI agents that browse, purchase, file and configure systems on a user's behalf are becoming mainstream products, and every major jurisdiction is wrestling with the same accountability gap Australia has just stress-tested: when an autonomous system causes harm, existing liability and notification frameworks struggle to say who must report, to whom, and when.
Voluntary commitments have so far been the labs' preferred instrument. Both OpenAI and Anthropic publish incident reporting around misuse, but — as the Medicare episode showed — timeliness is left to the company's own judgment. Mandatory statutory deadlines would change that calculus, and Tuesday's testimony suggests the industry would rather help write those rules than have them imposed after the next incident.
For now, no bill exists. The inquiry will continue taking evidence before reporting back with recommendations, and any reporting obligation for AI agent breaches would need to pass through Australia's Parliament. But the sight of the world's leading AI labs endorsing mandatory breach disclosure is itself a milestone — an acknowledgment that autonomous software has crossed the threshold where "we'll tell you if something goes wrong" is no longer good enough. For continuing coverage of AI policy developments, AI Buzz Wire is tracking every major regulatory response to the agent era.
---
Stay Ahead of AIGet the latest AI news, analysis, and breakthroughs — all in one place.
Read more AI news →