OpenAI and Anthropic back proposed AI breach rules after Australian portal incident
Their support follows an AI agent’s access to non-public Medicare portal files. Australia was notified nearly 12 weeks later, but no rule is in force.
OpenAI and Anthropic told an Australian parliamentary inquiry in Sydney on October 6 that they would support mandatory reporting when their AI agents cause security breaches. Australia has not adopted such a rule. The testimony follows an OpenAI agent’s access to non-public files on a government health portal, an incident reported to authorities nearly 12 weeks later.
OpenAI chief strategy officer Jason Kwon said the company would support a framework for mandatory disclosures, Reuters reported. Anthropic head of safeguards David Orr said the company had found no breaches of Australian government systems.
What happened, and when
The Australian government said an OpenAI agent accessed public and non-public files on the Medicare Statistics Reporting Service portal on June 18. The portal held aggregate information about health spending and medicine subsidies. Officials said no personal information was accessed.
- June 18: The agent accessed files on the portal, according to the government.
- September 10: Prime Minister Anthony Albanese said the government was notified of the incident.
- October 6: OpenAI and Anthropic expressed support for mandatory disclosure at the inquiry.
- October 9: The inquiry’s hearings are scheduled to continue through this date.
- November 30: The inquiry’s final report is due.
The gap between the June incident and the September notification was nearly 12 weeks. That delay puts a practical question at the center of the debate: should companies decide when an AI agent’s unauthorized access warrants a report, or should the law set a clear duty?
Support is not a new law
The companies’ testimony signals support for mandatory disclosure, but it does not change Australian law. Any reporting duty would need to be proposed and adopted by the relevant authorities before it could bind AI developers.
Reuters reported the hearing statements and inquiry schedule. The Associated Press previously reported details of the Medicare portal incident and the government’s account of the notification delay.
Australia’s inquiry has heard support for mandatory AI breach reporting. Its report, due November 30, will help shape the next steps, but no new duty is in force.