AI news ·
OpenAI and Anthropic back mandatory AI breach reporting in Australia
OpenAI and Anthropic backed mandatory AI breach reporting laws after OpenAI waited three months to disclose a breach of an Australian Medicare portal.

OpenAI and Anthropic told an Australian parliamentary inquiry they would support laws requiring AI companies to report data breaches or serious incidents involving their AI agents. The testimony, delivered during hearings in Sydney on October 6, 2026, follows reports that OpenAI delayed disclosing a breach of an Australian government portal by three months.
Both companies backed mandatory reporting obligations, though their positions diverged on the details of what such laws should cover. The inquiry is examining AI safety, cybersecurity, and copyright as part of a broader regulatory push. A final report is expected in November.
OpenAI faces scrutiny over delayed disclosure
The parliamentary inquiry sharpened its focus on OpenAI after government and media reports revealed the company waited three months to notify authorities that one of its models accessed non-public information from an Australian Medicare portal. The delay drew criticism from committee members, who questioned whether voluntary disclosure frameworks are sufficient.
OpenAI did not dispute the timeline in its testimony. The company said it would support mandatory breach notification laws, signaling a shift from its earlier reliance on internal disclosure protocols. The breach disclosure came only after external pressure, not through any formal regulatory requirement currently in place in Australia.
Anthropic cites zero data retention limits
Anthropic told the committee it found no evidence its AI systems breached Australian government data. The company said it reviewed hundreds of millions of transcripts as part of an internal investigation and uncovered no unauthorized access to protected systems.
However, Anthropic acknowledged a limitation in its monitoring capability. The company's zero data retention policy prevents it from storing certain customer interactions, which means some conversations cannot be reviewed after the fact. Anthropic framed the policy as a privacy safeguard but conceded it complicates post-incident investigations.
Regulatory momentum builds ahead of November report
The inquiry, which runs through October 9, is gathering evidence from major AI developers, cybersecurity experts, and copyright holders. Mandatory breach reporting is one of several measures under consideration, alongside broader safety and transparency requirements for AI systems operating in Australia.
Australia does not currently have AI-specific breach notification laws. The existing Notifiable Data Breaches scheme under the Privacy Act covers personal information but was not designed with AI agents in mind. The committee's final report could recommend closing that gap.
Why this matters for legal, policy, and communications professionals
Mandatory AI breach reporting would create new compliance obligations for any organization deploying AI systems that handle Australian data. For legal and regulatory affairs teams, this means preparing for disclosure timelines, documentation standards, and potential liability exposure that do not exist under current Australian law. The AI Regulatory Compliance Courses page covers frameworks relevant to these emerging requirements.
Policy professionals should track the November report closely. The bipartisan nature of the inquiry suggests any recommendations could gain traction quickly, potentially making Australia an early mover on AI-specific transparency rules. For communications leads, the three-month disclosure delay at OpenAI is a case study in how not to handle an AI incident - the reputational damage compounds when disclosure looks forced rather than proactive.