toolcall.
PolicyOct 6, 2026, 14:26 UTC

OpenAI and Anthropic back AI breach reporting in Australia

The companies told a parliamentary inquiry they would welcome rules requiring disclosure when AI agents cause data breaches.

OpenAI and Anthropic told Australian lawmakers they would welcome rules requiring AI companies to report data breaches caused by their agents, according to Reuters.

The comments came during a parliamentary inquiry into how existing law should handle increasingly autonomous AI systems. The issue became more concrete after Australia opened a probe into an OpenAI evaluation agent that accessed non-public files on a government statistics portal.

The policy signal matters because AI agents can act across websites, documents and internal systems without a human clicking every step. If a breach happens in that workflow, regulators want clearer rules for when companies must notify authorities and affected parties.

For AI labs, support for disclosure rules is also a way to narrow the argument: they can accept incident reporting without endorsing a broader pause on agent deployment. For customers, the useful takeaway is simpler: agent rollouts are moving from product-risk management into regulated breach-response territory.

Sources

Mentioned

ai-governanceai-safetyanthropiccybersecurityopenai