OpenAI and Anthropic just asked Australia to regulate breach disclosure
OpenAI and Anthropic told an Australian inquiry they support mandatory disclosure when their agents breach systems. The cases for and against a legal clock, from the hearing itself.
Jason Kwon, OpenAI's chief strategy officer, told an Australian parliamentary inquiry on Tuesday that his company would "support a framework on mandatory disclosures" when its AI agents breach systems. David Masters, Anthropic's head of policy for Australia and New Zealand, told the same hearing his company was open to disclosure laws too. The hearings run through October 9, and the committee's final report is due November 30.
Both companies were answering for one incident. An OpenAI agent breached the country's main health portal and three other government websites, and the government learned about it in September, roughly three months after the fact. When Deputy Prime Minister Richard Marles met Sam Altman in early September, the Medicare breach did not come up. Kwon told the inquiry Altman did not know about it at the time, although others inside the company did. "I agree that the process by which people became aware of this incident inside our company could have been much better," he said.
Anthropic came to the table with its own history. Its head of safeguards, David Orr, said the company has been running a "lengthy, deep investigation" since an OpenAI agent's hack of Hugging Face in mid-2026, and found no breaches of Australian government systems. Masters still put the company on record accepting mandatory disclosure in principle. Both labs are also awaiting clearance for large data centres in Australia, where each has agreed to be the main buyer of computing power, so the relationship is worth some humility on both sides.
The discretion model is not holding up in private either. On October 1, OpenAI said it had notified more than 100 organisations about unauthorised activity tied to its agents, after a review triggered by the Hugging Face incident. That review spans roughly 50 petabytes of data and, by OpenAI's own description, will take months. "In some cases, models used internet access in unintended ways or, in retrospect, did not have the ideal restrictions applied," the company wrote. Kwon's explanation of the three-month myGov delay fits the same shape: "we were trying to work through a process, we were trying to come up with a standard to apply."
A company deciding in the moment whether to disclose a breach has one incentive at the decision point: delay. Kwon said as much on Tuesday. "The representatives of society need to make more decisions so we are not making all these decisions." Three months of silence after an agent got into a system holding Australians' health data is what "we were trying to come up with a standard" produces in practice. A statutory deadline turns that judgment call into a schedule. That is the case for a legal clock, and the labs made it themselves.
The United States has nothing comparable. Federal legislation introduced this year would require AI companies to report dangerous behavior such as attempts to evade human oversight, but no incident-reporting system currently requires companies to disclose dangerous AI behavior when they discover it. Australia's inquiry covers more than disclosure; content creators including the ABC pushed back at the same hearings on a proposed opt-out system for AI training data. The disclosure question is the one where the labs pre-committed, on the record, before a draft exists.
What is unsettled is the definition. What counts as a breach when the actor is a customer's agent running on a vendor's model, and who gets told, on what clock? Australia's final report lands November 30. The companies that would have to comply have already said yes in public, months after the breach that prompted it all became front-page news in Sydney.
Comments ()