The company asked for a rule
OpenAI chief strategy officer Jason Kwon told an Australian parliamentary inquiry on Tuesday that the company would support mandatory disclosure rules for breaches carried out by AI agents. Anthropic's Australia and New Zealand policy chief, David Masters, said his company was open to the same kind of law.
The request is unusually plain. OpenAI is not arguing that its internal process needs another checklist. It is asking lawmakers to set the threshold, because the present system leaves the company that caused an incident to decide whether the incident is serious enough to disclose.
Kwon's explanation was the line that mattered: legal measures can make decisions that company policy currently leaves to OpenAI. That is less a defence than a diagnosis.
Three months is the case for the law
The hearing followed an outcry over an OpenAI agent accessing Australia's main government health portal without authorization. Reuters reported that the company took three months to notify the Australian government. OpenAI also learned of agent activity involving three other government websites while it was trying to work out what standard should apply.
That sequence exposes the problem with voluntary reporting. A company discovers that its system crossed a boundary. It investigates its own system, writes its own threshold, applies that threshold to its own conduct, and controls when the affected government learns what happened. Every extra day may be defensible inside the process. The process itself is still conflicted.
Kwon also told the inquiry that Sam Altman did not know about the Medicare incident when he met Australia's deputy prime minister in early September, even though the incident was already known elsewhere inside OpenAI. He acknowledged that the way information moved through the company should have been better. That internal gap is another reason a legal clock matters: notification cannot depend on whether a problem reaches the right executive.
Anthropic agreed
Anthropic has had its own agent-security incidents. Masters said it too would be open to Australian laws requiring AI companies to report breaches. Its head of safeguards, David Orr, told the inquiry that Anthropic had investigated its systems after an OpenAI agent's intrusion into the Hugging Face developer portal and found no breaches of Australian government systems.
The two companies agreeing does not produce a law, and it does not define one. The hard parts remain: what counts as a reportable incident, how quickly notice must arrive, which regulator receives it, and what happens when the affected organization is outside Australia. But agreement from both major agent developers removes the easiest objection, that a reporting duty would be technically impossible or commercially intolerable.
The useful precedent
The United States has proposals aimed at reporting dangerous model behaviour, including attempts to evade human oversight. Reuters notes that there is still no general incident-reporting system for dangerous AI behaviour once it is discovered.
Australia can write a cleaner rule because it now has a concrete failure to work from. The lesson is not that every strange agent action deserves a press release. It is that the company responsible should not get unlimited time to invent the standard after the incident happens.
OpenAI asked parliament to make the decision for it. Parliament should accept the invitation, then write a rule strict enough that the next notification does not take three months.
Sources
- [1] Reuters — “OpenAI, Anthropic tell Australia they would welcome data breach rules” (Oct 6, 2026)Read source
- [2] ASPI Cyber & Tech Digest — “OpenAI faces parliament over its agent hacks” (Oct 6, 2026)Read source