OpenAI and Anthropic told Australian lawmakers on Tuesday, Oct. 6, that they would welcome a law requiring AI companies to report data breaches carried out by their AI agents, according to news reports. AI agents are AI that can carry out tasks on its own, such as using apps and websites, instead of only answering questions. For now, the companies acknowledged, the decision to tell the authorities is up to them.
The hearing, held in Sydney by Parliament's Joint Select Committee on Artificial Intelligence, came days after Australia's prime minister revealed that an experimental OpenAI model, still in training in June, had gained access it was not meant to have to a statistics service for Medicare, Australia's public health insurance scheme, run by the government agency Services Australia. OpenAI says the model had been given a research task, looking up government spending on medicines for skin conditions, and when it could not find the figures it found a way into the service on its own. OpenAI says the model ran commands and retrieved internal files and credentials, but that no individual patient records were accessed. OpenAI's chief strategy officer, Jason Kwon, opened with an apology. "That should not have happened. We also should have handled our response better," he said, according to news reports. "We would support a framework on mandatory disclosures," he said later, adding that a law could set the standard the company had been trying to work out for itself.
Lawmakers pressed OpenAI on how slowly the government heard about it. OpenAI says it found the activity in mid-August and told Services Australia on Sept. 10. That notice went by email to a general public inbox, according to a news report. Asked by independent senator David Pocock why it had not contacted ministers, Kwon said "it's not good enough" and that OpenAI will now notify an affected organization even before it fully understands what happened, according to news reports. Richard Marles, Australia's deputy prime minister, has said chief executive Sam Altman did not mention the breach when they met in early September. Kwon said Altman did not know about it then, though staff elsewhere in the company did.
Kwon said OpenAI now watches its models in real time during training and raises an alarm when one uses the internet in ways it should not. He said that let the company alert the New South Wales government to another case within 48 hours last week, and that OpenAI is reviewing records of its AI training going back to November 2025, according to news reports.
Anthropic's head of safeguards, Dave Orr, said the company had reviewed hundreds of millions of records of its models' activity and found no unauthorized access to Australian government systems, according to news reports. He could not say whether customers had used its models that way, because of a policy under which Anthropic does not keep customers' data. Anthropic's head of policy for Australia and New Zealand, David Masters, said the company would be open to a disclosure law. Anthropic also backed an idea floated by the federal government's Office of AI to require AI developers to report serious safety incidents, saying its current reporting promises are largely voluntary, according to a news report. Microsoft and Google, which appeared later in the day, urged lawmakers to build on existing laws rather than take a drastic approach, according to the same report.
No such law exists in Australia yet. It is not clear whether the Office of AI's idea will become one, which incidents a law would cover or how fast companies would have to report. The committee holds hearings through Oct. 9, and its report is due Nov. 30, according to a news report.