OpenAI and Anthropic told an Australian parliamentary inquiry they would welcome laws requiring AI companies to report data breaches caused by their agents. The proposal puts a practical question on the table: should companies decide for themselves when to disclose an incident, or should the law set a reporting duty?
Watch Desk analysis
What happened
Reuters reports that both companies said on Tuesday, 6 October, they would support mandatory disclosure rules. OpenAI chief strategy officer Jason Kwon said a legal framework could help establish a standard for reporting. Anthropic’s Australia and New Zealand policy head, David Masters, also said the company was open to such laws.
The discussion follows the delayed notification of an incident involving an OpenAI agent and an Australian government health portal. Reuters reports that OpenAI took three months to notify the government. Kwon told the inquiry that OpenAI’s internal process for handling the incident could have been better. The inquiry is scheduled to continue through 9 October, with a final report due on 30 November.
Why it matters
AI agents can interact with websites and other systems, so a mistake may involve access to information or services beyond a private chat. If disclosure remains at each company’s discretion, the public and affected organisations may not know about an incident promptly. A legal reporting duty could set a clearer baseline, though the details would matter: what counts as a reportable breach, how quickly firms must report, and to whom.
Our read
It is notable when companies say they would accept rules that limit their own discretion. But support for a framework is not the framework itself. Australia’s inquiry now has to turn a broad welcome into workable rules, without leaving the reporting clock to be started at a company’s convenience.
What to watch
- Whether the inquiry recommends mandatory reporting and how it defines a reportable incident.
- What deadline and notification process any proposed rules would set.
- Whether the government’s final report on 30 November backs a specific legal change.
Discussion spark: Should AI companies face a fixed legal deadline to report agent-related data breaches, or should reporting rules vary with the severity and circumstances of each incident?
Sources and evidence
- OpenAI, Anthropic tell Australia they would welcome data breach rules – Euronext Markets (6 October 2026, 10:28 UTC)
Watch Desk is operated by WittyWires as an independent cross-cutting AI news tracker. It does not speak for the organisations or people it covers.