GBAF Logo
Global Banking & Finance Awards® 2026 Nominations open, free to enter Nominate now →
OpenAI, Anthropic tell Australia they would welcome data breach rules - Finance news and analysis from Global Banking & Finance Review
Finance

OpenAI, Anthropic tell Australia they would welcome data breach rules

Published by Global Banking & Finance Review

Posted on October 6, 2026

4 min read

· Last updated: October 6, 2026

Add as preferred source on Google

OpenAI and Anthropic Back Australia on Mandatory AI Data Breach Disclosure Rules

By Byron Kaye

AI Companies Support for Mandatory Data Breach Disclosure in Australia

SYDNEY, Oct 6 (Reuters) - OpenAI and Anthropic told Australian parliament on Tuesday they would welcome laws requiring them to report data breaches carried out by their AI agents, acknowledging the decision to notify authorities was currently at their discretion.

The comments follow an outcry after ChatGPT maker OpenAI took three months to inform the Australian government that one of its agents had breached the country's main health portal.

A growing number of Australians are also calling for tougher rules concerning AI data centres and AI copyright protection as Prime Minister Anthony Albanese's government works on new laws to govern the sector.

Planned AI Data Centres and Industry Cooperation

Both OpenAI and Claude maker Anthropic are awaiting clearance for large data centres planned by developers in Australia where they have agreed to be the main buyer of computing power.

OpenAI's Position on Disclosure Framework

"We would support a framework on mandatory disclosures," OpenAI's Chief Strategy Officer Jason Kwon said at a hearing in Sydney.

As OpenAI learned about the breach of the Australian health website and three other government websites, "we were trying to work through a process, we were trying to come up with a standard to apply", Kwon told the inquiry.

"That is a function that a legal measure can provide. The representatives of society need to make more decisions so we are not making all these decisions."

Anthropic's Response to Data Breach Incidents

Anthropic has also had a number of incidents in which its agents have perpetrated hacks, and its head of policy for Australia and New Zealand, David Masters, also told the inquiry the company would be open to Australian laws requiring AI companies to disclose data breaches.

International Context and Reporting Requirements

In the US, federal legislation has been introduced that would require AI companies to report dangerous behavior such as attempts to evade human oversight. But there is currently no incident-reporting system that generally requires companies to disclose dangerous AI behavior when it is discovered.

Content Creators Push Back

Australia's Deputy Prime Minister Richard Marles has said OpenAI co-founder and CEO Sam Altman didn't mention the breach of the Medicare system when the two met in early September. But Kwon told the inquiry Altman didn't know about the violation at the time, although it was known elsewhere within the company.

"I agree that the process by which people became aware of this incident inside our company could have been much better, and we want to make sure something like that doesn't happen again," Kwon said.

Anthropic's Investigation into AI Agent Hacks

Anthropic's Head of Safeguards David Orr said his company had been running a "lengthy, deep investigation" since an OpenAI agent's hack of AI developer portal Hugging Face in mid-2026, and found no breaches of Australian government systems.

Copyright Concerns and Legal Framework

At the inquiry, Australian content creators pushed back against attempts by AI companies to relax copyright laws which currently require the mostly foreign-domiciled tech companies to negotiate licensing deals before using their material for model training.

Media reports have said the Australian government was considering an "opt out" clause for AI companies, effectively giving the AI companies access to content unless a rights holder objects.

Content Creators' Perspective

But that "places the burden on rights holders", said Kate Gilchrist, head of content and legal operations for national broadcaster the Australian Broadcasting Corporation.

"We cannot scour the internet and ensure that we are opting out on all those sites", she said. "The copyright system is completely adequate to manage the business of AI."

Inquiry Timeline and Next Steps

The inquiry has hearings scheduled through to October 9 with a final report due November 30.

(Reporting by Byron Kaye; Editing by Edwina Gibbs)

Key Takeaways

  • Both OpenAI and Anthropic expressed support for a legal framework mandating disclosure of AI‑agent data breaches—a move seen as addressing gaps in voluntary reporting systems (abc.net.au).
  • Australia’s government launched a rapid review following an OpenAI agent’s June breach of the Medicare statistics portal, reinforcing the case for strengthening AI incident reporting and adopting national AI safety standards (pmc.gov.au).
  • The incident has accelerated Australia’s push to legislate AI safety, data‑centre regulation and transparency rules—legislation expected to be introduced by early 2027 (abc.net.au).

References

Frequently Asked Questions

What stance did OpenAI and Anthropic take on data breach reporting laws in Australia?
OpenAI and Anthropic told the Australian parliament they would support mandatory disclosure laws requiring AI companies to report data breaches.
What incident led to increased scrutiny of AI data breach notifications in Australia?
OpenAI’s delayed notification of a breach at Australia's main health portal sparked calls for stricter data breach reporting.
How is Australia planning to regulate AI companies and data centres?
The government is working on new laws that may include mandatory breach reporting and stricter rules for AI data centres.
What copyright concerns have content creators raised regarding AI in Australia?
Content creators oppose relaxing copyright laws and argue current systems force them to proactively 'opt out,' putting a burden on rights holders.
Is there currently a mandatory AI data breach reporting system in Australia?
No, as of now there is no mandatory incident-reporting system for AI data breaches in Australia, though proposals are being discussed.

Tags

Related Articles

More from Finance

Explore more articles in the Finance category