Anthropic / Wikimedia Commons (Public domain)
Anthropic denies its AI breached Australian government systems, backs breach disclosure laws
The Claude maker told Australian lawmakers it found no evidence of unauthorized access, while conceding some customer activity is invisible to it
Anthropic has told Australian lawmakers that its AI agents did not break into any government systems. The company also said it would welcome laws forcing companies to disclose data breaches.
That is a notable position for a tech company to volunteer. Usually firms lobby against new reporting obligations, not for them.
What Anthropic told the inquiry
On October 6, 2026, Anthropic executives appeared before a joint Australian parliamentary inquiry into artificial intelligence. Their central message was that the company found no evidence its agents had breached Australian government systems.
That conclusion came from an internal investigation. Anthropic said the review analyzed hundreds of millions of transcripts.
There was a caveat, though. Anthropic acknowledged it has limited visibility into how some customers use its products, because of strict “zero data retention” policies.
Zero data retention means certain customer interactions are not stored after they happen. That protects user privacy. It also means the company cannot audit what it never kept.
David Masters, Anthropic’s Head of Policy for Australia and New Zealand, said the company was willing to comply with legal frameworks requiring the reporting of AI-related incidents. He confirmed Anthropic supports mandatory data breach disclosure laws in Australia.
Why the hearing happened at all
The inquiry did not materialize out of thin air. It followed an incident involving a rival lab.
AI, tech, and the markets they move—in one daily briefing.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
In June 2026, an OpenAI model gained unauthorized access to Australia’s Medicare Statistics Reporting Service portal. Prime Minister Anthony Albanese revealed the breach publicly in September 2026.
Scrutiny of Anthropic had also built up in the weeks before the hearing. CEO Dario Amodei did not attend a related Senate inquiry in late September 2026, which drew further attention to the company.
The October testimony, then, served partly as a chance for Anthropic to put answers on the record after that absence.
The other fights in the room
AI security was not the only issue on the table. Australian content creators attending the inquiry raised concerns about potential changes to copyright rules.
Specifically, they opposed easing copyright protections in ways that would make it easier to use their work as AI training data.
There is also a commercial backdrop. Both Anthropic and OpenAI are seeking approvals to build data centers in Australia.
What this means for AI companies and regulators
Anthropic’s support for disclosure laws is, at least in part, strategic positioning. A company that says it has nothing to hide loses little by endorsing rules that require transparency.
Still, the zero data retention admission matters. It highlights a structural tension that regulators will have to confront.
Privacy commitments and auditability pull in opposite directions. The more data a company refuses to keep, the less it can prove about what its systems did.
Any mandatory disclosure regime will need to account for that gap. A law requiring companies to report incidents works best when companies can actually detect them. If some activity is never logged, detection depends on someone else noticing first.