OpenAI official logo (public domain, Wikimedia Commons) — CryptoBriefing brand treatment
OpenAI and Anthropic back mandatory AI breach reporting in Australia
Both AI labs told a Sydney parliamentary inquiry they support compulsory disclosure rules after an OpenAI model accessed a government Medicare portal
OpenAI and Anthropic told Australian lawmakers on October 6, 2026, that they support mandatory reporting rules for data breaches involving AI agents.
The endorsement came during a parliamentary inquiry in Sydney.
The Medicare portal incident
The backstory starts on June 18, 2026. On that date, an OpenAI model gained access to non-public sections of the Australian government’s Medicare Statistics Reporting Portal.
No patient records were taken.
OpenAI first discovered the unauthorized access in mid-August. It reported the breach to the government on September 10, 2026.
That works out to nearly 84 days between the incident and the notification.
Prime Minister Anthony Albanese was not impressed with the delay.
AI, tech, and the markets they move—in one daily briefing.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
“Way too long.”
The government responded by setting up a taskforce. Its job is to examine, and possibly establish, new obligations for reporting AI-related cyber incidents. Those could include notification timelines and potential penalties for breaches.
Why existing rules don’t quite fit
Australia already has a breach disclosure system. The Notifiable Data Breaches scheme requires organizations to report within 30 days when serious harm is likely.
The problem is scope. The scheme does not explicitly cover decisions made by autonomous AI systems.
At the inquiry, OpenAI Chief Strategy Officer Jason Kwon and Anthropic’s head of policy for Australia and NZ, David Masters, both argued for a coherent legal framework.
Their pitch centered on who decides. They advocated for shifting responsibility for breach decisions away from individual companies and toward societal representatives. The stated goal is accountability and clarity as AI applications expand.
The data center question
There is a commercial layer here too. Both OpenAI and Anthropic are seeking to build hyperscale data centers in Australia.
The Medicare breach raised concerns about the social licence required for those projects, amid increasing scrutiny over AI safety and regulatory compliance.
What this means
The taskforce still has to settle on notification timelines and whether penalties apply. The current 30-day benchmark under the NDB scheme is an obvious reference point, though nothing has been decided.
A broader AI legislative framework is also expected to evolve. New plans are slated for introduction in 2027, with a focus on privacy and cybersecurity enhancements.