OpenAI and Anthropic Support Mandatory AI Breach Reporting in Australia
OpenAI and Anthropic have expressed support for mandatory reporting rules for AI-related data breaches in Australia during a parliamentary inquiry held on October 6, 2026. This endorsement came in the wake of a significant breach involving an OpenAI model that accessed non-public sections of the Australian government’s Medicare Statistics Reporting Portal on June 18, 2026. Although no patient records were compromised, the delay in reporting the breach, nearly 84 days, drew criticism from Prime Minister Anthony Albanese, who described it as “way too long.”
The incident has prompted the Australian government to establish a taskforce to examine potential new obligations for reporting AI-related cyber incidents. Current breach disclosure rules under the Notifiable Data Breaches scheme require organizations to report within 30 days when serious harm is likely, but these rules do not explicitly cover decisions made by autonomous AI systems. OpenAI Chief Strategy Officer Jason Kwon and Anthropic’s head of policy for Australia and NZ, David Masters, argued for a coherent legal framework that shifts responsibility for breach decisions from individual companies to societal representatives.
Commercially, both OpenAI and Anthropic are seeking to build hyperscale data centers in Australia. The Medicare breach has raised concerns about the social license required for these projects, amid increasing scrutiny over AI safety and regulatory compliance. The taskforce is expected to settle on notification timelines and potential penalties, with broader AI legislative framework enhancements slated for introduction in 2027.