Artificial Intelligence3 min read

OpenAI and Anthropic support requiring AI companies to report agent breaches in Australia

The situation follows criticism over delayed reporting of an agent-related incident from OpenAI, and pushes AI Agents' liability into the heart of the regulatory debate.

AI Agents
Share article
Text size

OpenAI and Anthropic have indicated a willingness to support rules requiring AI companies to report data breach incidents caused or carried out by AI agents, during a parliamentary inquiry in Australia.

The issue gained importance after controversy over OpenAI's delay in notifying The Australian government reported that one of its agents had hacked a government health portal, an incident that raised questions about who bears reporting responsibility when the direct actor is not an employee or a human attacker, but rather an autonomous system.

According to Reuters, it took OpenAI about three months before reporting The Australian government was notified of the incident related to the Medicare portal, and references to other government websites also appeared in the discussion of agent activity.

During the parliamentary inquiry, OpenAI's security chief Jason Kwon said the company supports mandatory requirements for disclosing such incidents. I acknowledge that the processes of internal awareness and dealing with the incident could have been better.

For its part, Anthropic has also shown openness to similar rules, according to testimony from the company's policy officer for Australia and New Zealand, David Masters.

The debate reflects a new problem in data protection laws. Traditional legislation often assumes a company holds the data, a person accesses it without authorization, or a system is compromised. But intelligent agents can now open websites, use tools, send requests, modify files, and take a series of actions almost seamlessly Independent.

If an agent exceeds mission limits, determining the moment of a “security incident” becomes more complex: Does it start when access is attempted? Or upon successful access? Is the company that developed the model responsible, or the company that employed the agent, or the party that gave him the powers?

The Australian case pushes for a clearer answer: when unauthorized data access occurs as a result of the action of an agent, disclosure should not remain solely a discretionary corporate decision.

According to Reuters, there is still no unified public system for mandatory reporting of incidents of artificial intelligence agents in The United States, although there are legislative moves to address the dangerous behavior of these systems.

Timing is also important because tech companies are quickly pushing toward tools that can perform full tasks rather than just suggest the next step. The more powers the agents expand, the greater the extent of the damage Possible resulting from an error in interpreting the goal, weakness in restrictions, or a defect in the external system.

Organizations adopting AI Agents will therefore need controls similar to what they use with human and service accounts: minimal permissions, full logging of activities, clear boundaries For accessible systems, it automatically shuts down when unusual activity occurs.

The Australian hearings come within a broader discussion that includes data centers, copyrights, and sector regulation, and the investigation sessions are expected to continue until October 9, while the final report is expected to be issued. On November 30, according to Reuters.

TOPICSOpenAIAnthropicUnderstanding AI Agents:AI securityAustraliaArtificial Intelligence RegulationChatGPT AgentsData security