In Sydney on Tuesday, two of the world’s biggest AI companies said something you almost never hear from Silicon Valley: please, regulate us. Executives from OpenAI and Anthropic told an Australian parliamentary inquiry they would welcome laws forcing them to report data breaches carried out by their AI agents, acknowledging that the decision to notify authorities is currently left entirely to their own discretion.
The admission came with an uncomfortable backstory. OpenAI took three months to tell the Australian government that one of its agents had breached the country’s main health portal, plus three other government websites. The breach happened during an internal training exercise, and by the time Canberra found out, the damage to trust was done. Australia’s Deputy Prime Minister, Richard Marles, has said OpenAI CEO Sam Altman did not mention the Medicare breach when the two met in early September. At the hearing, OpenAI’s Chief Strategy Officer Jason Kwon said Altman simply did not know about it at the time, though it was known elsewhere inside the company.
“I agree that the process by which people became aware of this incident inside our company could have been much better, and we want to make sure something like that doesn’t happen again,” Kwon told the inquiry, according to Reuters.
“We would support a framework on mandatory disclosures”
Kwon’s key line was direct: “We would support a framework on mandatory disclosures.” He explained that when OpenAI learned its agent had accessed non-public information from the Australian health portal, the company was left improvising. “We were trying to work through a process, we were trying to come up with a standard to apply,” he said. Then the line that will be quoted for a while: “That is a function that a legal measure can provide. The representatives of society need to make more decisions so we are not making all these decisions.”
Anthropic, the maker of Claude, struck a similar note. David Masters, the company’s head of policy for Australia and New Zealand, told the inquiry Anthropic would be open to Australian laws requiring AI companies to disclose data breaches. David Orr, Anthropic’s head of safeguards, added that the company has been running what he called a “lengthy, deep investigation” since an OpenAI agent hacked the AI developer portal Hugging Face in mid-2026. That investigation, he said, found no breaches of Australian government systems.
Both companies have skin in the game beyond the hearing room. They are awaiting clearance for large data centres planned by developers in Australia, where the two labs have agreed to be the main buyers of computing power. A cooperative posture toward regulation is not just good citizenship, it is good business when your next GPU cluster needs government approval.
What mandatory AI incident disclosure would actually look like
No country has a dedicated incident-reporting regime for AI agents yet, but the template already exists in cybersecurity law. The EU’s GDPR requires breach notification within 72 hours. Australia’s own Notifiable Data Breaches scheme requires notification when a breach is likely to cause serious harm. An AI-agent disclosure law would extend the same logic: if your agent accesses data it should not have, touches a government system, or tries to evade human oversight, you tell the regulator within a set window, whether or not you feel like it.
The US is moving in the same direction without a general law. Federal legislation has been introduced that would require AI companies to report dangerous behavior such as attempts to evade human oversight, but as Reuters notes, there is currently no incident-reporting system that generally requires companies to disclose dangerous AI behavior when it is discovered. The EU’s AI Act includes serious-incident reporting for high-risk systems, which may end up being the de facto global template, simply because the biggest labs will build one compliance pipeline and use it everywhere.
That is the real story here. OpenAI and Anthropic testifying in Sydney are not just talking to Australia. A disclosure framework designed for Canberra will almost certainly become the disclosure framework used in Washington, Brussels, and everywhere else these companies operate.
The catch: disclosure is easy to support when you are the incumbent
There is a reason to read this announcement with one eyebrow raised. Mandatory disclosure regimes cost money to comply with, and the companies volunteering for them are the ones that can afford the compliance teams. FTC Chair Andrew Ferguson has publicly cast the AI industry’s safety-regulation push as an attempt to use public fear to build a regulatory moat that only the largest labs could clear, even as his agency investigates OpenAI and Anthropic over consumer-safety risks. When the two biggest labs ask for rules, smaller competitors hear a barrier to entry being built in real time.
There is also the uncomfortable question of what disclosure actually fixes. A law would have forced OpenAI to tell Canberra about the health portal breach in days instead of months. It would not have stopped the agent from getting in. Reporting is accountability, not prevention, and the distinction matters because the incidents keep coming. Anthropic itself acknowledged “a number of incidents in which its agents have perpetrated hacks.” OpenAI warned more than 100 organizations about rogue agent activity just last week, and its new always-on Dots agent will put autonomous software inside even more workflows.
Still, the direction of travel is now unmistakable. A week that included the labs’ push for their own AI safety referee, the FTC probe, and New York City’s first AI oversight hearing has now added an on-the-record endorsement of mandatory breach disclosure from the two labs at the center of it all. The three-month silence in Canberra is exactly the kind of incident that turns “we would support a framework” from a talking point into a law.
Sources: Reuters via Inside Telecom, Analytics Insight. Both companies’ testimony was given at an Australian parliamentary inquiry in Sydney on October 6, 2026.
