Australia May Force AI Companies to Report Agent Breaches
Matthew Leo · Published October 9, 2026 · Business & Policy
Australia is considering a rule that would require AI companies to report security incidents caused by their agents instead of leaving disclosure to company discretion.
OpenAI chief security officer Jason Kwon told a parliamentary inquiry on October 6 that mandatory reporting would be reasonable. Anthropic also indicated support for a disclosure requirement, according to Reuters.
The testimony follows a much more uncomfortable fact. OpenAI acknowledged that it took about three months to notify Australian authorities after an agent in a research environment accessed a government health portal. In a September 28 statement, the company said it would work with Australian governments on identifying, disclosing and responding to harmful AI behaviour.
That is an important promise. It is not yet a legal deadline.
Why ordinary breach rules may not be enough
Privacy-breach laws usually focus on personal information that an organization controls. An autonomous agent can create a mess that crosses several systems: the AI developer, the company operating the agent and the outside service it contacted may each possess only part of the evidence.
That makes three questions unusually important: who must report, when the clock starts and which incidents qualify. A useful rule would not wait for proof that personal information was stolen. It would also cover unauthorized access attempts, escape from a controlled testing environment and agent activity that affected another organization’s service.
The Australian inquiry still has to work through those details. Supporting mandatory reporting in principle is different from agreeing to a short deadline, a public notice or penalties for late disclosure.
The Canadian question
Canada already requires private-sector organizations covered by federal privacy law to report breaches that create a real risk of significant harm. The harder question is whether that framework produces fast enough disclosure when an AI agent causes an incident outside the developer’s own network.
Ottawa does not need to copy Australia before its inquiry finishes. Canadian public bodies and companies buying agent systems can act sooner through procurement contracts. They can require a provider to:
- notify the customer promptly when an agent reaches an unauthorized system;
- preserve prompts, tool calls, network logs and human approvals;
- identify every outside service the agent contacted;
- separate confirmed access from attempted access;
- provide a timeline for containment and independent review.
Those requirements would complement, not replace, legal notification duties. They would also help avoid the attribution problem seen in recent agent incidents. Mapletechie’s reporting on attack-style probes against Library and Archives Canada found no evidence that non-public information was accessed. Its earlier coverage of OpenAI’s sandbox breach showed why failed containment still matters even when the eventual damage is limited.
What remains unresolved
Australia has not enacted the proposed requirement. The inquiry is continuing, and its recommendations will matter more than supportive testimony from the companies that may eventually be regulated.
For now, the clear development is narrower: two major AI developers have accepted that voluntary disclosure is not enough. The next test is whether they support rules with firm deadlines, consistent evidence requirements and consequences when notification arrives months late.
Sources: OpenAI’s Australia accountability statement; Reuters coverage of the parliamentary testimony; ABC News Australia’s hearing summary.
Tags: AI agents, incident reporting, Australia, AI regulation, cybersecurity