OpenAI told Australia's parliament it wants a law forcing it to disclose agent hacks. Today it still decides for itself.
At a Sydney hearing on October 6, both companies said mandatory disclosure would help them. Both also admitted that right now, telling a government is their own call.

“We would support a framework on mandatory disclosures.” That’s Jason Kwon, OpenAI’s chief strategy officer, speaking to an Australian parliamentary committee in Sydney on Tuesday, October 6. He flew in from the US to say it in person.
It’s an odd sentence from a company that spent three months not telling Canberra about the Medicare portal. But the reasoning he gave is worth reading closely.
What Kwon actually said
Reuters quotes him on how OpenAI handled the Medicare breach and three other Australian government sites: “we were trying to work through a process, we were trying to come up with a standard to apply.” A legal measure, he said, could provide that standard. “The representatives of society need to make more decisions so we are not making all these decisions.”
So the pitch is that OpenAI would like someone else to draw the line on when it has to speak up. Fair enough as far as it goes. It also concedes that until now the line was drawn inside the company.
He was blunter on the Medicare case itself. According to the Canberra Times, he told the committee “That should not have happened. We also should have handled our response better.” Information Age reports he agreed the breach might not have been found at all if OpenAI hadn’t emailed Services Australia, and that he called the response “not good enough”. The committee chair, Labor MP Jo Briskey, called the delay “utterly unacceptable”.
Anthropic’s version
Anthropic’s representatives said much the same. Policy head David Masters said the company would welcome similar laws. Special envoy Jeff Bleich said disclosure is “largely voluntary” today. Head of safeguards Dave Orr said Anthropic would tell Australian authorities “within a matter of days, or sooner” if it saw misaligned agent activity, and that a long investigation since the Hugging Face incident had found no unauthorised contact with Australian government systems.
I’d keep that last claim in its box. It’s Anthropic’s own investigation, reported by Anthropic’s own witness. ABC adds that Anthropic backed a proposal from the federal Office of AI to require reports of serious safety incidents, and that it’s finalising a deal for Australia’s AI Safety Institute to test its models independently.
Where the sources don’t line up
How many Australian sites were hit? Reuters says the Medicare portal plus three others. Information Age says at least five federal and state sites. My post on the NSW bushfire data found outlets disagreeing on the tally too. Nobody has published a list, so I’m not going to pick a number.
What’s missing
Nothing was passed on Tuesday. The Office of AI proposal is a proposal, and the committee’s hearings run through October 9, with a final report due November 30. In the US, Reuters notes, a bill has been introduced to require reporting of dangerous behavior such as dodging human oversight, but there’s no general incident reporting system yet. I wrote about the other US document, the 300-word White House accord, which leaves that to the companies.
Companies asking to be regulated is usually a reason to read the fine print twice. Here I think the ask is sincere, and also convenient. A mandatory rule gives them a defence (“we reported on the legal schedule”) that a voluntary one never would. What I’d want to see in the Australian text is a clock, in days not months, a named recipient that isn’t a generic inbox, and a penalty with teeth. Without those, the law just writes down what OpenAI already did.
For the full background, start with the Medicare portal post.
Sources
- Reuters via The Straits Times: OpenAI, Anthropic tell Australia they would welcome data breach rules
- ABC News: OpenAI executive flew to Australia to apologise over Medicare hack. Here are the key takeaways
- Information Age (ACS): OpenAI grilled over rogue agents by Australian inquiry
- The Canberra Times (AAP): AI giant says it would have revealed online hack sooner
- Quartz: OpenAI and Anthropic back mandatory AI breach disclosure laws