Artificial Intelligence
Written by: Tathagata Sen
Updated 4:21 AM EDT, October 6, 2026

Photo caption: Unsplash.com
OpenAI and Anthropic told Australian lawmakers October 6 that they would support mandatory reporting of data breaches caused by their AI agents, Reuters reported.
The companies currently have discretion over whether to notify authorities when an AI agent causes a data breach.
The issue follows an incident in which an OpenAI agent accessed Australia’s main health portal without authorization.
OpenAI took three months to notify the Australian government, highlighting the difficulty of applying traditional data-breach reporting rules to AI systems that can act on their own.
For chief data officers (CDOs), it’s important to note that since AI agents can access data and systems while carrying out tasks, it is important to create new questions about who is responsible when an agent accesses information without authorization.
Organizations need strict AI governance in place: what data agents can access, which actions they can take and how those actions are monitored. They also need defined processes for determining when an agent’s activity constitutes a data incident and who is responsible for reporting it.
Mandatory reporting could provide a clearer framework for handling incidents involving autonomous systems. It would also reinforce the need for clear AI governance roles and accountability as organizations give agents greater access to enterprise data and systems.