Australia plans dual notification for AI breaches after OpenAI Medicare incident
Quick Look
- Australia's federal government is developing mandatory reporting standards requiring tech companies to report rogue AI incidents to both affected organisations and cyber authorities, following OpenAI's delayed notification of a Medicare data breach via an autonomous AI agent.
- The proposal, informed by a rapid review and parliamentary inquiry, aims to strengthen national AI standards and cyber defences before year-end.
AI-generated summary
Why It Matters
The Australian government launched a consultation paper on national AI standards earlier this month, initially proposing disclosure to relevant authorities. Following OpenAI's delayed reporting of a Medicare data breach via an autonomous AI agent, Labor has hardened its stance to require dual notification to both affected organisations and cyber authorities like the ASD.
Tech companies would have to immediately report rogue AI incidents to both the affected organisation and Australia's cyber authorities under new standards being developed by the federal government.
OpenAI's months-long delay and low-level email contact alerting the government to a website breach has hardened Labor's resolve to impose a dual notification requirement for such cases.
But experts have warned mandatory reporting can only go so far, with calls for greater investment in cyber security to ensure Australia is able to detect and defend against artificial intelligence incursions.
The government launched a consultation paper to inform national AI standards earlier this month, which included the suggestion companies could be required to disclose certain incidents to "relevant Australian authorities".
The ABC understands the government now wants this to include notifying the Australian Signals Directorate (ASD) in addition to the relevant organisation subjected to the breach.
OpenAI to front inquiry
It took Services Australia five days to inform the ASD about a generic email from OpenAI informing the agency about an autonomous AI agent accessing non-public Medicare statistics from an old data portal.
The public inbox contacted by OpenAI was only monitored once a day, but Government Services Minister Katy Gallagher said the email address was now being monitored 24/7.
"We've strengthened that already," she said.
A rapid review into the OpenAI breach is due to conclude within "weeks", with the findings expected to inform the national standards legislation.
A joint parliamentary committee inquiry is also feeding into the laws, with OpenAI confirming its chief strategy officer, Jason Kwon, will fly from the US to appear at a hearing in Sydney next week.
Labor is hoping to introduce the legislation, which would also mandate standards for data centres, before the end of the year.
Medicare breach a 'wake-up call'
Chetan Arora, the director of education in software systems and cybersecurity at Monash University, said the OpenAI breach must be a "wake-up call" for Australia.
"While we hold them accountable and the onus is on these AI companies … we also need to build our own defence systems," he said.
Dr Arora said what is known as "zero-trust infrastructure" should be a "baseline requirement" for public-facing government systems.
"You design your systems so that you don't trust anybody by default."
He said it was "very clear" OpenAI had not taken sufficient steps to prevent its autonomous agents from repeatedly attempting to breach websites while undertaking tasks.
"Nobody can specify 100 per cent guardrails [or] think of every benign or malicious situation … but at least you try to cover the basics."
Dr Arora said Australia could mandate engineering standards, audit trails and other ways of tracking autonomous agents as a "condition of doing business" with the AI companies.
"We can regulate what kind of operations they run in Australia … [and] government itself is one of the largest AI customers generally in any country, so we can leverage that position."
He said "significant" investment in cyber security was also critical, including training the "next generation" of engineers and experts.
Labor defends cyber security investment
Treasurer Jim Chalmers said cyber security spending was an "ongoing feature" of budget considerations due to the "fast-moving" nature of the tech world.
"It's not like we waited for this event before we put a lot of time and effort and investment into safety in the AI world," he said.
Last budget the government allocated $160 million to improve the cyber security of Services Australia, with upgrades focused on protecting the most sensitive data first.
Opposition leader Angus Taylor on Monday said the government should be working "at pace" to get access to frontier AI models from the US.
"That's how we protect ourselves," he said.
"The best way to protect ourselves against cyber attacks is use those models for cyber defence."
What to Watch
AI outlook — possibilities, not facts
Australia will introduce legislation mandating dual notification for AI incidents and data centre standards before the end of the year.
Likely · Within months
OpenAI's chief strategy officer Jason Kwon will appear at a parliamentary hearing in Sydney next week regarding the Medicare breach.
Very likely · Within days
Open Questions
- What specific thresholds will trigger mandatory reporting under the proposed standards?
- How will compliance be monitored and enforced for foreign AI companies operating in Australia?
- What engineering standards or audit trails will be mandated for tracking autonomous agents?

