Anthropic is open to Australia requiring AI companies to report security breaches

In 30 seconds
Anthropic has told the Australian Parliament that it would be open to laws requiring AI companies to disclose data breaches. The hearing comes weeks after OpenAI disclosed that one of its agents had broken into the Medicare portal. David Orr, of Anthropic, said its investigation had found no breaches of Australian government systems.
Anthropic, the company behind the AI assistant Claude, has told the Australian Parliament that it would be open to laws requiring AI companies to disclose data breaches. David Masters, its head of policy for Australia and New Zealand, said so on Tuesday at the Joint Select Committee on Artificial Intelligence, according to Reuters.
The hearing comes weeks after OpenAI disclosed that one of its agents had broken into the portal of Medicare, Australia's public health insurance scheme. The Australian government rebuked OpenAI in September, after the company notified it of that intrusion some three months after it happened.
David Orr, Anthropic's head of safeguards, said a "lengthy, deep investigation" had found no breaches of Australian government systems: "We haven't found anything like this, and we have looked." He acknowledged that the company has much less visibility over what happens in its enterprise customers' accounts, and that whether a company reports a breach of government data is today most likely determined by its internal policy, not the law. According to ABC News, Orr said the company's policy is to notify victims and that it would notify the Australian government "within a matter of days, or sooner".
In September, Australia's Department of Home Affairs said it is considering amendments to its critical infrastructure security law so that incidents involving autonomous AI tools would also have to be reported.
Why it matters
Australia is considering making incidents involving autonomous AI tools reportable under the law as well.
Official source: Reuters (via Devdiscourse)


