The two leading AI labs say clear, enforceable data‑breach obligations for frontier models would improve safety and public trust, as Canberra considers new rules for high‑risk AI systems.
OpenAI and Anthropic have told Australian policymakers that they would welcome targeted data‑breach rules for advanced AI systems, arguing that clear, enforceable obligations would improve safety, accountability and public confidence in frontier models. The comments, made in submissions and meetings with government officials, come as Australia weighs new regulations for high‑risk AI applications, including requirements for incident reporting, risk assessments and stronger safeguards around sensitive data.
OpenAI Anthropic Support for Australia AI Data Breach Rules
Both companies have signalled that they are not opposed to regulation in principle, but are urging Canberra to design rules that are narrowly targeted, technically informed and aligned with international standards. In their view, a well‑crafted data‑breach regime for AI could:
- Require providers of frontier AI models to notify regulators and affected users when certain types of incidents occur.
- Mandate basic security controls, logging and access restrictions around training data and model weights.
- Encourage investment in safety research, red‑teaming and incident response capabilities.
OpenAI and Anthropic say they already operate internal processes along these lines, but argue that a consistent regulatory framework would level the playing field and reduce uncertainty for developers and enterprise customers.
Frontier AI Models and High‑Risk AI Systems in Australia
The Australian government has been developing proposals to regulate high‑risk AI systems, defined as applications that could cause significant harm to individuals, critical infrastructure or national security if they fail or are misused. Frontier AI models—large, general‑purpose systems with broad capabilities—are seen as a subset of high‑risk AI due to their potential use in sensitive domains such as:
- Cybersecurity and critical infrastructure, where compromised models could assist in attacks on networks or industrial systems.
- Biotechnology and life sciences, where misuse could facilitate harmful research or dual‑use experiments.
- Finance, law enforcement and public administration, where errors or bias could have wide‑reaching consequences.
Under the options being considered, providers of such systems could face obligations to:
- Conduct pre‑deployment risk assessments and document known limitations.
- Implement technical and organisational measures to reduce the risk of misuse or accidental release.
- Report certain data breaches, model leaks or security incidents to regulators and, in some cases, to affected users.
OpenAI and Anthropic have indicated that they could support a regime along these lines, provided it is proportionate, evidence‑based and coordinated with other jurisdictions.
AI Safety Regulation and Data Breach Notification Requirements
A central element of the proposed framework is data‑breach notification tailored to AI systems. Unlike traditional data‑breach laws that focus on personal information held by companies, the AI‑specific rules under discussion would also cover:
- Unauthorised access to or release of model weights, training data or system prompts.
- Incidents where models are exploited to facilitate harm, such as large‑scale phishing, fraud or cyberattacks.
- Cases where safety controls are bypassed or degraded, increasing the risk of misuse.
OpenAI and Anthropic argue that clear thresholds and reporting channels would help them prioritise resources, improve transparency and build trust with regulators and the public. They caution, however, that overly broad or vague requirements could lead to notification fatigue, where every minor incident triggers a report, diluting attention from the most serious events.
AI Industry Response to Australian Government Proposals
The AI industry’s response to Australia’s proposals has been mixed. While OpenAI and Anthropic have expressed openness to targeted rules, other actors have raised concerns about:
- The risk of regulatory fragmentation, where different countries impose conflicting requirements on the same models.
- The potential for compliance costs to disproportionately affect smaller developers and open‑source projects.
- The challenge of defining clear, objective criteria for what counts as a high‑risk AI system or a reportable incident.
Some industry groups are calling for greater reliance on existing standards and voluntary frameworks, arguing that these can evolve more quickly than legislation. Others contend that only binding legal obligations will ensure consistent behaviour across the sector, especially for companies operating across multiple jurisdictions.
What Australia’s AI Breach Rules Could Mean for Global AI Governance
Australia’s approach is being watched closely by other governments considering how to regulate frontier AI and high‑risk applications. If Canberra adopts a model that combines:
- Clear definitions of high‑risk AI systems.
- Practical data‑breach and incident reporting requirements.
- Proportionate obligations that reflect technical realities and international coordination,
it could serve as a reference point for other mid‑size economies seeking to balance innovation with safety.
For OpenAI, Anthropic and other frontier AI developers, supportive but well‑designed rules could:
- Provide a regulatory moat that favours companies with mature safety and compliance functions.
- Encourage enterprise customers to adopt AI more confidently, knowing that providers operate under clear oversight.
- Strengthen the case for international alignment on AI safety standards, reducing the burden of complying with divergent regimes.
As Australia continues to refine its proposals, the positions taken by OpenAI and Anthropic suggest that at least some leading AI labs see thoughtful data‑breach regulation not as a constraint, but as a tool to legitimise and stabilise the rapid growth of frontier AI.