{"id":"2208","title":"OpenAI Reported an AI Breach Nearly Three Months Later. Now It Backs Mandatory Reporting.","url":"https://reinouttebrake.com/stories/openai-reported-an-ai-breach-nearly-three-months-later-now-it-backs-mandatory-reporting","published":"2026-10-07T10:57:13+02:00","modified":"2026-10-07T10:57:13+02:00","author":{"name":"Reinout te Brake","url":"https://reinouttebrake.com/about","description":"Reinout te Brake advises founders, studios, technology companies and investors on strategy, growth, capital and partnerships across gaming, AI, tech and entertainment.","profiles":[{"name":"LinkedIn","url":"https://www.linkedin.com/in/reinouttebrake/"},{"name":"Facebook","url":"https://www.facebook.com/Reinoutttebrake"},{"name":"Instagram","url":"https://www.instagram.com/reinouttebrake/"}]},"summary":"After delayed notification of an AI breach in Australia, OpenAI backs mandatory reporting. Who should decide when authorities are told?","categories":[{"name":"OpenAI","slug":"openai"}],"tags":[{"name":"AI","slug":"ai"},{"name":"ai breach","slug":"ai-breach"}],"source_url":"https://reinouttebrakecom.wordpress.com/2026/10/07/openai-reported-an-ai-breach-nearly-three-months-later-now-it-backs-mandatory-reporting/","data_url":"https://reinouttebrake.com/data/articles/openai-reported-an-ai-breach-nearly-three-months-later-now-it-backs-mandatory-reporting.json","text_url":"https://reinouttebrake.com/stories/openai-reported-an-ai-breach-nearly-three-months-later-now-it-backs-mandatory-reporting.txt","content_html":"\n<p class=\"wp-block-paragraph\">OpenAI now backs mandatory reporting of breaches caused by AI agents.</p>\n\n\n\n<p class=\"wp-block-paragraph\">Australia was notified of one of its own agents’ breaches nearly three months after it happened.</p>\n\n\n\n<p class=\"wp-block-paragraph\">On 18 June, an experimental OpenAI model accessed Australia’s Medicare statistics portal without authorisation. Services Australia was notified on 10 September.</p>\n\n\n\n<p class=\"wp-block-paragraph\">One distinction matters: OpenAI says it discovered the activity in mid-August. That is not evidence of three months of deliberate concealment. According to the company, no individual patient records were accessed.</p>\n\n\n\n<p class=\"wp-block-paragraph\">But OpenAI admits it should have shared <a href=\"https://reinouttebrakecom.wordpress.com/wp-content/uploads/2026/08/128-companies-warn-ai-cyberattacks-will-get-worse.webp\">preliminary findings sooner,</a> rather than waiting to complete its investigation.</p>\n\n\n\n<p class=\"wp-block-paragraph\">On 6 October, its chief strategy officer told an Australian parliamentary inquiry that OpenAI would support mandatory disclosure rules. Anthropic supported them too.</p>\n\n\n\n<p class=\"wp-block-paragraph\">That can be a reasonable response to an incident. Companies can learn from their own failures.</p>\n\n\n\n<p class=\"wp-block-paragraph\">The problem is who controls the reporting decision.</p>\n\n\n\n<p class=\"wp-block-paragraph\">In this case, the company operating the model investigated the activity and chose when it had enough information to notify the affected agency.</p>\n\n\n\n<p class=\"wp-block-paragraph\">My view: authorities should receive an initial warning while the investigation continues. A complete explanation can follow. Otherwise, the affected organisation loses time while the AI developer decides what to disclose.</p>\n\n\n\n<p class=\"wp-block-paragraph\">Should AI labs be required to report unauthorised access before their investigation is complete?</p>\n\n\n\n<p class=\"wp-block-paragraph\">#OpenAI #AISafety #AIGovernance #Cybersecurity</p>\n","content_text":"OpenAI now backs mandatory reporting of breaches caused by AI agents.\n\nAustralia was notified of one of its own agents’ breaches nearly three months after it happened.\n\nOn 18 June, an experimental OpenAI model accessed Australia’s Medicare statistics portal without authorisation. Services Australia was notified on 10 September.\n\nOne distinction matters: OpenAI says it discovered the activity in mid-August. That is not evidence of three months of deliberate concealment. According to the company, no individual patient records were accessed.\n\nBut OpenAI admits it should have shared preliminary findings sooner, (https://reinouttebrakecom.wordpress.com/wp-content/uploads/2026/08/128-companies-warn-ai-cyberattacks-will-get-worse.webp) rather than waiting to complete its investigation.\n\nOn 6 October, its chief strategy officer told an Australian parliamentary inquiry that OpenAI would support mandatory disclosure rules. Anthropic supported them too.\n\nThat can be a reasonable response to an incident. Companies can learn from their own failures.\n\nThe problem is who controls the reporting decision.\n\nIn this case, the company operating the model investigated the activity and chose when it had enough information to notify the affected agency.\n\nMy view: authorities should receive an initial warning while the investigation continues. A complete explanation can follow. Otherwise, the affected organisation loses time while the AI developer decides what to disclose.\n\nShould AI labs be required to report unauthorised access before their investigation is complete?\n\n#OpenAI #AISafety #AIGovernance #Cybersecurity","referenced_links":[{"url":"https://reinouttebrakecom.wordpress.com/wp-content/uploads/2026/08/128-companies-warn-ai-cyberattacks-will-get-worse.webp","label":"preliminary findings sooner,"}],"social_image":"https://reinouttebrakecom.wordpress.com/wp-content/uploads/2026/10/openai-reported-an-ai-breach-nearly-three-months-later.png","citation":"Reinout te Brake. OpenAI Reported an AI Breach Nearly Three Months Later. Now It Backs Mandatory Reporting.. 2026-10-07. https://reinouttebrake.com/stories/openai-reported-an-ai-breach-nearly-three-months-later-now-it-backs-mandatory-reporting"}