AI companies face mandatory reporting of 'rogue' incidents under proposed Australian laws

Federal government floats new safety, environmental and industrial rules for data centres and AI development ahead of 2027 legislation

By LineZotpaper
Published
Read Time2 min
The Albanese government has proposed requiring AI companies to legally report 'rogue incidents' such as hacking of another company, as part of a broader push for national AI standards that could also force data centres to use recycled water and reserve computing capacity for Australian businesses and researchers.

The proposal comes in a new paper from the Department of Prime Minister and Cabinet on the proposed national 'AI standards', which the federal government hopes to legislate in early 2027.

The paper sets out the goal of attracting major investment from top AI companies in a 'sustainable' way. It calls for feedback on a range of measures, including mandatory disclosure of 'defined reportable AI incidents' to relevant authorities. The document does not define what constitutes a reportable incident, but seeks input on whether developers should provide information proactively, on request, or through public disclosures.

Data centres already in development but not yet built could also be retrospectively required to comply with new rules, including prioritising the use of recycled water and reserving computing capacity for Australian businesses and researchers.

Assistant Science Minister Andrew Charlton said in a statement: 'The Australian Government has been clear about the important objective of growing AI capability in Australia. We welcome investment, but on Australia's terms.'

The discussion paper is open for feedback as the government works toward legislation. Prime Minister Anthony Albanese announced in July his government would create a set of national laws and rules governing AI development and its infrastructure, including data centres. Australia currently has no such incident reporting rule.

§

Analysis

Why This Matters

  • Australian companies developing or deploying large-scale AI systems would face safety and security obligations for the first time, including reporting serious incidents to regulators.
  • The rules could affect existing data centre projects if they are not yet built, potentially slowing investment while adding environmental and equity conditions.
  • The proposals signal a shift toward government oversight of AI infrastructure, setting a precedent for other nations considering similar frameworks.

Background

The Australian government has been exploring AI regulation for several years, but this paper represents the most detailed plan so far for binding rules specifically around the infrastructure and development phase. In July 2026, Prime Minister Albanese announced the government would create a national set of laws for AI. The discussion paper released today fleshes out that commitment, targeting both the training of AI models and the data centres that power them. The timeline for legislation is early 2027, with a public consultation period now open.

Key Perspectives

Australian Government: Seeks to attract AI investment while imposing conditions it deems necessary for safety, sustainability and national benefit. The paper frames these rules as 'getting it right' and ensuring Australia's terms are met. AI Companies and Developers: Will face new compliance costs and potentially slower project timelines if data centre retrospection applies. The lack of a clear definition for 'reportable incident' creates uncertainty about reporting obligations. Critics and Privacy Advocates: May argue the rules do not go far enough in defining incidents or that mandatory reporting could be used to penalise companies for minor issues. Others might see the requirements as too burdensome for an emerging industry.

What to Watch

  • The outcome of the public consultation period: how industry and civil society respond to the undefined 'reportable incident' threshold.
  • Whether data centre investors pull back or accelerate projects before the retrospective rules take effect.
  • The final legislative text expected in early 2027, particularly how 'reportable AI incidents' are defined and what penalties apply for non-compliance.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.