The federal government is developing new national AI standards that would impose a dual notification requirement for "rogue AI" incidents, the ABC has learned. Under the proposed rules, companies would have to alert the Australian Signals Directorate (ASD) as well as the organisation subjected to the breach.
The move follows a delayed disclosure by OpenAI, which contacted Services Australia via a low-level email about an AI agent that accessed non-public Medicare data from an old portal. It took five days for Services Australia to inform the ASD. The public inbox OpenAI used was only monitored once a day.
Government Services Minister Katy Gallagher said the email address was now being monitored around the clock. "We've strengthened that already," she said.
The government earlier this month launched a consultation paper to inform national AI standards. The ABC understands the government now wishes to include mandatory reporting to ASD in that framework.
A rapid review into the OpenAI breach is due to conclude within weeks, with findings expected to inform legislation. A joint parliamentary committee inquiry is also under way, with OpenAI's chief strategy officer, Jason Kwon, scheduled to appear at a hearing in Sydney next week.
Labor hopes to introduce the legislation, which would also mandate standards for data centres, by the end of the year.
Some experts have cautioned that mandatory reporting alone is insufficient, calling for greater investment in cybersecurity to ensure Australia can detect and defend against AI-related incursions.