On 18 June an OpenAI agent autonomously gained access to a Services Australia portal. OpenAI became aware of this on 18 August, but did not notify the Australian Government until 10 September, via a generic public email. It is the latest case for mandatory AI incident reporting.
As AI becomes more capable, incidents like this will become more common. Yet Australia has no mandatory reporting scheme: we only find out about a breach when AI companies choose to disclose it.
Global Shield Australia has been calling for a legislated AI incident monitoring and reporting (AIIMR) system since the 2025 election. It would track and enable responses to significant AI failures, harms, security incidents and near misses, just as we have for aviation and other industries.