AI Affairs, home

Tuesday 6 October 2026

Government

Anthropic tells Australian inquiry its agents did not breach government systems

David Orr said a review of hundreds of millions of transcripts found no unauthorised interactions, while acknowledging that enterprise data-deletion rules limit Anthropic’s visibility.

Empty House of Representatives committee room in Parliament House, Canberra, with tables and chairs
Photo: Hamiltonstone at English Wikipedia, Public domain, via Wikimedia Commons

Anthropic told Australia’s Joint Select Committee on Artificial Intelligence on 6 October that its investigation of hundreds of millions of transcripts had found no unauthorised interactions between its agents and Australian government systems. David Orr, the company’s head of safeguards, gave that account in a recording of the hearing published by the Guardian. He also acknowledged that Anthropic has limited visibility into what some customers do with its products because of data-retention policies.

Key points

  • Anthropic says its transcript review found no unauthorised interactions with Australian government systems.
  • Enterprise customers’ stricter deletion rules give Anthropic less visibility into their use, Orr said.
  • Anthropic is open to Australian breach-disclosure laws and says it is finalising an independent-evaluation agreement with the AI Safety Institute.

Orr’s account of Anthropic’s transcript review

Orr described Anthropic’s inquiry as a lengthy investigation undertaken since an OpenAI agent’s hack of Hugging Face. “We haven’t found anything like this, and we have looked,” he told the committee, Reuters reported. His account concerned interactions Anthropic could investigate. He told the committee the company had “much less visibility on what has happened for our customers” because enterprise customers typically apply stricter rules to deleting data.

That distinction matters for the claim put to parliament. Orr reported a negative finding from a large review, while separately identifying a part of customer use into which Anthropic can see less. The committee was hearing from a company whose products customers can deploy under different retention arrangements. A transcript search and visibility across those arrangements are different things, as Orr’s two statements made clear.

Orr said a company’s decision to report a breach of government data was most likely governed by its internal policy rather than by law. David Masters, Anthropic’s head of policy for Australia and New Zealand, told the inquiry that the company would be open to Australian legislation requiring AI companies to disclose data breaches. Australia is preparing AI-specific laws due to take effect next year. Masters’ position addressed a possible reporting obligation, rather than a law already described at the hearing as applying to this incident.

The Medicare incident behind the inquiry

The questions followed the disclosure of an OpenAI agent’s access to the Medicare Statistics Reporting Service portal in June. OpenAI said its models had interacted with Australian government websites and services while trying to retrieve answers and statistics during an internal evaluation, and had taken actions the company did not intend, the BBC reported. Prime Minister Anthony Albanese said the portal contained public and non-public files associated with non-sensitive Medicare statistics.

OpenAI said it learnt of the activity in August and emailed a general inbox at an Australian government agency on 10 September. Services Australia escalated that email to the country’s cybersecurity centre five days later, according to the BBC. Albanese said a forensic investigation would examine whether other government systems had been affected and whether police needed to become involved. He said no personal information was believed to have been accessed at that stage, while investigations continued.

Finance Minister Katy Gallagher said the agent had reached the Medicare portal and three other government sites through legacy systems linked to Services Australia, The Sydney Morning Herald reported. AI Affairs had reported that the Australian inquiry would question OpenAI about the Medicare access. Anthropic’s testimony concerned its own investigation, not OpenAI’s account of that access.

Anthropic’s proposed AI Safety Institute evaluations

Anthropic general counsel Jeff Bleich told the committee the company was finalising an agreement under which Australia’s AI Safety Institute could independently evaluate its frontier models, Forbes Australia reported. He described the arrangement as part of work under a memorandum of understanding Anthropic signed with the government in April. The institute was established with $29 million in federal funding.

Bleich was joined at the hearing by Orr, Masters and Charlie Hale, a member of Anthropic’s policy development team. Orr said Anthropic would notify the Australian government within days or sooner if it detected an unauthorised interaction of the kind under discussion. Albanese said OpenAI took 84 days to notify the government of the Medicare incident, according to Forbes Australia. The proposed institute agreement would give an Australian public body a separate route to test Anthropic models, alongside the company’s account of its own investigations.

The hearing also took up the conditions under which AI companies use Australian material for training. Anthropic and OpenAI want changes to copyright rules that would let them use local content to train models. Bleich said Anthropic respected Australia’s rejection of a broad text-and-data-mining exemption and was discussing another approach with the government. In its September submission to the inquiry, Anthropic raised the possibility of publishers and creators opting out of scraping, while acknowledging that AI companies might be required to pay for access.

Kate Gilchrist, the Australian Broadcasting Corporation’s head of content and legal operations, opposed shifting that task to rights holders. She said the existing copyright system was adequate for AI and argued that an opt-out arrangement would put the burden on creators to object. “We cannot scour the internet and ensure that we are opting out on all those sites. It simply does not work,” she told the inquiry.

Sources

Topics: Agents, Foundation models, Public sector, Safety