Industry News

Government Consults on Rules Forcing AI Firms to Report 'Rogue' Security Incidents

ABC News · 18 Sept 2026
Key Takeaway Australian businesses using or partnering with AI providers should watch this consultation closely, as new incident-reporting obligations could soon affect how AI-related security breaches must be disclosed.

The federal government has opened public consultation on proposed national standards for AI and data centres, including a requirement that AI companies report serious security incidents, such as being hacked, to Australian authorities. The Department of Prime Minister and Cabinet paper does not yet define what counts as a "reportable incident", but asks for feedback on whether companies should disclose proactively, on request, or through public statements.

Other proposals include minimum safety and security requirements for companies doing large-scale AI training in Australia, rules on recycled water use for data centres, and requirements for AI firms to reserve computing capacity for local businesses and researchers. Some of these rules could apply retrospectively to data centres already under development but not yet built.

The government hopes to legislate these national AI standards by early 2027, aiming to attract major AI investment while managing safety and sustainability concerns. Consultation on the paper is open until October 9, and it arrives amid growing global debate over the pace and safety of AI development.

AI regulation data breach reporting Australia policy

Summarised by CISO AI from ABC News. We link back to every original so you can read it yourself.