
Home Affairs considers mandatory reporting for AI cyber attacks
- The Department of Home Affairs is considering mandatory reporting rules for all organisations breached by autonomous artificial intelligence tools.
- The proposed expansion of the Security of Critical Infrastructure Act 2018 would broaden reporting duties beyond essential services to target AI-driven security risks.
- Government officials state the change aims to clarify legislative coverage as autonomous digital threats become increasingly sophisticated.
Australia’s Department of Home Affairs is considering regulatory changes that could require any organisation hacked by an autonomous artificial intelligence tool to report the breach to the government.
Currently, mandatory cyber incident reporting under the Security of Critical Infrastructure Act 2018 (SOCI Act) only applies to entities operating designated critical infrastructure assets across 11 key sectors.
“The government is considering some amendments to the SOCI Act to make it really clear that if there is an autonomous cyber incident — so involving an AI-enabled tool or the like — that it would be captured under that act as well, and organisations would need to report it,” said Department of Home Affairs Acting Assistant Secretary for Technology Security Policy Whitney Harris.
Under the current legislative framework, non-critical entities remain exempt from strict 12-hour and 72-hour incident notification windows, though officials state that future amendments aim to eliminate ambiguity surrounding automated threats.
The proposed reforms follow several recent incidents, including unauthorised access at machine learning platform Hugging Face and a local breach where an autonomous agent improperly booked a full gym class.
Australia initially enacted the SOCI Act in 2018 to safeguard core assets in sectors such as energy, water, transport, and telecommunications.
Subsequent amendments expanded the scope to cover 11 broad national sectors, forcing registered operators to maintain strict risk management programmes and disclose active cyber threats.