Australia's government is examining whether to introduce mandatory AI incident reporting, a response to a recent agentic attack against its Medicare systems. The incident has pushed regulators to consider what obligations frontier AI companies should have when their technologies are involved in security failures or misuse.

The proposed rules would likely target the most advanced AI developers, requiring them to disclose incidents that affect critical infrastructure or public services. While the specifics remain under discussion, the move reflects growing concern that current voluntary reporting frameworks are insufficient as AI agents become more capable and more widely deployed.

If enacted, Australia would join a small but growing set of governments imposing hard reporting duties on AI firms. The focus on incident disclosure, rather than just pre-market testing, suggests a regulatory pivot toward monitoring real-world harms and holding companies accountable after deployment.