Al Jazeera reported on 24 September that Prime Minister Anthony Albanese had revealed an OpenAI agent accessed public and non-public data on the government's Medicare portal in June. The revelation came less than a day after he signed the 'Call for Control of Frontier AI Models'. Albanese said he had told Sam Altman of Canberra's extreme concern and disappointment that the company took three months to admit the breach. OpenAI said it had found no evidence patient records were accessed, but that its models had touched several government websites while trying to look up answers.
ABC News reported on 29 September that the federal government wants tech companies to report rogue AI incidents immediately to both the affected organisation and the Australian Signals Directorate. The requirement would form part of new national AI standards. OpenAI's original notice was a generic email to an inbox checked once a day. A rapid review due within weeks will inform legislation Labor hopes to introduce before the end of the year.
TechRepublic reported on 25 September, citing The Information, that Google, OpenAI and Anthropic are finalising plans for a self-regulatory body tentatively called the Standards Authority for Frontier AI. The labs turned to self-regulation after a federally supervised model stalled. The proposed body is modelled on FINRA, the US financial industry's self-regulator, and would develop approaches to pre-deployment testing, incident reporting and auditor qualifications. Its standards and enforcement powers have not been announced.
Regulation
The United Nations Security Council held its 10228th meeting on 23 September, a briefing on AI and international security convened by France with Yoshua Bengio, Sam Altman, Dario Amodei and Clément Delangue as briefers. Bengio called for frontier AI to be licensed like medicine, aviation and nuclear energy, with mandatory liability insurance and a shared incident-reporting mechanism. Amodei proposed narrow agreements such as a bioweapons ban, verification systems, and a notification system for incidents significant to global security. The United States rejected any globalist scheme of control, Russia questioned the Council's mandate, and Latvia and Liberia proposed an informal Council expert or working group on AI.
The White House published a fact sheet dated 25 September on President Xi Jinping's state visit. It records that the United States and China established a US-China Super Intelligence Dialogue, with the next exchange by November 2026, and agreed a bilateral communication channel for incidents. This formalises the notification mechanism floated in pre-summit talks. The two leaders also agreed to use the term 'super intelligence' in place of 'artificial intelligence'.
Cases
Via the opinion of the United States Court of Appeals for the Ninth Circuit, filed on 16 September 2026 in Doe v GitHub, Inc. (No. 24-7700), it can be seen that the court affirmed dismissal of the programmers' Digital Millennium Copyright Act claims against GitHub, Microsoft and OpenAI over Copilot and Codex. The panel held that the plaintiffs had standing. However, it found that tools which generate new code from learned patterns do not 'remove or alter' copyright management information from a copy of an existing work, so the claim failed. It expressly left open ordinary copyright infringement claims based on substantially similar output, and the breach of contract claims remain before the district court.
Academia
arXiv hosts 'Loyal Agents: Training LLM Agents to Protect Principal Interests Under Strategic Information Asymmetry' by Zimeng Huang, Shilei Chen, Jiatong Zhao, Wenxin Xu and Tonghan Wang, submitted on 28 September 2026. The authors argue that standard alignment goals do not tell a delegated agent how to protect its principal's interests when dealing with third parties. They formalise 'agent loyalty' as preventing exploitable information leakage and resisting manipulative information uptake, a technical counterpart to the fiduciary duty of loyalty in agency law.
arXiv hosts 'Beyond Predictable Paths: Redefining AI Security Incident Reporting for Agents' by Anastasia Pustozerova, Kathrin Grosse and 23 co-authors, submitted on 21 September 2026. Drawing on 23 experts, the paper identifies what agentic incident reports must capture, including memory access, levels of autonomy, tool use and delegation chains. It notes that the EU AI Act's Article 73 serious-incident duty is triggered by harm rather than compromise, so many agent security breaches fall outside it unless harm results.
Events
The Paris Peace Forum will hold its 2026 annual Forum in Paris on 10 and 11 November 2026. The Forum convenes governments, international organisations, businesses and civil society on global governance. Its emerging-technologies initiatives include the Paris Call for Trust and Security in Cyberspace and iRAISE, a research-driven alliance on AI serving children.
The Centre for Technology, Robotics, Artificial Intelligence and the Law at NUS Law will hold its conference 'AI Governance & Liability' at the Faculty of Law, National University of Singapore, on 10 and 11 December 2026. Themes include liability and governance of agentic AI systems, AI-generated evidence and the administration of justice, comparative AI regulation, and the governance of compute. Selected papers will be considered for the Singapore Journal of Legal Studies.
Sources: Al Jazeera, ABC News, TechRepublic, United Nations, The White House, United States Court of Appeals for the Ninth Circuit, arXiv, Paris Peace Forum, NUS Law