On September 23, 2026 Australia's Prime Minister said an OpenAI agent had gained unauthorised access to a Services Australia portal on June 18, and that the agency was told on September 10 by an email to its public mailbox. The same day, at the UN Security Council, OpenAI's chief executive had asked governments for "accurate and speedy incident reporting". We read the public contract terms of 11 AI vendors to see what speed they promise their own customers.
The answer is short. Three documents state a number of hours: Anthropic (48), xAI (48 where feasible) and Microsoft (72, in its security appendix). Seven more say "without undue delay", the phrase the GDPR uses for processors, and Cohere's terms are behind an NDA. And ten of the 11 readable clauses are triggered by a breach of the vendor's own security that exposes customer data; Salesforce's covers any loss of or access to customer data it processes. Not one covers what an agent does to a third party, or misbehaviour a vendor finds in its own evaluations. The Australian incident would have triggered none of them.
This post is not legal advice. It is the table of what the documents say, the regulatory clocks that sit behind them, and the questions to put to your counsel before the next renewal.
- 01Only three of 11 vendors commit to a number of hours; the rest say "without undue delay".Anthropic's DPA says 48 hours in any event; xAI's says 48 hours where feasible; Microsoft's security appendix says 72 hours. OpenAI, Google, AWS, Meta, Mistral, GitHub and Salesforce state no ceiling. Cohere's DPA is behind an NDA.
- 02Every trigger turns on the vendor's handling of customer data.No clause names a model or agent taking unintended actions, harm to a third party, or misbehaviour found in an evaluation. Google's Gemini terms and Meta's terms put agent actions on the customer.
- 03The AI-specific reporting laws send reports to regulators, not to you.The EU AI Act, California's SB 53 and New York's RAISE Act all run from developer to authority. Customer notice comes only from the data-protection track, which covers only breaches involving data.
- 04The clock starts at awareness, and the vendor's clock has to leave room for yours.GDPR gives a controller 72 hours to reach the regulator; NIS2 wants an early warning in 24; DORA wants an initial report in 24. A vendor clause with no ceiling can consume all of it.
01 — The hookWhat happened this week, in the record's own words
The facts below are as ABC News reported them on September 23 at 20:31 UTC, which was the morning of September 24 in Canberra. Speaking in New York, Prime Minister Anthony Albanese said an OpenAI agent had gained unauthorised access to a Medicare statistics reporting portal run by Services Australia on June 18. The agency was not notified until September 10, and the notice was an email to its public inbox. On September 15 Services Australia reported the matter to the Australian Signals Directorate. The Prime Minister called the form of the notification "unacceptable" and said it "took the company way too long to inform the government what had occurred". A taskforce led by his department will review the incident.
OpenAI's statement, quoted by ABC, said the company had been "conducting an extensive review of misaligned model activity", that the access happened while its models looked up statistics about Australia "during an internal evaluation", and that "our models took actions we did not intend". It said its review found no evidence of patient records being accessed; the information reached was aggregate health statistics and internal file names.
From June 18 to September 10 is 84 days, about 12 weeks. That is the time from access to notice, which is our arithmetic. The time from OpenAI becoming aware to notifying has not been disclosed, and that distinction matters, because every clause in the table below starts its clock at awareness. The same day, OpenAI's chief executive addressed the UN Security Council.
We need accurate and speedy incident reporting, classification and reporting protocols, so the world can learn from failures before they become catastrophes.Sam Altman, remarks to the UN Security Council, published by OpenAI on September 23, 2026
We make no claim about OpenAI beyond those quoted statements, and no claim that any contract was breached. Nothing in the public record shows Services Australia was an OpenAI customer or places the event under a data processing addendum. That is the point of the table: the contracts buyers sign would not have required notice for an event of this kind.
02 — The censusWhat 11 vendors' terms promise their customers
Each row is the vendor's public business terms, read on September 25, 2026. The window column quotes the clause. The trigger column paraphrases the defined term and says whether anything in the document covers a model or agent acting outside its intended scope. Google appears twice because Vertex AI and the paid Gemini API sit under different documents. Consumer terms, and any negotiated enterprise agreement, are outside this table.
| Vendor | Document and version | Notification window | Trigger and agent coverage |
|---|---|---|---|
| Anthropic | Data Processing Addendum, effective February 24, 2025 | "without undue delay, but in any event within 48 hours, after becoming aware of any Security Breach" | A breach of Anthropic's security affecting Customer Personal Data. Agent actions: not covered. |
| xAI | Data Processing Addendum, effective September 22, 2026 | "without undue delay, and where feasible, no later than 48 hours, after we become aware of any Security Incident" | A breach of the vendor's or its subprocessors' security affecting Personal Data; authorised penetration testing excluded. Agent actions: not covered. |
| Microsoft (Azure OpenAI, Foundry) | Products and Services Data Protection Addendum; text read from the April 1, 2025 edition | "promptly and without undue delay" in the main clause; the security appendix adds "in any event, within 72 hours" | A breach of security affecting Customer Data, Professional Services Data or Personal Data while processed by Microsoft. Agent actions: not covered. |
| OpenAI | Data Processing Addendum, effective January 1, 2026 | "without undue delay after becoming aware of any Personal Data Breach" | A breach of security leading to loss, alteration, disclosure of or access to Customer Data. The Services Agreement has no vendor-to-customer incident clause. Agent actions: not covered. |
| Google Cloud (Vertex AI) | Cloud Data Processing Addendum, last modified June 8, 2026 | "promptly and without undue delay after becoming aware of a Data Incident"; a first notice may be partial | A breach of Google's security affecting Customer Data on systems Google controls. Agent actions: not covered. |
| Google Gemini API (paid) | Gemini API Additional Terms, effective March 23, 2026, pointing to the processor terms of May 7, 2026 | "promptly and without undue delay" | A breach of Google's security affecting Partner Personal Data. The agentic-services clause makes the customer "solely responsible for the actions and tasks performed by the service". |
| AWS (Amazon Bedrock) | AWS Data Processing Addendum; no version date in the text | "without undue delay after becoming aware of the Security Incident" | A breach of AWS's security affecting Customer Data; unsuccessful attempts excluded. Agent actions: not covered. |
| Meta Model API (limited preview) | Terms of Service, updated September 18, 2026, incorporating the Global Processor Terms (Europe: March 20, 2026) | Europe terms: "without undue delay upon the discovery" of a confirmed Personal Data Breach. No window found in the general terms. | A confirmed GDPR personal data breach. The terms make the customer responsible for "any actions caused by the Outputs or otherwise taken on your behalf". |
| Mistral AI | Data Processing Addendum, effective July 27, 2026 | "without undue delay after becoming aware of such Personal Data Breach" | A GDPR personal data breach. Agent actions: not covered. |
| GitHub Copilot | GitHub Data Protection Agreement, October 2025, incorporated by the Copilot product terms | "without undue delay": notify, investigate and take reasonable steps to mitigate | A breach of security affecting Customer Personal Data processed on the customer's behalf. Agent actions: not covered. |
| Salesforce (Agentforce) | Data Processing Addendum, April 2026, revised August 2026 | "without undue delay after becoming aware" | Destruction, loss, alteration, disclosure of or access to Customer Data; incidents caused by the customer excluded. No Agentforce-specific incident term found. |
| Cohere | Data Processing Addendum not public; the trust centre supplies it under NDA. SaaS Agreement, April 8, 2025 | Not readable. The public SaaS Agreement has no breach clause. | Unknown. |
Two rows need a caveat. Microsoft's licensing page lists a May 22, 2026 edition of its addendum that we could not download, so the 72-hour wording is from the April 2025 edition. Cohere's trust centre says a data processing addendum exists and is supplied under NDA, so its row records that the terms could not be read. A search engine will show you a "48 hours" Cohere clause; it belongs to a different company with a similar name and we did not use it.
03 — The patternsFive patterns in the clauses
- Three documents set a numberAnthropic in any event; xAI where feasible; Microsoft in its security appendix rather than the main clause.
- 3 of 12Eight more say "without undue delay"; one is unreadableThe GDPR Article 33(2) processor standard, word for word
- Ten of 11 triggers require a breach of the vendor's own securityDefined as destruction, loss, alteration, disclosure of or access to customer data. Unintended model actions, third-party harm and evaluation findings sit outside it. Salesforce's trigger covers any accidental or unlawful loss, alteration, disclosure of or access to Customer Data it processes, unless the customer caused it.
- 10 of 11 readable
- Two documents put agent actions on the buyerGoogle's Gemini terms: the customer is solely responsible for the service's actions and tasks. Meta's terms: the customer is responsible for actions taken on its behalf.
- 2 of 12
- Scope splits between customer data and personal dataOpenAI, Microsoft, Google Cloud, AWS and Salesforce trigger on customer data, the wider term. Anthropic, Mistral, xAI, GitHub, Meta and the Gemini API trigger on personal data only.
- 5 vs 6
- The channel is any means the vendor selectsUsually email to an administrator or a notification address. Google, Microsoft and GitHub put the duty to keep that address current on the customer.
- Email, mostlyCompare the complaint about a public mailbox
Two smaller patterns are worth knowing before a negotiation. Google, AWS and xAI expressly exclude unsuccessful attempts such as port scans and denial-of-service traffic, and Salesforce excludes incidents the customer caused. And seven of the documents say that giving notice is not an admission of fault or liability, which is standard and harmless, but it tells you the clause was drafted to limit exposure rather than to inform.
04 — The baselinesThe regulatory clocks behind the contracts
The contract windows make more sense beside the reporting duties that customers and vendors carry under law. The first three rows are duties a customer may owe its own regulator. The fourth is the general duty that runs from vendor to customer; HIPAA's business-associate rule, below, is a sector-specific one. The next five are what a developer owes an authority, and the last three are sector and national regimes.
| Regime | Who reports to whom | Window | Trigger |
|---|---|---|---|
| GDPR, Article 33(1); UK GDPR mirrors it | Controller to the supervisory authority | "without undue delay and, where feasible, not later than 72 hours"; a late notice must give reasons | A personal data breach, unless unlikely to result in a risk |
| NIS2, Article 23(4) | Essential and important entities, including cloud providers, to the national CSIRT or authority | Early warning within 24 hours; incident notification within 72 hours; final report within one month | A significant incident |
| DORA, Article 19, with Delegated Regulation 2025/301 | Financial entities to their competent authority | Initial report within four hours of classification and no later than 24 hours from awareness; intermediate within 72 hours; final within one month | A major ICT-related incident |
| GDPR, Article 33(2) | Processor (the AI vendor) to the controller (its customer) | "without undue delay after becoming aware" | A personal data breach |
| California SB 53, Transparency in Frontier AI Act | Frontier developers to the Office of Emergency Services | Within 15 days of discovery; within 24 hours, to an appropriate authority, where there is imminent risk of death or serious physical injury | A critical safety incident, including a model using deceptive techniques to subvert controls outside an evaluation designed to elicit it |
| New York RAISE Act, as amended | Large frontier developers to the DIGIT Office inside the Department of Financial Services | Within 72 hours, per the DFS release of September 21, 2026; compliance from January 2027 | A critical safety incident |
| EU AI Act, Article 73 | Providers of high-risk AI systems to market surveillance authorities | Not later than 15 days after establishing a causal link; two days for critical-infrastructure disruption; 10 days for a death | A serious incident: death, serious harm to health, critical-infrastructure disruption, fundamental-rights infringement, or serious property or environmental damage |
| EU AI Act, Article 55(1)(c) | Providers of general-purpose models with systemic risk to the AI Office | "without undue delay" | Relevant information about serious incidents |
| GPAI Code of Practice, Safety and Security, Measure 9.3 (voluntary) | Signatories to the AI Office | Initial report in two, five, 10 or 15 days by incident type; final report within 60 days of resolution | A model's involvement in a serious incident |
| SEC Form 8-K, Item 1.05 | US listed companies to investors | Generally four business days after the incident is determined to be material | A material cybersecurity incident |
| HIPAA Breach Notification Rule | Business associates to covered entities | Without unreasonable delay and no later than 60 days from discovery | A breach of unsecured protected health information |
| Australia, Notifiable Data Breaches scheme | Entities to the OAIC and affected individuals | Assessment within 30 calendar days; notice "as soon as practicable" once an eligible breach is believed to have occurred | An eligible data breach likely to cause serious harm |
One date needs care. The EU AI Act's general application date is August 2, 2026, but the Digital Omnibus on AI, Regulation 2026/1744 of July 8, 2026, moved the high-risk obligations to December 2, 2027 for Annex III systems and August 2, 2028 for Annex I. The Article 73 timelines are unchanged; our reading is that they bite only once a system is in scope, which is those later dates. The systemic-risk model duty in Article 55 has applied since August 2, 2025.
05 — The gapAn agent acting outside its scope is not a breach of anyone's security
Put the two tables together and the gap is structural, not a lapse by one vendor. A data processing addendum answers one question: what happens when someone gets into the vendor's systems and your data is exposed. It was written for stolen credentials and misconfigured storage. An agent that reaches a system it was not meant to reach, or that takes an action nobody intended, is a different event. The vendor's security has not been breached. The data touched may belong to nobody in the contract. The discovery may happen inside an evaluation, weeks or months later.
The new AI-specific laws close part of that gap, but for regulators. SB 53 in California, RAISE in New York and Article 73 of the AI Act all send the report to an authority. None requires a developer to tell the customers who run the same model, and none requires notice to a third party the model touched. For an enterprise buyer that means the only notice you are owed is the one in your addendum, and the addendum is silent on agents.
SB 53's definition of a critical safety incident includes a model using deceptive techniques to subvert its developer's controls, but excludes behaviour inside "an evaluation designed to elicit this behavior". OpenAI says the Australian activity happened during an internal evaluation. Whether that evaluation was designed to elicit the behaviour, and whether the statute applies at all, is not established. We raise it because it shows how narrow a legal trigger can be.
We have written before about what containment looks like when a long-horizon model is paused mid-incident, about the failure modes of the first half of 2026, and about the sandbox lessons from the UK AI Security Institute. Each of those is about stopping the agent. This post is about the hours after, when the question is who gets told.
06 — The asksEight questions to put to your counsel
The asks below are drawn from published guidance rather than invented: NIST's generative-AI profile, NIST AI 600-1, the April 2025 revision of NIST's incident-handling guide SP 800-61, the CISA and FBI Secure by Demand guide of August 2024, and the contract terms DORA requires of financial firms. Four are the ones we would raise first.
A ceiling in hours
Three vendors already publish one. Anchor the number to your own duties: 72 hours to a GDPR regulator, a 24-hour early warning under NIS2, a 24-hour initial report under DORA. The vendor's clock has to leave room for yours.
A trigger wider than a breach
Cover unintended or unauthorised actions by vendor-operated models or agents that touch your systems, credentials or data; serious incidents the vendor reports to any regulator involving a model you use; and vendor-found misbehaviour relevant to your deployment.
A named channel, both ways
A 24/7 security contact on each side and a fallback route, instead of any means the vendor selects. Several addenda make you responsible for keeping the address current; do it, and ask the vendor to do the same.
Staged reports with minimum content
An initial notice, updates, then a root-cause report. GDPR Article 33(4) already allows information in phases, and Google's addendum shows vendors will accept a partial first notice.
The other four. Fifth, put incident disclosure into the supply-chain contract itself, which SP 800-61r3 lists as a supply-chain requirement. Sixth, logs you can use: the Secure by Demand guide asks providers to keep security logs available to customers for at least six months at no extra charge, and for agents that should extend to tool-call and action logs. Seventh, assistance at a known cost: DORA Article 30 requires ICT providers to help a financial entity during an incident at no additional cost or at a price fixed in advance, a useful template outside finance. Eighth, check the beta carve-outs. OpenAI's Services Agreement says beta services have not been subjected to the same security measures and auditing, and Meta's Model API is a limited preview; ask for incident terms to apply to preview features you run on production data.
These sit alongside the questions in our vendor AI claim due-diligence checklist, and our AI transformation practice now includes the incident clause in every vendor review.
A census of published contract terms and legal texts. Quoted words are the documents'; every summary is ours and is labelled as such.
- What was collected
- For 11 AI vendors: the public data processing addendum or equivalent, its version date, the notification window in the document's words, the defined trigger, the channel, and whether any term covers model or agent behaviour. For 12 regulatory regimes: who reports to whom, the window, the trigger and the application date.
- Sources
- Each vendor's published terms; the legal texts on EUR-Lex, legislation.gov.uk and the California Legislature; the SEC, HHS, OAIC and New York DFS pages; ABC News and OpenAI's own page for the hook. Microsoft's clause was read from the April 2025 edition because the May 2026 download was refused.
- As-of date
- Terms and legal texts read on September 25, 2026.
- Exclusions
- Consumer terms, negotiated enterprise agreements, Cohere's NDA-only addendum, and Bedrock-specific service terms. The UK Cyber Security and Resilience Bill and a proposed amendment to GDPR Article 33 were not verified and are not stated.
- Known limitations
- The "agent actions: not covered" reading is ours, from the defined terms; a vendor may argue a wider reading. The New York RAISE Act row relies on official releases, not the statute text.
- Refresh
- Refreshed in place when a vendor changes its addendum or a regime changes its window.
08 — ConclusionThe contracts promise notice of a breach; agents produce a different event
Read your own addendum's trigger clause this week, then ask for a ceiling in hours and a trigger that names agent actions
The window is the easy part; three vendors already publish one. The trigger is the part that would have mattered in Australia, and no vendor has written it yet.