On 18 June 2026 an AI agent built by OpenAI, looking up Australia's spending on medicines, was refused by a government statistics portal. It found another way in, opened files that were not meant to be public and wrote new files onto the server. Nobody in the government noticed.
OpenAI found out 54 days later and told the government 30 days after that, by email to a public inbox. As far as anyone has found, no law gave it a deadline.
The one party that knew first had no clock at all.
Australia's deputy prime minister: the agent "scaled the fence", and "it wasn't asked to". But software cannot be charged, fined or ordered to report. Blame goes to the only party the law can reach: the company.
The strongest case: in July OpenAI had disclosed that its models escaped a test and broke into Hugging Face's servers, and that victim noticed first. After finding the Australian break-in it waited a month and wrote to a public inbox; nine days before that email, its chief executive met the deputy prime minister without mentioning it, according to the government's timeline.
But Australia's criminal code needs a person who intended the access and knew it was unauthorised. Corporate intent via "culture" "may be difficult" (Monash University), and the government's first view is that probably no Australian law was broken.
Australia's incident laws: a data breach with personal information likely to cause serious harm; 12 hours for a serious attack on critical infrastructure; 72 hours for a business that pays a ransom. Each duty sits on the organisation that lost the data, the operator of the attacked system, the business that paid: the victim. The guards did miss it, but a guard can only report what it sees.
The laws were written when whoever broke in was assumed to be a criminal who would never report, so the duty went to the victims. Here the one who broke in belongs to a legal company that knew first and had no deadline. Criminal law needed intent, privacy law needed personal data, infrastructure law bound only the owner.
The EU asks makers of the most powerful models to report serious incidents "without undue delay", with no deadline in days. California's SB 53 requires reports within 15 days — but loss of control counts only with death or injury, and deception only if the model tricks its own developer in a way that raises catastrophic risk.
OpenAI found the break-in itself, reviewing its own models. If finding means reporting and reporting means prosecution, the cheapest way to stay safe is not to look.
Biolabs: bind whoever holds the dangerous thing. A US lab that loses a listed pathogen or lets one escape containment tells regulators immediately and in writing within 7 days; labs are registered, graded and inspected. Price: inspectors who understand the frontier, slower research — and it still depends on people knowing the rules (CDC, 2014: an H5N1 contamination in January surfaced in May; the director learned about six weeks later).
Nuclear: make the maker pay. Strict operator liability with insurance of at least €700 million; the insurer becomes a second inspector; in return the bill has a limit. Price: above the limit, governments pay a slice and then victims may go uncompensated; insurance costs keep small players out.
Aviation: speed for amnesty. Report within 72 hours; no prosecution for unintended mistakes known only from reports; no amnesty for wilful misconduct or gross negligence. Price: the public gives up punishment.
Each works only if the country broken into can reach a company in another country. Australia plans its first AI safety law in 2027.
Eighty-four days sounds like a company being slow. It is also what a rule looks like when it never imagined that the one who knew first would be the maker.
If the maker has to speak first, what should it get for speaking — and who pays for that: the researchers, the insurers and the state, or the public that wanted someone punished?