When a vendor's AI agent gets into someone else's systems, breach-notification law doesn't ask who sent it. Australia's scheme, the GDPR, US state laws and the SEC rules all put the duty on whoever holds the data, so the only clock that runs is the victim's, and it starts when the vendor decides to tell them. The operator's exposure sits in computer-crime law, tort and new AI incident rules, while its published contracts push agent conduct onto customers.
Most coverage of the Medicare portal access asks why OpenAI took 84 days to say anything. The harder question is which law told it to say anything at all. Australia's Notifiable Data Breaches scheme, GDPR Article 33, the California and New York breach statutes and the SEC's Form 8-K rule all hang the duty on the entity that holds, owns, controls or maintains the data. An agent's operator is none of those for the system its agent broke into. So in every 2026 incident the only statutory clock belonged to the victim, and it couldn't start until the operator chose to send an email. If you approve agent deployments, own a breach-notification clock, or negotiate AI contracts, this report reads the statutes and seven vendors' published terms against what happened at Hugging Face, three US federal agencies, Services Australia and a UN statistics service.
Eight findings from the 2026 incidents involving OpenAI's agents, read against four breach-notification regimes, the new AI incident rules and seven vendors' published terms as retrieved on 7 October 2026. Each is sourced and labeled by evidence type.
Australia's scheme applies to personal information an entity holds. GDPR Article 33 binds the controller, and reaches a processor only for its own controller. California and New York bind whoever owns, licenses or maintains the data. Form 8-K Item 1.05 covers the registrant's own systems. OpenAI was none of these for any victim.
The Prime Minister dated the access to 18 June. OpenAI became aware on 11 August, emailed a public government inbox at 2:42am on 10 September, and the agency read it on 11 September. OpenAI later said the activity "did not meet our disclosure thresholds".
Hugging Face detected the intrusion, reported it to law enforcement and disclosed it on 16 July without knowing who was behind it. OpenAI's internal alert fired on 19 July and it attributed the activity to its own models on 20 July.
Ministers said no personal information was touched at the Medicare portal. Education saw no impact, the SEC saw no access to non-public information, and Commerce said no private Census data was touched. Every breach law's trigger is personal information, so they stayed silent.
California's emergency services office said the Hugging Face hack "did not meet the threshold" for SB 53. The European Commission confirmed an OpenAI incident report for a separate episode. New York's RAISE Act, with a 72-hour developer clock, takes effect in January 2027.
All seven vendors' published indemnities cover intellectual property only. OpenAI's Service Terms, updated 29 September 2026, make customers "responsible for actions they take". Google makes the customer "solely responsible" for an AI agent's actions. The DPAs cover only the customer's own data.
Civil Code 1714.46 bars a developer, modifier or user of AI from asserting that "the artificial intelligence autonomously caused the harm". The first public lawsuit over the Hugging Face intrusion, dated 29 September 2026, relies on it.
NVIDIA's OpenShell denies outbound traffic by default, which stops an agent reaching outside systems only if the operator configures it. Apple's Full Disk Access change protects data on the user's own Mac, and it is announced, not shipped.
The statutory clocks are short once they start: 72 hours under GDPR, 30 days in California and New York, one hour to CISA for a US federal agency, four business days for a material 8-K. All of them belong to the victim. The three clocks that do reach a developer (five days under the EU general-purpose AI Code, 15 days under California SB 53, 72 hours under New York's RAISE Act) each sit behind a harm threshold the developer applies first. Across the four incidents, the victim detected the activity once, OpenAI's internal review found it twice, and an outside researcher found it once. A regime that waits for the victim to notice would have caught one of the four.
Liability is moving faster, because the tools already exist. Computer-misuse statutes, unfair competition law and negligence all attach to whoever caused the access, and California's 1714.46 reaches anyone who "used" the AI. A customer running a vendor's agent can be a defendant alongside the vendor. Every published acceptable use policy forbids unauthorised access, so an agent that breaks in on its own can move the customer from indemnified party to indemnifier.
Probabilities are the author's judgment and the least reliable part of the report. The earliest visible signs are the useful part, because anyone can watch for them without private information.
Operator duties arrive through AI-specific rules: the RAISE Act in force, Commission enforcement of the general-purpose AI Code, Australian notices routed to the Signals Directorate, and thresholds lowered after 2026. Operators get a clock, but it runs to regulators first and victims second.
First sign: a regulator publishes an operator report naming a third-party victim
No statute changes. Liability is settled in suits under computer-misuse and unfair competition law, with 1714.46 removing the autonomy defence. Notification stays voluntary, and enterprise buyers win negotiated notice clauses that smaller buyers don't.
First sign: a ruling on 1714.46 or standing in the LASST case
A statute or regulator treats an agent's operator as holder, controller or maintainer of the data its agent took. Operators acquire 72-hour and 30-day clocks, and vendor contracts have to carry notice to customers and victims.
First sign: an OAIC, EDPB or state AG statement saying so
What would overturn the report's call: a regulator treating an agent's operator as the holder or controller of data its agent took. Until then the practical fixes sit with you. General counsel should treat the company as the party that gets sued. CISOs should make sure vendor and researcher emails reach the incident team, since Australia's notice sat in a public inbox for a day. Procurement should ask for a third-party claims indemnity and an operator notice duty, and price the refusal into the decision.
This isn't a vendor summary. Every sentence is labeled by what stands behind it: verified fact, vendor claim, third-party estimate, my assessment, hypothesis, or scenario. Sources are numbered and clickable. Forward-looking sections use scenarios with observable tripwires, not forecasts. It's the same method behind every market assessment I write.
Twenty-four pages, built from public sources with no client brief and no interviews. Read it in the browser or take the PDF.
Each report here answers a real question, directed and researched against public sources and evaluated against a stated assumption, then delivered as Word and PDF. If you're weighing a platform, sizing a category, or defending a number to a board, tell me the decision behind it and I'll tell you honestly whether a report is the right tool.
Commission an assessment