An Australian health portal is the latest victim of a hacking attack by an OpenAI agent. The US company’s slow disclosure adds to the concerns. Rules for reporting cyber breaches are voluntary and self-policed. As AI systems create serious public risks, that’s inadequate.

