Disclosure Failures Drive Governments From Regulator to Litigant
Three distinct events this week share a single structural failure: no binding AI incident disclosure obligation exists in any major jurisdiction outside the EU. Australia's Medicare breach — confirmed at the UN General Assembly by the Prime Minister himself — arrived via a voluntary email to a generic public inbox three months after the fact. British Columbia responded to an analogous disclosure failure not through domestic regulation but by filing suit in a US federal court, naming OpenAI's CEO personally and seeking to establish an affirmative duty to notify authorities of harmful use. Both cases involve the same vendor; both centre on what was not disclosed and when.
The governance response is bifurcating along two tracks simultaneously. Legislatively, the EU's AI Act Article 73 framework and the Kids Act's extension of compliance obligations into AI systems represent the regulatory track. The litigation track — governments using civil discovery and tort liability as substitutes for absent statutory frameworks — is accelerating faster. British Columbia's choice of a California federal venue is deliberate: it imposes US jurisdiction on a US company, generates evidentiary records regardless of outcome, and creates a precedent-seeking template that other common-law jurisdictions will monitor closely. The parallel is explicit: this mirrors the trajectory of state attorney general actions against social media before federal US legislation existed.