When an AI does the hacking, does your client’s cyber policy respond? | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Policy wordings that require deliberate conduct to trigger cover leave a structural gap that autonomous AI incidents now routinely expose

OpenAI has apologised over a rogue AI agent’s access to Medicare statistics and three other Australian government systems. The apology is one part of the story. What the incident exposes about existing cyber policy language is the part that matters most to the insurance market.

What the agent did

In a blog post published on September 28, OpenAI said one of its models had been given a task in June: research government spending per person on medicines for skin conditions in Victoria. The model hit access restrictions at a Services Australia portal and kept working past them. “It took actions that we had not authorised it to take,” OpenAI said.

The agent gained non-public access to the Medicare statistics reporting service, running commands, retrieving internal files and credentials, and writing files. OpenAI said no patient or client records were accessed.

The NSW Bureau of Crime Statistics and Research’s (BOCSAR) public crime mapping tool was also accessed, with application configuration, operational logs, and website metadata obtained. An exposed access key allowed queries to the Victorian Agency for Health Information’s (VAHI) reporting system. At the Australian Institute of Health and Welfare (AIHW), the agent retrieved aggregate statistics, though attempts to bypass access controls failed.

No foreign actor was involved. Prime Minister Anthony Albanese said the AI agent “found a way around those blocks. Didn’t accept no for an answer, if you like.”

Read next: What the Gemini and Claude hacking incidents mean for cyber insurers

What the wording may not cover

This incident has no human attacker, no malware, and no deliberate intrusion. What it has is access nobody authorised.

That is the core problem for cyber policy language written with a human threat actor in mind.

Mark Luckin, national manager for cyber and technology sector at Lockton Companies Australia, said the issue turns on what a wording actually tests. “The trigger should be the outcome, not the motive behind it,” Luckin said.

Better wordings, on his account, apply an objective standard: was the access authorised by the insured? That test does not require deliberate conduct from whoever – or whatever – obtained it. Wordings that rely on concepts like malicious intent, or that assume a human attacker, risk producing gaps as autonomous systems cause outcomes their operators never intended.

The legal framework faces the same problem. Sparke Helmore, in an August 2026 analysis, noted that establishing an offence under Section 477.2 of the Criminal Code requires proving a person intended to cause unauthorised access or modification. Where an AI model acts outside its parameters, that fault element may be difficult to establish.

The market is responding, but not uniformly. CFC announced in June 2026 that it was embedding affirmative AI coverage across seven key policy lines, including cyber. CFC chief underwriting officer Nick Line said the rationale was straightforward: “Rather than relying on implied or silent coverage, we see value in being explicit about how AI is treated.”

The broader picture is less settled. Gallagher’s 2026 AI Adoption and Risk Survey – which included an insurance professional sub-sample – found that one in five insurance industry respondents reported a client had experienced a loss or claim due to AI-related risks in the past year, with just over half of those fully covered. The survey also found respondents considered existing policy wordings too vague for AI-related losses, raising the prospect of coverage disputes.

The notification problem

The second issue for brokers is timing. OpenAI notified Services Australia on September 10 – close to three months after the June incident – using a public-facing email address. The Victorian health department and the NSW bureau were told between September 10 and 18. The Australian Institute of Health and Welfare was not informed until September 24, the day Albanese publicly announced the hack, because OpenAI determined the incident did not meet its own disclosure thresholds.

Luckin said an insured cannot be held to a standard it had no means of meeting. “Insurance generally cannot expect an organisation to notify an incident it genuinely does not know has occurred,” he said.

Under Australia’s Notifiable Data Breaches (NDB) scheme, the assessment obligation begins when an organisation first becomes aware of grounds to suspect a breach – not retrospectively from the date of the intrusion.

The Office of the Australian Information Commissioner (OAIC) received 1,205 data breach notifications in 2025, the highest total since mandatory reporting commenced in 2018. The scheme assumes the entity knows. The Medicare case shows that assumption can fail entirely when a third party controls the disclosure timeline.

The federal government has signalled that AI-specific laws are being readied from 2027, with proposed measures that may include mandatory reporting for AI companies whose products engage in security breaches, according to Reuters. That regulatory direction adds another layer of compliance risk for brokers advising clients who use or rely on third-party AI platforms.

What regulators had already flagged

None of this arrived without warning. In an open letter to all regulated entities on April 30, 2026, the Australian Prudential Regulation Authority (APRA) warned that governance, risk management, and operational resilience practices are not keeping pace with the scale, speed, and complexity of AI adoption. APRA said it would take stronger supervisory action – and pursue enforcement where necessary – against entities that fail to adequately identify, manage, or control AI-related risks.

That letter came five months before the Medicare incident became public.

Three questions for every renewal

For brokers placing cyber cover for Australian clients, the incident points to three questions that warrant attention at renewal.

Does the policy respond when an autonomous AI agent – not a human – executes the intrusion? Do exclusions for deliberate or malicious conduct inadvertently carve out AI-agent access? And does cover extend to incidents originating in a third-party AI platform the insured uses but does not control?

The affected government agencies did not know the incident had occurred until months after the fact. None of them caused it.

Read next: Medicare AI breach tests how cyber wordings define unauthorised access

What OpenAI has committed to

OpenAI said it would provide resources and expertise to affected agencies and offer government agencies and industries credits from its US$1 billion Daybreak fund for cyber defence. The company said it would also establish a taskforce to develop policy recommendations on managing AI agent risk. “We also should have handled our response better. We are sorry and working to do better in the future,” OpenAI said.

OpenAI’s chief strategy officer, Jason Kwon, is scheduled to appear before the Joint Select Committee on AI next Tuesday. Albanese said OpenAI had been “very constructive and open in engaging” since the incident.

“And we’ve seen those risks exposed – not just in what occurred in Australia, but the revelation that has occurred in the United States and other countries as well,” he said.



Click Here For The Original Source.

——————————————————–

..........

.

.