For eleven years after Australia's terrorism reinsurance scheme opened for business, nobody ever had to use it. Then, within the space of six weeks this summer, the Australian Reinsurance Pool Corporation (ARPC) made two separate terrorism declarations - the Bondi Beach attack in December 2025 and an attempted bombing in the Perth CBD in January 2026.
Neither ended up generating a claim large enough to touch the pool's reserves. But together they were only the second and third time in the scheme's history that it has ever been switched on, the first being the Lindt Café siege back in 2014.
Twenty-five years after 9/11, that's the real measure of what changed in Australian insurance: not a loss, but a piece of infrastructure that sat almost entirely dormant for two decades and is now being tested more often than anyone who designed it expected.

Australia's response to the September 2001 attacks followed the same first chapter as everyone else's: reinsurers worldwide withdrew terrorism cover from commercial policies almost immediately, and Australian insurers began attaching terrorism exclusions to commercial property, business interruption and public liability policies through 2002, leaving large parts of the commercial property sector effectively uninsured against the risk.
What made Australia's path distinctive was timing. While the Commonwealth government was still working out the design of a national scheme, the Bali bombings killed 202 people on 12 October 2002, 88 of them Australian. Weeks later, on 25 October 2002, the government announced its finalised proposal for a national terrorism reinsurance scheme. A sequence that state parliamentary records linked at the time, warning that after Bali, terrorism risk "may become completely uninsurable" without government intervention. The Terrorism Insurance Bill followed that December, received royal assent on 24 June 2003, and the Australian Reinsurance Pool Corporation began operating a week later, on 1 July 2003.
The mechanics were designed to mirror what other governments were building at the same time: the Act overrides terrorism exclusions in eligible commercial contracts once the Treasurer formally declares an incident, and insurers can then recover eligible losses through ARPC, backed by a layered structure of premium reserves, a bank line of credit and a Commonwealth government guarantee. The scheme's total protection has grown from an initial $10.3 billion in aggregate cover to roughly $13.4 billion today.
For its first decade, the pool collected premiums and paid nothing out, because there was nothing to declare. That changed on 15-16 December 2014, when the Treasurer declared the Lindt Café siege in Sydney's Martin Place a terrorist incident which was the first activation of the Act in its history. Even then, insured losses stayed well under $1 million, nowhere near the point where ARPC's own reserves would have been touched.
It stayed quiet again for another eleven years. Then, on 14 December 2025, an attacker killed and injured multiple people at Bondi Beach; ARPC's formal declaration followed two days later, on 16 December, with the reduction percentage set at 0% which meant no cap applied to what insurers could recover. "The Terrorism Reinsurance Pool exists to safeguard the Australian insurance market from the financial impact of rare but severe terrorism events," ARPC chief executive Dr Christopher Wallace said at the time.
Barely six weeks later, an attempted bombing in the Perth CBD on 26 January 2026 triggered a second declaration, though ARPC confirmed no property damage or insured losses were expected from that incident.
The other thing that's changed since 2003 is what ARPC actually does. In March 2022, the government amended the original Act, renamed the Terrorism and Cyclone Insurance Act, to give ARPC a second job: administering a $10 billion Cyclone Reinsurance Pool for cyclone and cyclone-related flood damage to homes, strata properties and small businesses in northern Australia.
The ACCC's fifth and final mandatory monitoring report confirmed the cyclone pool has reduced premiums in high-risk areas since it began, even as affordability pressure keeps building nationally; ARPC's own May 2026 assessment put the cumulative reduction in the highest-risk areas at 37% since October 2022. It's a similar trajectory to what happened with the UK's Pool Re and the US's TRIA: a piece of infrastructure built for one specific, deliberately-caused loss ends up getting adapted to handle other perils that private capital alone won't fully price.
A statutory review of the whole Act, examining whether both pools are still fit for purpose, opened in September 2025 and remains ongoing.
The underlying question ARPC exists to answer, can a loss be modelled with confidence, does it stay independent of other losses, and does the country need a public backstop to keep coverage available if the answer is no, is exactly the question now being asked of cyber risk. Coalition's own executives have warned that 2026's cyber threat looks less like isolated breaches and more like correlated, systemic loss running through shared cloud and software dependencies, the same clustering problem that made terrorism uninsurable on private capital alone in 2001.
Twenty-five years on, the number worth remembering about Australia's answer to 9/11 isn't the size of the pool or even the two declarations this summer. It's eleven. That’s the number of years the scheme operated without ever being needed, and the reminder that infrastructure built quietly after a crisis often proves its worth only long after everyone has stopped expecting to use it.