AI has changed the cyber threat. Has your clients’ cover kept up?

Regulators say existing risk assumptions may no longer hold

AI has changed the cyber threat. Has your clients’ cover kept up?

Cyber

By Roxanne Libatique

A coordinated wave of warnings from Australian regulators and intelligence agencies has converged on a single message for insurance brokers: frontier AI is changing the threat environment faster than most clients’ risk tolerances – or their policy wordings – currently reflect.

The Australian Signals Directorate (ASD) and the Australian Institute of Company Directors (AICD) released Frontier AI Cyber Threat Considerations for Boards of Directors on August 5, 2026. The guidance warns that frontier AI models are compressing attack timelines, lowering the skill barrier for malicious actors, and – in its most commercially significant finding – that these developments “may rapidly invalidate organisations’ current risk tolerances.” For brokers, that assessment now has weight from multiple directions.

The regulatory sequence brokers need to track

The ASD-AICD guidance is the latest in a sequence that began in April. The Australian Prudential Regulation Authority (APRA) issued its first published, AI-specific expectations of boards and accountable executives on April 30, 2026, drawn from a targeted supervisory engagement with selected large banks, insurers, and superannuation trustees, covering cyber and information security, governance, supplier risk, and change management. APRA stated that AI adoption is materially changing the cyber threat landscape for regulated entities, increasing the pathways attackers can use and leading to more frequent attacks.

The Australian Securities and Investments Commission (ASIC) followed on May 8, 2026, with an open letter to all AFS licensees and market participants calling for urgent action, warning that misuse of frontier AI models could expose cyber security vulnerabilities at an unprecedented speed, scale, and sophistication. ASIC commissioner Simone Constant was direct. “Cyber risk has entered a new era. The advent of frontier AI models creates opportunity, but also materially increases risk, with the ability to expose vulnerabilities far faster than many realise,” Constant said.

On June 22, 2026, the Five Eyes intelligence agencies jointly warned that frontier AI models will likely “exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities,” and that “the timeline is not years, it is months.”

Brokers with clients holding Australian Financial Services Licences (AFSL) are now operating in an environment where AI cyber risk governance is an active supervisory focus across ASIC, APRA, and the ASD simultaneously.

The numbers behind the risk

The Office of the Australian Information Commissioner (OAIC) recorded 1,205 data breach notifications in 2025 – the highest since mandatory reporting commenced in 2018 and an 8% increase over 2024, with 716 attributable to malicious or criminal activity. The ASD’s Annual Cyber Threat Report 2024-25 found the average cost per cybercrime report for businesses rose 50% to $80,850, while large businesses experienced a 219% rise in losses. Against this, cyber insurance pricing also softened in 2025, with EBM Insurance and Risk reporting that some clients received premium reductions of 1% to 10% as competition increased. Cyber gross written premium has never exceeded $73 million in a single quarter in the APRA dataset – a penetration gap that the soft market alone has not closed.

The coverage question brokers must now raise

The ASD-AICD guidance identifies agentic AI – autonomous systems acting on behalf of organisations – as a category requiring strict privilege controls. That governance recommendation points directly to an unresolved coverage question the Australian market has not yet answered.

The insurance market has devoted growing attention to so-called “silent AI” exposure, where policies neither expressly cover nor exclude AI-related risks. A study by the Artificial Intelligence Underwriting Company (AIUC), co-authored by researchers from Anthropic, OpenAI, insurers, brokers, and universities, found that agentic AI exposure is concentrated across cyber, directors and officers, commercial general liability, and technology errors and omissions policies – risks that are neither expressly included nor excluded, leaving insurers potentially liable for losses they never priced.

Nicholas Blackmore, partner at Kennedys in Melbourne and head of the firm’s APAC cyber risk group, has flagged the practical consequence for Australian brokers. “It may be that we get a large case, a big dispute about whether a particular scenario is covered by PI or product liability when it was a case of an AI tool going wrong,” he said, adding that brokers in Australia should start a thorough AI fact-finding process with clients now.

Gallagher’s 2026 research found that one in five insurance professionals surveyed reported their insureds had already experienced losses linked to AI risk, yet most policy wordings were never designed with AI liability in mind.

Some insurers are responding. CFC has updated policy language across technology errors and omissions, professional liability, and cyber lines, with chief underwriting officer Nick Line stating: “Rather than relying on implied or silent coverage, we see value in being explicit about how AI is treated.” However, the broader market remains fragmented, with carriers moving in divergent directions across endorsements and exclusions.

Three client conversations the guidance enables

The ASD-AICD document structures three risk categories that map directly to coverage and renewal discussions. On legacy systems, the guidance formally elevates infrastructure that cannot meet current security requirements as materially more exposed in an AI-driven threat environment. On supply chain, it asks whether organisations have visibility of third and fourth-party supplier security postures – language that maps to sublimits and exclusions common in Australian cyber policies. On agentic AI, it specifies minimum-privilege controls for AI agents, raising the question of how existing policy wordings respond to incidents where an autonomous system – operating under legitimate credentials – causes loss without any external attacker.

The Australian Cyber Security Centre (ACSC) responded to 138 ransomware incidents in 2024-25, and 39% were detected by the ACSC rather than by the affected organisations themselves – a detection gap that underscores the incident response readiness question the guidance directs at boards, and that brokers can now raise as both a coverage and an underwriting conversation.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!