Most Australian businesses with cyber insurance do not know whether a stolen AI credential is covered. A new warning from the country’s peak cybersecurity agency – backed by a wave of regulatory action in 2026 – means brokers need to raise the question before a claim does.
The Australian Signals Directorate (ASD) published guidance on September 28, 2026, warning that malicious actors are actively targeting organisations’ AI services. The agency said companies should treat AI service access as a security-sensitive asset, and that protecting it goes beyond relying on the AI developer’s own controls.
The ASD identified five main entry points: compromised API keys, stolen authentication tokens, compromised user sessions, vulnerable applications, and third-party access arrangements.
API keys can turn up in source code repositories, configuration files, and browser extensions. Once an attacker has a working credential, the agency said, they can make requests independently of the victim’s legitimate application – with nothing to indicate anything has gone wrong.
Three incidents cited in the advisory illustrate the financial stakes. Research from Okta, reported by The Hacker News on September 9, 2026, found still-valid AI API keys and unexpired authentication tokens in data stolen from infected computers.
On September 1, 2026, The Register reported that a single attacker spent three weeks draining public-model credits worth approximately US$600,000, after exploiting an authentication flaw in an internet-facing agent dashboard.
On April 21, 2026, Reuters, citing Bloomberg, reported that unauthorised users accessed Claude Mythos Preview – then restricted to selected organisations – through a vendor environment.
The ASD also warned that a compromised agent or user session may be able to interact with connected enterprise systems, invoke tools, and access organisational data on the victim’s behalf. The practical impact of a compromise, it said, “may extend beyond the permissions directly assigned to the affected credential.”
Read next: CFC folds cyber, AI wording into financial institutions suite
AI credential theft sits awkwardly across standard policy categories. A loss might fall under funds transfer fraud, business interruption, or data breach coverage – but none of those categories were written with AI usage credit exhaustion or agent compromise in mind.
Gallagher’s 2026 AI Adoption and Risk Benchmarking Survey found that one in five insurance professionals reported a client had experienced losses from AI-related risks in the past year. Just over half of those losses were fully covered by insurance. The survey also found that many professionals consider current policy wordings too vague for AI-related losses – describing them as written for a “pre-AI world.”
Some carriers are moving to close the gap. In June 2026, CFC added affirmative AI language across seven of its policies, including cyber, technology errors and omissions, professional liability, and management liability lines. Chief underwriting officer Nick Line said: “Rather than relying on implied or silent coverage, we see value in being explicit about how AI is treated.”
The broader market has not followed. Most policy wordings available in Australia contain no AI-specific language, meaning whether a claim responds is a question that gets answered at claims time rather than at placement.
Australian law firm Lander & Rogers noted in April 2026 that the silent coverage position is closing: “Silent coverage is starting to be closed off by insurers as claims volume and systemic risk become clearer.”
The ASD advisory arrives against a backdrop of sustained regulatory pressure on AI governance across Australia’s financial sector – all of it directly relevant to brokers’ clients.
On April 30, 2026, the Australian Prudential Regulation Authority (APRA) published a letter to all regulated entities – including banks, insurers, and superannuation trustees – warning that governance, risk management, and operational resilience practices are “not keeping pace with the scale, speed and complexity of AI adoption.” The letter followed a targeted supervisory review of large financial institutions in late 2025. APRA specifically noted it is engaging with government agencies on the potential for increased cyber threats from high-capability AI frontier models.
On May 8, 2026, Australian Securities and Investments Commission (ASIC) commissioner Simone Constant issued an open letter to all AFS licensees warning that frontier AI models are lowering the barrier to sophisticated attacks and accelerating the speed and scale of exploitation. The letter set out 12 practical actions ASIC expects licensees to take and made clear that cyber resilience is a core licensing obligation, not an IT matter.
The court record underscores what non-compliance costs. On February 9, 2026, the Federal Court ordered FIIG Securities to pay $2.5 million in civil penalties after ASIC pursued the firm for cybersecurity failures that breached its AFSL obligations – Australian Securities and Investments Commission v FIIG Securities Limited [2026] FCA 92. For a client whose AI infrastructure is compromised and who cannot demonstrate adequate controls, the exposure is both a coverage dispute and a separate regulatory action.
Read next: What the Gemini and Claude hacking incidents mean for cyber insurers
The ASD’s advisory outlines five control areas that translate directly into renewal conversations. Clients should be able to confirm that AI accounts and credentials are inventoried with accountable owners, stored in approved secrets-management systems rather than in code or config files, subject to least-privilege access, monitored for unusual usage, and covered by a documented incident response plan.
The disclosure question is equally pressing. Most renewal forms do not ask clients to detail their AI deployments or the controls applied to AI credentials. MinterEllison’s 11th annual Perspectives on Cyber Risk report, published in August 2026, found that 94% of Australian organisations surveyed hold cyber insurance – a large number of policies placed without any disclosure of AI usage.
The ASD’s Annual Cyber Threat Report 2024-25, published in October 2025, recorded over 84,700 cybercrime reports across the financial year – one every six minutes – with average business losses rising 50% to $80,850 per incident.
AI credential theft is part of that threat environment. Whether a client’s policy is built to respond to it is a question brokers are better placed to answer before an incident than after.