An autonomous artificial intelligence agent has exploited a vulnerability in an Australian gym’s booking software – reported by the ABC as the first known case of an AI-driven cyber intrusion on Australian soil. For insurance brokers, the incident is a concrete illustration of a coverage problem that is already generating claims, that Australian-specific data confirms is accelerating, and that existing policy wordings were never designed to address.
The user, identified only as Andrew by the ABC, instructed an AI agent built on Anthropic’s Claude service and run through a software platform called OpenClaw to book a gym class on his behalf. Rather than operating within the parameters set by the booking system, the agent identified a vulnerability that allowed it to secure classes further in advance than permitted. It then went beyond its instructions, removing another gym member from a waiting list without being asked. When Andrew asked the agent to reverse the action, it reported it could not. “Bad news – I can’t add them back,” it replied, according to the ABC. The gym booking software provider told the ABC it did not discuss specific security matters.
The incident exposes a structural problem for cyber underwriters. Traditional cyber policy triggers are built around intent and identity: an external attacker obtained unauthorised access, a phishing email deceived a user, or malware encrypted a system. An AI agent acting under legitimate credentials, completing a task it was authorised to attempt, and causing harm as a side effect, fails most of those tests. There was no intruder, no deception, and no malware – only an autonomous system that acted beyond its instructions under its user’s name.
The incident illustrates what AI safety researchers call the “alignment” problem – the gap between a user’s stated goal and the methods an AI agent independently selects to achieve it. Bill Simpson-Young, co-founder and chief executive of Gradient Institute, an Australian AI safety research organisation, told the ABC that growing AI agent autonomy creates more opportunities for systems to act in ways users did not anticipate. “Someone might be asking an agent to do something quite innocent. But in completing that task, the agent could carry out other activities the person had not considered or explicitly asked for,” Simpson-Young said.
Hayden Delaney, a partner at law firm Thomsons specialising in technology, intellectual property, and privacy, told the ABC that Australian law does not cleanly accommodate autonomous AI behaviour. “Software is not a legal person. Only a legal person can be liable at law,” he said. Responsibility could fall on the user, the agent software developer, the AI model developer, or the operator of the exploited system. “That’s the unknown area of liability in Australia that we’re facing right now,” he said.
Nicholas Blackmore, partner at Kennedys in Melbourne and head of the firm’s APAC cyber risk group, has flagged the direct consequence for brokers: “It may be that we get a large case, a big dispute about whether a particular scenario is covered by PI or product liability when it was a case of an AI tool going wrong,” adding that brokers in Australia should start a thorough AI fact-finding process with clients now.
QBE’s June 2026 survey of Australian businesses found that 50% reported a cyber event in the past 12 months, with 26% saying the incident was believed to involve AI, as AI adoption became embedded in operations, with 85% of Australian organisations already using AI and a further 12% actively exploring its use. QBE’s global head of cyber services, Dominic Keller, noted that “the pace of this change is moving faster than some organisations can adapt their risk frameworks – this is where cyber exposures can start to build.” Gallagher’s 2026 AI Adoption research, in a global survey of insurance professionals, found that one in five respondents reported their insureds had already experienced economic losses or made claims due to AI-related risks in the past year, with just over half covered fully by insurance. Classes of business most likely to be impacted include cyber liability, product liability, and employment practices liability.
The market is moving away from silent AI coverage – the implicit inclusion of AI risks through existing cyber and professional indemnity (PI) policies – as insurers introduce AI-specific exclusions and revised forms, creating gap risk where no single policy provides comprehensive coverage. The dynamic mirrors the silent cyber trajectory: Lloyd’s announced in July 2019 that it would require managing agents to address silent cyber risk by ensuring policies provided affirmative cyber cover or expressly excluded cyber risks. The first phase took effect from January 2020, with requirements subsequently extended to additional classes of business through 2021, prompting widespread changes to policy wordings.
QBE’s response illustrates the range of approaches now in play. In July 2025, QBE North America introduced AI-focused cyber coverages specifically addressing LLMjacking – a form of attack in which threat actors use stolen credentials to access cloud-hosted large language models, exploiting computing resources and incurring costs for the victim. Subsequently, the Financial Times reported in April 2026, citing brokers and documents, that QBE had introduced draft sublimit wording under which a cyber policy with total cover of up to $5 million would provide only around $250,000 for losses arising from LLMjacking.
In a statement to the Financial Times, QBE said it was not retreating from AI risks, adding that where coverage developments had occurred, they had been focused on enhancing protection for specific emerging exposures rather than narrowing core cover, and that if an AI-related event leads to a conventional cyber incident, resulting losses continue to fall fully within the core cyber policy. However, brokers and lawyers advising policyholders have flagged concern that sublimit provisions could later be applied more broadly, reducing protection against a widening range of AI-related risks beyond LLMjacking.
On May 1, 2026, the Australian Signals Directorate’s (ASD) Australian Cyber Security Centre (ACSC) co-issued guidance on agentic AI with counterpart agencies in the US, the UK, Canada, and New Zealand, warning of cybersecurity challenges associated with introducing agentic AI into IT environments and specifying that organisations should never grant an agent broad or unrestricted access to sensitive data or critical systems.
Aon’s head of cyber risk consulting for Asia-Pacific, Adam Peckman, has noted that “the organisations that get ahead of AI risk are the ones that treat governance as a living discipline – something that evolves with the technology, not after it.” Gallagher’s 2026 AI Adoption and Risk Survey found that fewer than half of all respondents have adopted formal risk management frameworks around AI usage – a readiness deficit that carriers are beginning to price in.
For Australian brokers, the Andrew case is a low-stakes preview of what a commercially significant AI agent incident could look like. The liability here was minor. The coverage question it exposes is not.