During internal model training in June 2026, a rogue AI agent accessed systems belonging to the NSW Department of Climate Change, Energy, the Environment and Water (DCCEEW). According to OpenAI’s own account, the agent used crafted queries against a National Parks and Wildlife Service (NPWS) fire history mapping service to retrieve database metadata that was not intended to be publicly accessible. The model also separately downloaded a publicly available NPWS fire history dataset. No personal information was accessed.
OpenAI says the NPWS activity was identified on September 29 as part of a broader internal review. A technical and legal review was completed within 48 hours, after which DCCEEW was notified and the Australian Signals Directorate (ASD) informed. DCCEEW is now working with Cyber Security NSW and its technology service provider to investigate.
The DCCEEW breach was the fifth Australian government system caught up in the same period of rogue AI agent activity. OpenAI’s public statement confirmed the earlier incidents involved Services Australia’s Medicare Statistics Reporting Service, the NSW Bureau of Crime Statistics and Research (BOCSAR), the Victorian Department of Health, and the Australian Institute of Health and Welfare (AIHW) – all during the same internal training and evaluation period in June.
According to OpenAI, the broader review began in mid-August, following a separate incident involving another technology organisation in July. Services Australia and the Victorian Department of Health were notified on September 10. BOCSAR was notified on September 18. The AIHW was notified on September 24. DCCEEW followed in early October.
The company acknowledged the response fell short: “We should have shared preliminary findings sooner and kept Australian agencies updated as more facts emerged.”
NSW Premier Chris Minns addressed the BOCSAR incident directly. “The mere fact the agent was told not to access the information – it’s not a malevolent company, they weren’t attempting to steal confidential information – and they did it anyway, that’s the power of artificial intelligence,” he said, according to ABC News.
NSW Greens MP Abigail Boyd called for a full audit of state government systems. “We clearly cannot rely on these multinational big tech companies to comply with even the most minimal of social obligations such as notifying when, or even taking enough care to notice if, their products are hacking government systems,” Boyd said.
Read next: When an AI does the hacking, does your client’s cyber policy respond?
For brokers with clients using third-party AI platforms, the disclosure timeline runs directly into how cyber policies are structured.
Under the Notifiable Data Breaches (NDB) scheme, covered entities must notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable after confirming a breach, with up to 30 days to complete an assessment from first becoming aware. NSW public sector agencies operate under a parallel mandatory scheme introduced in November 2023.
The structural problem is this: where a breach originates within a vendor’s AI system, the affected organisation has no visibility until the vendor chooses to disclose. Most cyber policies measure the notification window from when the insured “knew or ought to have known” – not from when a third party informed them. A gap of weeks between those two dates can determine whether a claim proceeds or is declined.
The OAIC recorded 1,205 data breach notifications in 2025 – the highest annual total since mandatory reporting began in 2018 and an 8% increase on the prior year. Australian government agencies contributed 118 of those, with health service providers the most commonly affected sector, accounting for 19% of the total.
“The threat posed to Australian businesses and organisations by data breaches is substantial and rising year on year,” said Australian Privacy Commissioner Carly Kind.
Two specific coverage issues come into focus from these incidents.
The first is how “computer system” is defined in the policy. Some wordings extend to third-party networks; others do not, leaving gaps where a breach originates outside the insured’s own infrastructure – the exact scenario across all five affected government systems.
The second is AI coverage. Until recently, AI rarely appeared in policy language at all. Where an AI tool caused a loss, cover often arose because the loss fell within a traditional insuring clause and was not expressly excluded. That position is changing. AI exclusions are beginning to appear in certain wordings, and their breadth varies. Clients who have not reviewed their policies since AI adoption accelerated may not know where they stand.
MinterEllison’s 2026 Perspectives on Cyber Risk report found that 57% of organisations surveyed had experienced a cyber incident through a supplier or vendor – precisely the exposure pathway these five incidents represent.
In April 2026, the Australian Prudential Regulation Authority (APRA) wrote to all regulated entities warning that AI adoption is materially changing the cyber threat environment. APRA specifically identified the manipulation or misuse of autonomous AI agents as an attack pathway and found that governance and assurance practices are not keeping pace with deployment. It also found that AI supplier contracts commonly lack provisions for incident notification.
In May 2026, the Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) co-published joint guidance on agentic AI security with agencies from the US, UK, Canada, and New Zealand. The guidance said organisations should assume agentic AI systems may behave unexpectedly and recommended prioritising resilience, reversibility, and risk containment as security practices and standards mature.
Read next: Cyber policies weren’t written for a world of stolen AI keys
For any client using third-party AI platforms, three questions need answers before renewal.
Does the policy definition of “computer system” extend to third-party infrastructure? If not, incidents originating in a vendor’s systems may fall outside cover.
When does the notification clock start? If it runs from when the insured “knew or ought to have known,” a vendor-controlled disclosure gap can put a compliant client in breach of their policy conditions through no fault of their own.
Does the policy contain an AI exclusion, and how broad is it? Silent coverage has been the default. It is no longer a reliable assumption, and confirming the current position before a loss is the only way to avoid finding out the hard way.