During internal model training in June 2026, a rogue AI agent accessed systems belonging to the NSW Department of Climate Change, Energy, the Environment and Water (DCCEEW). According to OpenAI's own account, the agent used crafted queries against a National Parks and Wildlife Service (NPWS) fire history mapping service to retrieve database metadata that was not intended to be publicly accessible. The model also separately downloaded a publicly available NPWS fire history dataset. No personal information was accessed.
OpenAI says the NPWS activity was identified on September 29 as part of a broader internal review. A technical and legal review was completed within 48 hours, after which DCCEEW was notified and the Australian Signals Directorate (ASD) informed. DCCEEW is now working with Cyber Security NSW and its technology service provider to investigate.
DCCEEW is the fifth Australian government body caught up in the same period of rogue AI agent activity. OpenAI's public statement confirmed the earlier incidents involved Services Australia's Medicare Statistics Reporting Service, the NSW Bureau of Crime Statistics and Research (BOCSAR), the Victorian Agency for Health Information (VAHI) and the Australian Institute of Health and Welfare (AIHW), all during the same internal training and evaluation period in June.
According to OpenAI, the broader review began in mid-August, following a separate incident involving another technology organisation in July. Services Australia and the Victorian Department of Health were notified on September 10. BOCSAR was notified on September 18, the AIHW on September 24 and DCCEEW in early October.
The company acknowledged the response fell short: "We should have shared preliminary findings sooner and kept Australian agencies updated as more facts emerged."
NSW Premier Chris Minns addressed the BOCSAR incident directly. "The mere fact the agent was told not to access the information – it's not a malevolent company, they weren't attempting to steal confidential information – and they did it anyway, that's the power of artificial intelligence," he said, according to ABC News.
NSW Greens MP Abigail Boyd called for a full audit of state government systems. "We clearly cannot rely on these multinational big tech companies to comply with even the most minimal of social obligations such as notifying when, or even taking enough care to notice if, their products are hacking government systems," Boyd said.
The affected bodies are government agencies, most of which are covered through government self-insurance arrangements rather than commercial cyber policies. The lessons for brokers come from the sequence of events, which could just as easily involve a commercial client using a third-party AI platform.
Read next: When an AI does the hacking, does your client's cyber policy respond?
Under the Notifiable Data Breaches (NDB) scheme, covered entities must notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable after confirming an eligible breach, with up to 30 days to complete an assessment from first becoming aware. NSW public sector agencies operate under a parallel mandatory scheme introduced in November 2023.
The difficulty arises when a breach originates within a vendor's AI system. The affected organisation has no visibility until the vendor chooses to disclose, and in these cases that took up to four months.
Cyber policies typically require the insured to notify the insurer promptly once it knows, or ought to know, of an incident. An insured that genuinely did not know because a vendor withheld the information is not automatically in breach of that condition. The risk is a dispute over whether the insured ought to have known sooner, for example through its own monitoring or contractual reporting from the vendor.
Australian law also limits how far a late notification can affect a claim. Under section 54 of the Insurance Contracts Act 1984, an insurer generally cannot refuse a claim because of something the insured did or failed to do after the policy was entered into, including late notification. It can reduce the claim only to the extent its interests were prejudiced by the delay. A vendor-driven delay is therefore more likely to raise questions about prejudice and the size of a claim than to void it outright, but those questions can still be costly to resolve.
The OAIC recorded 1,205 data breach notifications in 2025, the highest annual total since mandatory reporting began in 2018 and an 8% increase on the prior year. Australian government agencies contributed 118 of those, and health service providers were the most commonly affected sector, accounting for 19% of the total.
"The threat posed to Australian businesses and organisations by data breaches is substantial and rising year on year," said Australian Privacy Commissioner Carly Kind.
MinterEllison's 2026 Perspectives on Cyber Risk report found that 57% of organisations surveyed had experienced a cyber incident through a supplier or vendor, the same pathway these five incidents represent.
In April 2026, the Australian Prudential Regulation Authority (APRA) wrote to all regulated entities warning that AI adoption is materially changing the cyber threat environment. APRA specifically identified the manipulation or misuse of autonomous AI agents as an attack pathway, and found that governance and assurance practices are not keeping pace with deployment. It also found that AI supplier contracts commonly lack provisions for incident notification.
In May 2026, the Australian Signals Directorate's Australian Cyber Security Centre (ACSC) co-published joint guidance on agentic AI security with agencies from the US, UK, Canada and New Zealand. The guidance said organisations should assume agentic AI systems may behave unexpectedly, and recommended prioritising resilience, reversibility and risk containment as security practices and standards mature.
Read next: Cyber policies weren't written for a world of stolen AI keys
For any client using third-party AI platforms, three questions are worth answering before renewal.
The first is whether the policy definition of "computer system" extends to third-party infrastructure. Some wordings do, and others do not. If the definition stops at the insured's own systems, incidents originating in a vendor's environment, the scenario in all five government cases, may fall outside cover.
The second is how the notification condition is worded and what the client's vendor contracts require. Prompt notification obligations work best when suppliers are themselves contractually obliged to report incidents quickly. APRA's finding that AI supplier contracts often lack such provisions suggests many clients have a gap here.
The third is whether the policy contains an AI exclusion, and how broad it is. Until recently, AI rarely appeared in policy language. Where an AI tool caused a loss, cover often arose because the loss fell within a traditional insuring clause and was not expressly excluded. AI exclusions are now beginning to appear in some wordings, and their breadth varies. Clients who have not reviewed their policies since AI adoption accelerated may not know where they stand.