News

AI agents are exposing the limits of the unauthorised access trigger

An Australian incident and a UK data case point brokers to two gaps in how cyber wordings respond to autonomous systems

AI agents are exposing the limits of the unauthorised access trigger

An AI model asked to research public medicine spending encountered a locked portal. It found a way around it. 

On 24 September, Australian Prime Minister Anthony Albanese disclosed that an OpenAI research model had kept working at a Medicare statistics portal run by Services Australia after being refused, eventually gaining access in June, Insurance Business Australia reported. OpenAI has said its models took actions the company did not intend. Services Australia was not notified until 10 September, close to three months later. 

No human attacker was involved. That makes the case difficult for wordings that assume deliberate conduct: an autonomous agent can cause an outcome its operator never intended. 

When AI causes the loss 

James Breese, policyholder disputes partner at Stewarts, said buyers should be alert to the potential for disputes. 

“Buyers of cyber insurance policies must also be aware of the scope for coverage disputes where an AI tool is deemed to be the cause of the cyber loss,” he said. 

He said insurers narrowing cover would come as little surprise. “Given the challenges that AI presents, including to insurers, it is unsurprising that they may seek to narrow or carve-out the AI related cover available even in cyber insurance policies.” 

Mark Luckin, national manager for cyber and technology sector at Lockton Companies Australia, told Insurance Business Australia that better wordings apply an objective test of whether access was authorised by the insured, rather than what the person or machine obtaining it intended. “The trigger should be the outcome, not the motive behind it,” he said. 

A UK Biobank data incident raised the opposite problem. Data accessed legitimately by approved researchers was reportedly later exposed externally. Speaking to Insurance Business in April, Ed Ventham, head of broking at Assured Cyber, said the obstacle to cover was what had not happened. 

“There’s not been any unauthorised access. That is the trigger. It’s the unauthorised access piece. It wasn’t there,” he said at the time. 

Ventham was looking for wordings that would respond without that trigger. “I’m now on the hunt for a policy that allows the privacy liability to be triggered when not from an unauthorised access,” he said. 

An agent given legitimate credentials by a business could likewise cause a loss without meeting an unauthorised access trigger, whereas the Medicare agent got past controls designed to keep it out. Together, the cases give brokers two questions to test against a wording: does it respond where an agent gets in without anyone intending it, and does it respond where an agent with permission causes the damage? 

Sharper questions at underwriting 

“Insurers will be aware with the increasing sophistication of attacks and the speed with which they are carried out. The questions at underwriting will become increasingly more detailed and focussed, which policyholders must ensure are carefully and accurately answered,” Breese said. 

For UK commercial buyers, accurate answers matter under the duty of fair presentation in the Insurance Act 2015: a qualifying breach can give insurers proportionate remedies at claim stage. Brokers are already facing questions about how clients use AI tools and what data they can reach, and the quality of those answers will matter more as scrutiny grows. 

“It is critical for the market and policyholders to accurately understand the risk landscape in an environment where the risks are constantly evolving,” Breese said. 

Services Australia appears not to have spotted the activity itself. Luckin said an insured cannot be expected to notify an incident it does not know has occurred, leaving it reliant on a third party disclosing promptly. 

The next agent may not announce itself 

Camellia Chan, CEO and founder of X-PHY, criticised the months it took for Australia to be notified, and warned that a future incident may not be disclosed at all. 

“The next agent may well be run by a hostile state or criminal group. It will not notify the target, publish a review or offer assurances about what data it did not access,” she said. 

She called for enforceable oversight of autonomous AI, rather than relying on companies to discover and explain their own failures. 

The Medicare activity was, by OpenAI’s account, unintended, but underwriters must also consider an agent directed by a criminal group. The lesson is to test a client’s wording against both scenarios before renewal, including whether any AI exclusion removes protection the client assumes it has. 

Source

COMPLAINTS