Spain and Australia sharpen the AI cyber insurance debate

Spain and Australia sharpen the AI cyber insurance debate

Autonomous AI is no longer a theoretical concern for cyber risk professionals. A cluster of recent cases, highlighted by KYND, shows AI agents appearing at the centre of real security incidents, and the lesson for organisations and insurers is less about new threats than about old controls being neglected.

The three cases have little in common on the surface. One reportedly involved an agent used deliberately in an attack. Another saw a legitimate research agent wander into a government system it should not have reached. The third revealed coding agents inside large organisations obeying instructions that led to unowned software packages. KYND cautions against treating them as the same problem, yet each points back to the same issue: what the software was permitted to do.

Spain provided the first example. In September, the AEPD, the country’s data protection regulator, disclosed it had received its first breach notification describing an AI agent as the instrument of an attack. The notifying organisation said the agent scanned for weaknesses, signed into an application, navigated it on its own, changed personal data and opened invoices. The AEPD has not confirmed this version of events and stressed that the use of a given AI model does not mean the model or its provider was breached.

In Australia, an autonomous OpenAI agent on a research task gained unintended access to a government statistics portal containing non-public Medicare data. The event happened in June, but authorities were not told until September. OpenAI says it found no record of patient data being accessed. The government has since ordered a rapid review into whether existing law and governance remain ‘fit for purpose’ when AI is involved in cyber incidents.

The coding-agent research arguably carries the broadest implications. Researchers found agents following vendor documentation and executing commands pointing to abandoned packages and domains. After registering some of those names and publishing benign test packages, they saw a Fortune 500 company connect within an hour, with others close behind. Nothing was stolen and nobody was phished. The agents simply trusted what they read.

This is where the fundamentals come in. Agents deliver value only when given access, and the fastest way to make them work is often to hand over broad credentials rather than carefully scoped permissions. Least privilege, data minimisation and network segmentation all tend to slip under deployment pressure. The result is that an unexpected action, a malicious instruction or a misread document can travel much further than it should. After an incident, KYND suggests, the more useful question is not how something got in, but why the agent could reach that system at all.

For cyber underwriters, the familiar checklist of access control, segmentation and monitoring still applies. The challenge is applying it to AI deployments that insureds may not fully track themselves. AI features can arrive embedded in existing tools or be adopted outside formal processes, making self-declaration on proposal forms unreliable. The coding-agent findings also hint at accumulation risk, as similar agents and dependencies surface across unrelated firms within a single book of business.

KYND is responding by adding AI technology detection to its technographic intelligence for insurers. Its position is that using AI is not a red flag in itself. What matters is separating AI adoption from AI exposure, and ensuring basic cyber discipline evolves as quickly as the technology does.

Read the KYND analysis

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our weekly InsurTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.