Regulatory pressure building

Regulators in both markets are signalling closer scrutiny. In Australia, the Insurance Council of Australia (ICA) in September 2025 called for an expansion of business cybersecurity obligations as AI-driven automated cyberattacks and other emerging risks threaten the cyber resilience of Australian businesses, in a submission to the Department of Home Affairs Horizon 2 consultation on the 2023-2030 Australian Cyber Security Strategy that identified AI, quantum computing, and consumer-managed personal data stores as key weaknesses. In New Zealand, the Office of the Privacy Commissioner’s 2024-25 annual report noted a 43% increase in serious privacy breaches notified to the regulator, and the government published its Cyber Security Strategy 2026-2030 on Feb. 27, with officials weighing a civil penalty regime under the Privacy Act 2020, which already requires notification of serious breaches. For insurers, the combination of rapid agentic AI adoption, ungoverned tool use, a perception gap over deepfakes, and softening rates points to exposures that application questions may not capture. As AI systems move further into routine operations, governance, staff awareness, and incident reporting remain central to how cyber risk in the region is assessed.