Insurance and risk updates

What’s changing, and why it matters

Insurance, regulation and cyber risk do not stand still. Here is the plain-English version, with official sources so you can check the detail.

Page updated . Legislative sources were last checked on .

Ask what may affect your insurance

Australian property, construction, cyber and transport insurance examples

Data centres, AI and insurance: the risk is bigger than the building

William Law · Published on LinkedIn

Why is data-centre risk bigger than the building? A facility can remain physically intact yet lose uptime and revenue through a failed transformer, delayed grid connection, cooling breakdown, cyber incident or supply-chain disruption.

William Law's new article connects the risk across construction and commissioning, power and cooling machinery, property and ISR, business interruption, cyber and AI security, marine transit, external suppliers and project finance.

Why it matters: owners, developers, operators and lenders should test the hand-offs between construction and operation, physical damage and non-damage interruption, internal equipment failure and outside dependencies. A list of policies does not by itself prove that every failure route is covered.

The article is general commentary. Insurance response depends on the applicable wording and circumstances, while legal and regulatory duties require separate advice.

NSW strata and construction watch: DLI Act assented, not operational at 30 August 2026

Insurance wording reviewed 6 August 2026 · Official sources checked

This is a legislative watch item for strata and construction clients. Latent defects insurance is not currently one of Broking For You's six core services.

Here is the current position. The NSW strata building bond remains 2% of the contract price. The scheduled increase to 3% has been deferred until 1 July 2028.

The Fair Trading and Building Legislation Amendment Act 2026 received assent on 14 August 2026. Its substantive DLI amendments commence by proclamation and had not commenced as at 30 August 2026. Building Commission NSW was still assessing prospective providers' policies. The Act is important legislative groundwork, but it is not proof that an accepted product is generally available or that DLI is already mandatory.

The current NSW framework uses decennial liability insurance (DLI) for a qualifying policy taken out by a developer in favour of the owners corporation. The law in force at the review date addresses defined serious defects in common-property building elements for 10 years on a strict-liability basis. Recheck the in-force Act when the 2026 amendments commence.

If an eligible product is available and the legislative, policy and regulatory-acceptance requirements are met, DLI can provide an alternative to specified bond and inspection requirements. You may also see the market term latent defects insurance (LDI), but the label alone does not mean a policy meets the NSW DLI framework.

Important transitional warning: NSW Government guidance says evidence may be uploaded for an LDI policy purchased between 22 August 2022 and 24 October 2024, provided payment was made within that period. It says policies purchased after 24 October 2024 will not be accepted for that transitional purpose and all other SBBIS requirements continue to apply. Confirm the position for the particular project with Building Commission NSW before relying on an exemption.

Not the same as contract works: Contract works insurance addresses insured physical loss or damage to works and materials during construction. Latent defects cover addresses specified post-completion defect risk. One does not automatically replace the other.

Cyclone pool: 2026 SME mitigation pricing and the $5 million threshold

Official ARPC and ACCC sources checked

ARPC's cyclone-pool premium rates v4.0 took effect on 1 April 2026 and introduced discounts in the reinsurance pricing algorithm for qualifying small-business property mitigation, including specified roof, window, door and gutter improvements.

Eligible small-business commercial property policies are generally limited to a maximum policy-level sum insured of $5 million across property, contents and business interruption covered by the pool. Residential and qualifying mixed-use strata can also be eligible. The pool is a reinsurance arrangement between insurers and ARPC, not a policy bought directly by a client.

The ACCC reported that, in the first year after insurers joined the pool, average premiums per $100,000 sum insured in higher-cyclone-risk areas fell 8% for strata and 24% for small-business insurance. Those are monitored averages, not a promise about an individual quote. Insurers remain responsible for retail pricing.

Why it matters: a Business Pack or ISR and strata renewal in cyclone regions should document building values, roof and opening protections, completed mitigation and maximum interruption values. Better evidence does not guarantee a premium reduction or acceptance.

Heavy Vehicle National Law changed on 1 August 2026

Official NHVR sources checked

The amended Heavy Vehicle National Law and new Heavy Vehicle Accreditation scheme took effect on 1 August 2026 in participating jurisdictions. The tiered accreditation framework uses a whole-of-business Safety Management System and new audit standards, with transitional arrangements for existing NHVAS operators.

Why it matters: operators reviewing commercial motor and mobile plant/equipment fleet insurance should be ready to explain maintenance, fatigue, driver fitness, accreditation, chain-of-responsibility controls and incident management. These records may help an insurer understand fleet risk, but regulatory compliance does not itself guarantee cover or a lower premium.

Western Australia and the Northern Territory retain separate domestic heavy-vehicle laws. An interstate operation should check the rules applying in every jurisdiction in which it travels.

Marine transit: lost-container reporting and a new cargo-securing inspection campaign

Official legislation and AMSA sources checked

Amendments to Marine Order 27 took effect on 1 April 2026. A vessel master must report freight containers lost overboard, or observed in the water, by an appropriate means and at the earliest practicable time.

This is principally a vessel-operational reporting duty, not a new insurance policy term or a general reporting duty imposed on every cargo owner. For marine cargo and stock-throughput clients, the practical point is evidence: preserve carrier reports, voyage details, time and position of loss, shipping documents, survey material and prompt insurer notification for any claim or recovery.

New from 1 September 2026: AMSA is running a concentrated cargo-securing inspection campaign through 30 November 2026 during routine port State control inspections of foreign-flagged vessels. Officers will examine loading, stowage, securing equipment, records and use of the Cargo Securing Manual. This is an enforcement campaign, not new insurance legislation. Cargo owners and freight operators should retain securing and procedural evidence because deficiencies can affect loss prevention, causation and recovery disputes.

Building information that supports a clearer strata submission

Insurance wording reviewed 6 August 2026 · Official sources checked

A tidy building file does more than save everyone an email chase. It can give a broker and underwriter a clearer, evidence-based picture of the property.

NSW strata reforms from 1 April 2026 introduced standard forms for initial maintenance schedules and new or revised 10-year capital works fund plans, plus independent-review requirements for certain multi-storey schemes.

Next commencement: from 1 October 2026, NSW strata committee members must complete annual online training within three months of appointment, while two-lot schemes will no longer have to complete annual Strata Hub reporting. These governance changes do not alter policy wording by themselves, but current records and informed committee oversight can support a clearer insurance submission.

A useful insurance information pack may include:

  • a current replacement valuation, claims and excess history;
  • the 10-year capital works plan, fund balance and maintenance records;
  • occupation and fire-safety documents;
  • defect, inspection and engineer reports; and
  • evidence that identified defects and remedial work have been completed or are being managed.

Clear evidence may improve the quality of a strata insurance submission and help an underwriter assess condition, governance and risk controls. It does not guarantee a lower premium, lower excess, broader cover or insurer appetite.

An engineer’s report can work both ways: completed remediation may help explain the risk, while unresolved defects may lead to more questions, exclusions or different terms.

Cyber risk: AI prompts, data handling and social engineering

Insurance wording reviewed 6 August 2026 · Official sources checked

A useful rule: do not paste information into a public AI tool unless you are comfortable with where it could go.

For organisations covered by the Privacy Act, OAIC guidance says privacy obligations apply to personal information in AI inputs and outputs. It recommends not entering personal information, particularly sensitive information, into publicly available generative-AI tools. ASD also points to data leakage, prompt injection, manipulated outputs and third-party-provider risk.

Then there is the human angle. Social-engineering messages can impersonate a colleague, executive, supplier or adviser to steal credentials, change bank details or trigger a payment.

In ASD’s FY2024–25 threat report, phishing appeared in 60% of incidents reported to it, and the average self-reported cost per business cybercrime report was $80,850. Those figures describe reports received by ASD; they are not a forecast for every business.

OAIC figures published in July 2026 show that 1,205 data breaches were notified during 2025, the highest calendar-year total since the Notifiable Data Breaches scheme began and 8% above 2024. Malicious or criminal activity accounted for 716 notifications. These are notifications received by the OAIC, not a measure of every Australian data breach.

Notification duties still sit with the business. If the Privacy Act 1988 covers an entity, an eligible data breach that is likely to cause serious harm may need to be notified to affected individuals and the OAIC under the Notifiable Data Breaches scheme. A cyber policy does not transfer that legal obligation to the insurer.

Ransomware payment reporting is now an active compliance issue. Since 30 May 2025, an Australian business with annual turnover above $3 million, or a responsible entity for certain critical infrastructure assets, may have to report a ransomware or cyber-extortion payment within 72 hours of making the payment or becoming aware that it was made on its behalf. The Department of Home Affairs moved to its compliance-and-education phase on 1 January 2026. Incident plans should identify who will preserve evidence, obtain legal advice and coordinate any required reports.

Connected products now have mandatory baseline standards. Most in-scope consumer smart devices manufactured on or after 4 March 2026 must meet requirements dealing with universal default passwords, vulnerability reporting and published security-support periods. Suppliers must also supply an in-scope product with a statement of compliance. For manufacturers, importers and suppliers, this connects cyber, products liability and product recall risk. Legal compliance and insurance response remain separate questions.

Another date to prepare for: from 10 December 2026, APP entities using personal information in automated decisions that could reasonably be expected to significantly affect an individual’s rights or interests will have new privacy-policy transparency obligations. The OAIC was developing guidance during 2026. Businesses using automated claims, credit, employment, eligibility or customer-risk decisions should review their systems and privacy wording before commencement.

A few practical habits can help:

  • Limit or anonymise data entered into AI tools.
  • Use multi-factor authentication.
  • Train staff to spot suspicious requests.
  • Verify payment-detail changes through a known, separate channel.
  • Keep an incident-response plan and test it.

Cyber insurance may be one part of the response, but it does not prevent an incident or replace security controls.

Cover for data-breach response, interruption, social engineering, invoice redirection and funds transfer varies and may be excluded or sub-limited. Check the wording, limits, excesses, waiting periods, security conditions and insurer acceptance.

Want to know what applies to your business?

Start with the operation, the contracts and the exposures. Then we can discuss what insurance information may matter.

Start a conversation