Skip to Content

When risk outgrows cover: the biggest insurance gaps for Australian tech in 2026

The Forerunner Report — Technology  | Where tech ambition meets real-world risk.

A critical briefing on the technology risks that have moved faster than the policies meant to cover them. Developed for founders, CFOs and technology leaders at Australian technology, Software-as-a-Service (SaaS) and platform businesses. 

Where policies fall behind

AI is already making decisions inside your business. Regulators are testing who’s accountable for them. And those decisions are showing up in the claims system. Many policies were written for human error, not automated decisions, not risk that moves in real time. That gap isn’t theoretical. It’s the difference between the businesses that see it coming and the ones that find out at claim time.

Insights and analysis from Knightcorp’s technology risk research and what you need to stay ahead. Plus, a free Risk Debrief one step away.

Book a Free Risk Debrief

A free, senior-led session to see your exposure clearly and check it against your cover.

  • 84,700

    CYBERCRIME REPORTS FILED NATIONALLY

    ACSC Cyber Threat Report 2024

  • $80,850

    AVERAGE BUSINESS LOSS (UP ~50% YOY)

    ACSC Cyber Threat Report 2024

  • 1 in 4

    AUSTRALIAN BUSINESSES REPORT AI-LINKED CYBER INCIDENTS

    QBE, 2026

  • 40%

    GOVERNANCE FAILURES ARE LINKED TO 40% OF MISCONDUCT REPORT ISSUES REPORTED BY ASIC

    ASIC, 2026

Three shifts your cover wasn’t built for

A programme you renewed in good faith twelve months ago may already be behind: technically valid, and still not built to respond. Triple‑extortion ransomware and deep platform dependency are now driving some of the most expensive declined claims, especially where cyber, tech E&O and business interruption don’t cleanly meet.

AI has entered the claims system.

Automated decisions are increasingly assessed as operational risk, rather than insured error. Many businesses only discover the loss sits outside their programme when a claim is declined.

Ai entered

ESG is now a directors and officers (D&O) question.

Public ESG statements are being read as legal commitments, and it's directors personally, not just the company, who can be left carrying them.

ESG is now Director's

Connected Systems.svg

When platforms and vendors are wired together, and something breaks, the claim can fall between providers, and cover may not respond.

Connected Systems

The Forerunner Matrix

Not all risk is equal. Many leaders misallocate attention because they don’t separate how likely something is, how hard it hits, and whether it’s actually insurable. The Forerunner Matrix does. Here are the top three exposures for technology businesses right now, and the gap between how you see each one and how your insurer does.

Find the full matrix in the Forerunner Report.

We help you spot the exposures that matter, weigh your options, and know what to fix first. 

Book a Free Risk Debrief

During this no-obligation 45 minute expert-led session, we’ll run the full matrix against your actual program.

RiskLikelihoodImpactForerunner Index*PriorityNotes
AI / Automation ErrorMediumHight3.5/10CRITICALEmerging claims unclear policy fit
Cloud MisconfigurationHighHigh6/10CRITICALCoverage may be affected where third-party SaaS is not declared.
ESG MisstatementMediumMedium4/10RISINGD&O coverage considerations emerging around “greenwashing”

Forerunner Index: Scored by Knightcorp's placement team against the factors that shape insurer appetite and terms. A higher score points to a stronger position.

Placement, pricing and terms always come down to the insurer, market appetite and your specific risk profile.

When AI decisions become claims

A documented market case — not a hypothetical.

This is one of several real cases examined in the Forerunner Report.  

·  Sector: media / technology 
·  Year: 2025  
·   Exposure: AI-assisted editorial/ content liability

How exposed is your business today?

Three questions. Answer them honestly — the gaps tend to show up fast.

1.  Could you name every critical vendor and cloud platform your business runs on right now, without checking? If not, that’s a disclosure gap, and a failure involving an undeclared platform may sit outside cover.

2.  Has your use of AI been formally disclosed to your insurer, or does your policy just not mention it? Silence isn’t neutral. It can leave your AI exposure entirely outside the policy.

3.  If a regulator asked your board to substantiate your last ESG statement, line by line, could you, quickly? If not, your directors and officers (D&O) exposure may be larger than it looks.

That’s the first three.  If any of them gave you pause, you don't need to wait for renewal to find out how exposed you are — that's exactly what a Risk Debrief is for.

How exposed is your business today?

For a business like SafetyCulture, where we’re really scaling rapidly, having Knightcorp as a partner enables us to have an insurance portfolio that can scale with us.

Lara BakerSenior Corporate CounselMitti by SafetyCulture mitti

In the last 12 months they increased our coverages and lowered our premiums.

Joshua RossCo-founderHumanitix logo_Humanitix

We’re living through a generational change in technology. The risk of not acting is a real risk... Knightcorp spent the time to understand our unique needs and built insurance solutions to fit our business.

Alex BadranCo-FounderSpriggy (FinTech)sprruggy

Take the next step

You’ve seen where the market has moved. The real question is whether your cover has, and that gap doesn't wait for your renewal to show up. 

Book a Free Risk Debrief

A no-cost, senior-led session to see your exposure clearly and check it against your cover.

Take the next step

Most brokers cover where you've been. We cover where you're going.

That’s the forerunner’s edge.

FREQUENTLY ASKED QUESTIONS

  1. Whether your cyber insurance responds to an AI-related claim depends on the policy’s terms, conditions and exclusions and the circumstances of the claim. It’s worth reviewing your cover against how your business uses AI, including whether some exposures fall under other policies.

    In practice, that cover is often narrower than expected, and the position keeps shifting. Whether an AI-related loss is covered depends heavily on your specific policy wording, exclusions and the circumstances of the claim, and the market hasn't settled where AI liability sits: some claims fall between cyber, professional indemnity / technology errors and omissions (Tech E&O), and directors and officers (D&O) cover. Insurers are increasingly turning their attention to AI-specific exclusions, so it's the wording — not the age of the policy — that determines whether it responds to an AI-related claim. If AI is making or shaping decisions in your business, it's worth confirming in writing how your programme treats it.

  2. Most technology and Software-as-a-Service (SaaS) businesses build their programme around a few core covers: technology errors and omissions (Tech E&O) / professional indemnity (PI) for software-failure and service claims, cyber for breaches and privacy, and directors and officers (D&O) for leadership decisions — with general liability, property and employment practices cover alongside. The right structure depends on your contracts, data footprint and growth stage; enterprise customer agreements and investors often dictate specific covers and limits.

  3. Broadly, technology errors and omissions (Tech E&O) responds to claims that your product or service failed to perform — a bug, an outage, or a missed service-level commitment that causes a client financial loss. Cyber insurance responds to security and privacy events — a breach, ransomware, data exposure and the response costs that follow. Many incidents touch both at once, which is exactly where gaps and overlaps appear if the two aren’t read together. 

  4. Declined claims tend to cluster around a few recurring issues rather than bad luck: exposures involving vendors, cloud or AI services that were never declared to the insurer; AI use that’s assumed to be covered but isn’t named in the wording; and mismatches between what was disclosed at underwriting and what the business actually does. The pattern is usually a disclosure-and-controls gap — not a single dramatic failure.

  5. Increasingly, yes — and it’s a live enforcement area in Australia. Public ESG and sustainability claims can be assessed under the same misleading-and-deceptive-conduct principles as any other statement, and voluntary statements made outside formal reporting don’t attract the transitional protections that apply to parts of mandatory climate reporting. Whether directors and officers (D&O) cover responds depends on the wording and the nature of the claim. 

  6. There's no universal D&O number. The right limit depends on your funding, business activities, financial position, investor requirements and potential claims exposure. Funding rounds and new investors are usually what force the question.

General information only, current as at August 2026. It doesn’t take into account your circumstances and isn’t a substitute for advice on your specific programme. Any cover is subject to policy terms, conditions and insurer approval.