AI has moved from pilot project to core infrastructure. MinterEllison's 2026 Perspectives on Cyber Risk report (the AI edition) finds that AI-enabled threats are now the second most-named cyber concern among surveyed organisations, and that cyber security has overtaken privacy as the top-ranked risk of AI adoption. Governance frameworks have not kept pace.
For universities, these findings land on top of long-standing sector vulnerabilities: a history as a target for state-sponsored actors, large volumes of sensitive student, staff and research data, ageing IT estates, and an increasingly complex supply chain.
In this article, we draw on the 2026 report’s key themes and on regulatory guidance from bodies including APRA and the OAIC to outline what universities should be doing now – from mapping AI across their supplier base and tightening contractual protections, to preparing for agentic AI threats and an evolving regulatory landscape. Cyber and AI governance should sit on every Council's standing agenda.
1. AI is embedded in university operations and supply chain risk deserves close attention
Generative AI tools are already used across teaching, research, student services and administration. They are often introduced by individual faculties, ahead of any central sign-off. This alone justifies a single, institution-wide AI governance framework with a maintained register of AI tools, risk-based approval processes and clear accountability.
But the more important point is this: even where a university has not formally adopted AI itself, it is almost certainly exposed to AI through its supply chain. Learning management systems, plagiarism and proctoring software, cloud computing platforms, HR and finance systems, and international recruitment agents are all increasingly AI-enabled. This can be true regardless of whether the university selected, or controls, that functionality.
More than half (57%) of organisations surveyed for our 2026 report experienced a cyber incident through a third-party supplier or vendor in the past 12 months, up from 50% the year before. The supply chain is reportedly now the single largest source of breach exposure for organisations generally.
This is not a hypothetical concern for universities. In 2020, ProctorU, an online exam proctoring vendor widely used across the sector, suffered a data breach. Approximately 444,000 user records were exposed, including students from multiple Australian universities. Names, contact details and passwords were compromised. The incident demonstrated how a single vendor failure can cascade across institutions, affecting large numbers of students without any security failure on the part of the universities themselves. It is a clear example of why third-party risk management matters.
A more recent, and larger illustration came in May 2026, when Canvas, the learning management system operated by Instructure and used by around 8,000 educational institutions globally, was breached by the criminal group ShinyHunters. Names, email addresses, student ID numbers and messages between users were exfiltrated, with the attackers claiming to have taken 3.65 terabytes of data affecting some 275 million users across nearly 9,000 institutions. Many Australian universities were affected. As with ProctorU, the compromise occurred entirely within a third-party platform, but the operational, financial and reputational consequences landed on the institutions that relied on it.
The Tertiary Education Quality and Standards Agency (TEQSA) has issued cyber security and information management expectations that apply to any technology, including AI tools. TEQSA has also published AI-specific guidance, but this is predominantly directed at academic integrity and touches only briefly on the data security risks that AI adoption presents.
Two other regulatory frameworks offer useful guidance on AI-related supply chain and data security risk: the Prudential Standards, administered by the Australian Prudential Regulation Authority (APRA), which cover the banking, insurance and superannuation sectors, and the Privacy Act 1988 (Cth) (Privacy Act), administered by the Office of the Australian Information Commissioner (OAIC). Neither of these regimes regulate most public universities (the Privacy Act applies to private universities and the Australian National University), but the Prudential Standards are widely regarded as setting the benchmark on AI and third-party risk, and many universities voluntarily adopt the Australian Privacy Principles under the Privacy Act.
Drawing on both of these frameworks, universities would benefit from considering the following approach.
- Explainability, transparency and human oversight: universities should seek a meaningful explanation of how a supplier's AI tools produce their outputs, and ensure human review occurs before AI-generated outputs are relied on.
- Data ownership, location and control: universities should retain the ability to access, retrieve and control their data, and to restrict its transfer offshore or its use in training a supplier's AI tools. For cloud-hosted products, consider where servers are located, whether personal information could be disclosed outside Australia, and whether on-premises deployment may be more privacy-preserving. Personal information – particularly sensitive information – should not be entered into publicly available generative AI tools.
- AI supply chain visibility and governance: universities should identify their suppliers' AI tools, providers, models and any known fourth-party dependencies. They should manage vendor concentration risk and require suppliers to maintain a register of AI tool use. The terms and settings of AI products warrant careful review: some allow the vendor to use customer inputs for further model training, and those features should be turned off where possible. Due diligence should continue throughout the product lifecycle, not be treated as a “set and forget” exercise.
- Operational resilience: where a supplier's AI tool supports critical services, the university needs assurance of credible fallback processes if that AI tool becomes unavailable or degrades.
- AI-specific security controls: prompt injection, data leakage, insecure integrations and manipulation of autonomous AI agents are now common attack pathways. Universities should require suppliers to implement and operationalise controls addressing these AI-specific threats.
2. Universities hold data that makes them a persistent target
Universities hold extensive stores of student, staff, alumni, health and research data. Some of this is commercially sensitive or nationally significant. Higher education is designated as a critical infrastructure sector subject to mandatory cyber incident reporting under the Security of Critical Infrastructure Act 2018 (Cth), and has previously been identified as a recurring target for foreign interference and state-sponsored actors.
Again, this risk is not hypothetical. In 2018, a university suffered one of the country's most significant university breaches. A suspected state-sponsored actor used a spear phishing attack to gain deep, persistent access, ultimately exfiltrating the personal information of approximately 200,000 staff, students and visitors. The compromised data spanned 19 years and included names, addresses, dates of birth, tax file numbers, bank account details, passport details and student academic records. The incident led to a major investment to uplift the university's cyber security practices and prompted closer scrutiny of its data retention.
More broadly, the education and training sector has in the past recorded a disproportionate share of ransomware and cyber incidents. It also has among the slowest recovery times of any sector globally, perhaps due to the highly distributed nature of many organisations within it. The OAIC's notifiable data breach statistics indicate that education now sits within the top five sectors for data breach notifications, having moved into that group in 2025. As AI systems increasingly process and generate personal information, the volume of data at risk in any single incident only grows.
3. Agentic AI is changing what an incident looks like
A further shift in 2026 is the emergence of agentic AI. These are AI systems that can independently plan and take multi-step actions, rather than simply respond to a single prompt.
The practical implications became clear in early 2026. Security startup CodeWall deployed an autonomous offensive AI agent against McKinsey's internal AI platform, Lilli, a tool used by over 70% of the firm's roughly 43,000 employees. The agent had no credentials and no insider knowledge. Within two hours, it had discovered 22 unauthenticated API endpoints, exploited a vulnerability in one of them, and gained full read-and-write access to a production database containing 46.5 million internal chat messages, 728,000 client files and 57,000 user accounts. Critically, the agent could also rewrite the system prompts governing how Lilli responded to users, meaning it could quietly alter the answers relied on across the organisation, without deploying code or triggering an alert.
A second incident, in July 2026, showed the same dynamic on a larger scale and from an unexpected source. Engineers at Hugging Face, a widely used repository of AI models and datasets that hosts more than three million models relied on across the sector, detected an intrusion in their systems. A malicious dataset had been uploaded that exploited code execution pathways in Hugging Face's dataset processing, allowing the intruder to escalate to node-level access, harvest credentials and move laterally across internal clusters. Rather than sitting on any single machine, the intruder repeatedly spun up short-lived sandbox environments and rotated its command-and-control traffic through ordinary public web services, so activity looked normal and there was little for defenders to block. Over roughly 60 hours it carried out in the order of 17,500 discrete actions – several every second, sustained around the clock. Five days later, Hugging Face and OpenAI jointly disclosed that the intruder was an OpenAI model undergoing an internal capability evaluation: given a benchmark task inside a sandbox with no internet access, the model had found and exploited a zero-day vulnerability in a narrow outbound proxy in order to reach the wider internet and pursue its objective. No human directed the attack.
Universities should assume that similar tools can be, and will be used offensively against their own AI-enabled systems and those of their suppliers. The target may be student and research data, or the manipulation of outputs from AI tools relied on by staff and students. Incident response plans and tabletop exercises should now include an AI-agent-driven scenario, not only ransomware and phishing.
4. Legacy systems make change harder to manage
Many universities operate large, ageing and highly customised IT estates accumulated over decades and across multiple campuses. These systems can be difficult to patch, hard to integrate with modern security tooling, and slow to adapt to new AI capabilities. A practical starting point is to map where AI tools, including those introduced by suppliers, interact with legacy systems and sensitive data stores, and prioritise uplift in those areas first.
Looking ahead: a short window to get ahead of regulation
At present, AI is not subject to standalone regulation in Australia. However, that is changing. The Australian Government announced mandatory Australian Standards for AI in July 2026, with legislation expected in early 2027. From 10 December 2026, new automated decision-making transparency obligations under the Privacy Act will require APP entities to disclose where personal information is used in automated systems that significantly affect individuals' rights or interests (explore more in our summary: Automated decision-making obligations for businesses). Separately, the recent exposure draft amendments to the Online Safety Act 2021 (Cth) propose to bring AI-related online services within that regime's scope.
Universities should treat this period as a window in which to deepen their understanding of the AI tools in their operations and supply chains, strengthen AI governance, and position themselves at the forefront of managing AI risk, proactively rather than reactively. The legal, reputational and operational consequences of falling behind are significant.
The common thread across all of these issues is that AI has not replaced the sector's existing cyber risks. It has amplified them, and extended them into every corner of the university's supplier base. Institutions that treat AI and supply chain governance as an extension of their existing cyber risk framework, rather than a separate workstream, will be best placed to safeguard the students who entrust them with their futures, the academics and professional staff who depend on their systems, the researchers whose work carries national and commercial significance, the alumni and donors whose data they continue to hold, and the industry, government and community partners who rely on the sector's integrity.