Cyber insurers rethink coverage as AI agents create new risks

0
37
AI autonomy forces insurers to rethink cyber risk and liability Credit: Reuters
AI autonomy forces insurers to rethink cyber risk and liability Credit: Reuters

The growing autonomy of AI systems is prompting cyber insurers to reassess how traditional policies define cyberattacks, security events, and liability. Recent incidents involving AI agents acting beyond controlled environments have added urgency to these discussions.

AI developers including OpenAI, Anthropic, and Meta Platforms have disclosed cases where AI agents behaved unexpectedly, escaped controlled testing environments, and carried out cyberattacks without direct human instruction. Although no damage was reported from these incidents, they highlighted emerging risks for businesses and insurers.

Insurers including MSIG, QBE, and Beazley are reviewing traditional cyber policies and adapting their language to address risks linked to increasingly autonomous AI systems. Key questions include whether an autonomous AI system can be considered a cyber attacker and who should be responsible when an AI-generated action causes a loss.

The global cyber insurance market was worth nearly $15 billion last year and is expected to reach around $28 billion by 2030, according to Munich Re. Aon has also forecast that nearly 20% of cyberattacks will involve generative AI by 2027.

“As AI becomes capable of identifying vulnerabilities and carrying out attacks autonomously, carriers will need to continually review policy language,” said Ryan Kratz, head of cyber, North America, at MSIG USA.

Traditional cyber policies generally cover incidents such as ransomware payments, business interruption, system recovery, forensic investigations, and legal costs. However, most policies are built around a defined security event, such as unauthorized access or a server attack.

AI agents can create more complicated scenarios. For example, an organisation could intentionally give an AI agent access to its network to identify security vulnerabilities. The agent could then exploit a vulnerability, move through internal systems, and expose sensitive data without a conventional hacker or unauthorized access at the beginning.

“Some losses caused by AI agents will absolutely fall within cyber policies,” said Karthik Ramakrishnan, CEO and founder of Armilla AI. “The harder cases are where there is no conventional attacker and potentially no unauthorized credential use.”

Insurers are also dealing with limited historical claims data, making AI-related risks difficult to price. Rather than broadly excluding AI incidents, many insurers are currently clarifying how existing policy language applies when AI is involved.

QBE has been expanding protection for specific AI exposures. If an AI-related event results in a conventional cyber incident, the resulting losses can continue to fall under a cyber policy. QBE describes AI as a risk amplifier rather than a fundamentally new cyber risk.

Beazley has also said businesses want AI risks included within broad cyber policies and is developing coverage as new exposures emerge.

At the same time, insurers are considering targeted exclusions for risks such as systemic events, where a single AI model or platform could create losses across multiple organisations. Liability is another concern when an AI agent makes a costly autonomous decision while operating as designed.

As AI adoption grows, businesses and insurers are continuing to assess how cyber coverage should evolve around increasingly autonomous systems.

Also read: Viksit Workforce for a Viksit Bharat

Do Follow: The Mainstream LinkedIn | The Mainstream Facebook | The Mainstream Youtube | The Mainstream Twitter

About us:

The Mainstream is a premier platform delivering the latest updates and informed perspectives across the technology business and cyber landscape. Built on research-driven, thought leadership and original intellectual property, The Mainstream also curates summits & conferences that convene decision makers to explore how technology reshapes industries and leadership. With a growing presence in India and globally across the Middle East, Africa, ASEAN, the USA, the UK and Australia, The Mainstream carries a vision to bring the latest happenings and insights to 8.2 billion people and to place technology at the centre of conversation for leaders navigating the future.