Cyber insurers revise policies as autonomous AI agents create new risks

Photo: Towfiqu barbhuiya / Pexels

Cyber insurers revise policies as autonomous AI agents create new risks

Insurers are weighing liability and coverage for AI systems that can act without direct human instruction and trigger losses without a conventional hack.

Cyber insurers are reviewing traditional policies as autonomous artificial intelligence agents create new questions about what constitutes a hack and when coverage should apply.

OpenAI, Anthropic and Meta recently disclosed that AI agents behaved unexpectedly, escaped controlled test environments and carried out cyberattacks without direct human instruction. 

The incidents caused no reported damage but highlighted emerging risks for companies and insurers.

Advertisement

Insurers including MSIG, QBE and Beazley are adapting policy language, according to executives and analysts cited by Reuters. They are assessing whether an autonomous AI system can fit the definition of a cyber attacker and who is liable when its actions cause a loss.

The global cyber-insurance market was worth nearly $15 billion last year and could reach about $28 billion by 2030, according to Munich Re. Aon forecasts that generative AI will be involved in nearly 20% of cyberattacks by 2027.

Traditional cyber policies generally cover events such as ransomware, business interruption, system recovery and legal costs after unauthorized access or a server attack. AI agents could cause losses while using access that a company deliberately granted them.

Insurers are mostly clarifying how existing language applies rather than adding exclusions. 

QBE said losses from an AI-related event that becomes a conventional cyber incident would continue to fall within its cyber coverage, while specialized policies are emerging for risks such as hallucinations, model underperformance and intellectual-property infringement.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
Cyber insurers revise policies as autonomous AI agents create new risks
Cyber insurers revise policies as autonomous AI agents create new risks

Insurers are weighing liability and coverage for AI systems that can act without direct human instruction and trigger losses without a conventional hack.

Share

Add us on Google

Photo: Towfiqu barbhuiya / Pexels

Cyber insurers are reviewing traditional policies as autonomous artificial intelligence agents create new questions about what constitutes a hack and when coverage should apply.

OpenAI, Anthropic and Meta recently disclosed that AI agents behaved unexpectedly, escaped controlled test environments and carried out cyberattacks without direct human instruction. 

The incidents caused no reported damage but highlighted emerging risks for companies and insurers.

Advertisement

Insurers including MSIG, QBE and Beazley are adapting policy language, according to executives and analysts cited by Reuters. They are assessing whether an autonomous AI system can fit the definition of a cyber attacker and who is liable when its actions cause a loss.

The global cyber-insurance market was worth nearly $15 billion last year and could reach about $28 billion by 2030, according to Munich Re. Aon forecasts that generative AI will be involved in nearly 20% of cyberattacks by 2027.

Traditional cyber policies generally cover events such as ransomware, business interruption, system recovery and legal costs after unauthorized access or a server attack. AI agents could cause losses while using access that a company deliberately granted them.

Insurers are mostly clarifying how existing language applies rather than adding exclusions. 

QBE said losses from an AI-related event that becomes a conventional cyber incident would continue to fall within its cyber coverage, while specialized policies are emerging for risks such as hallucinations, model underperformance and intellectual-property infringement.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.