The emergence of agentic AI and frontier models has led to widespread uncertainty for policyholders.
As the cyber insurance industry has worked to regain momentum against a rising wave of cyber risk, the rapid emergence of AI has put increased pressure on determining whether the sector could afford to cover potentially billions in losses from a catastrophic event.
After months of uncertainty, Beazley, a leading specialist in the cyber sector, on Thursdayconfirmed it would provide “AI-afffirmative cover,” meaning it would cover losses stemming from an incident, even if the attacker utilized artificial intelligence.
For years the insurance industry has been mostly noncommittal on how it would handle AI-based cyberattacks, and there are a wide range of AI-related disputes currently winding through the court system in the U.S. and other parts of the world.
The insurance industry has largely been silent on how it will address AI-related risks, leaving a great deal of uncertainty across multiple industries — including cyber — about whether losses will be covered,according to a report released Wednesdayfrom Rand.
“There is an emerging story about whether this just adds to existing risks in insurance lines or whether it creates new risks,” said Sasha Romanosky, a senior policy researcher at Rand and co-author of the report.
Silent coverage rules
As concerns have risen about the growing risk of AI-enabled attacks and the use of frontier AI, insurance providers are beginning to provide insight into how they are addressing specific AI-related risks.
The Financial Times in April reported that some insurance firms, including Beazley, were looking to cap payouts for certain AI-related losses.
QBE, a major provider of cyber insurance across the globe, says, in contrast to prior reports, it remains committed to providing coverage for AI-related claims.
“We are continuing to support coverage for cyber risks and claims arising out of AI, not retreating from them,” Serene Davis, global head of cyber at QBE Insurance, told Cybersecurity Dive. “AI is treated as a risk amplifier, not a fundamentally new cyber risk.”
Under the company’s core cyber policies, the insurer covers losses from system compromise or data breaches in the same manner, whether or not AI is involved in the incident.
Contrary to earlier reports, AIG says it has no immediate plans to limit coverage for AI-related claims. The company told Cybersecurity Dive that one of its subsidiaries filed a response to the Insurance Services Offices, which is an industry office that interacts with state insurance policy regulators across the U.S.
AIG said even though the General Liability policy update from ISO includes GenAI exclusions, the company is “not specifically seeking to use or implement any of these exclusions at this time.”
Some of the competitive pressure on the insurance sector is coming from so-called InsureTechs, which are mostly Silicon Valley–backed startup firms that use AI, machine learning and low overhead expenses to bypass traditional insurance firms in the same way fintechs are bypassing traditional banks.
Boxx Insurance, a subsidiary of Zurich Insurance, says its cyber policies have consistently covered losses from social-engineering attacks and failures to secure an insured’s computer network. As concerns grew around AI-related attacks, the company added coverage for AI-driven social-engineering attacks and security failures global head of underwriting at Boxx
Frontier AI threat
The uncertainty around AI-related coverage has created a great deal of concern in the security industry. Criminal and state-linked hackers are increasingly using AI to accelerate and scale attacks beyond the ability of current technologies to track them. If policyholders don’t have clarity on whether they will have full insurance coverage, they may have to take additional measures to protect their systems from disruption and future liability.
“As organizations accelerate AI adoption and threat actors use AI to increase the speed and scale of their attacks, organizations are looking for greater clarity around how these risks are assessed and managed,” says Kevin Kiser, senior director of strategy for insurance solutions at Arctic Wolf.
Filed Under:Strategy,Vulnerability,Threats
