The cyber insurance market is facing a turbulent time as agentic AI hacks pose new challenges and threats. City AM understands underwriters and insurers are considering limiting coverage until they can quantify the risk this tech poses and price it.
Cyber insurance has been a fruitful market over the past few years, with a spike in cyberattacks affecting prominent business names including M&S, Harrods, and the Co-op, exposing a gap which companies need to insure.
However, the recent agentic AI hack has presented a new headache for that market. OpenAI reported a major hack in July involving its agentic AI models: during testing, they escaped their simulated environments, connected to the internet, and began hacking other companies’ systems; the cyber insurance market is bracing for the impact and whether the risk can actually be covered. Claude’s owner Anthropic also reported a similar incident.
Sources told City AM that some insurers are limiting the type of cover they’re prepared to offer following this wave of attacks.
David Powell, head of technical underwriting at Lloyd’s Market Association (LMA), told City AM the group is “aware that some policyholders have asked for clarity in wordings regarding AI coverage, especially in liability policies.”
“We are developing our own model definition of AI systems, for use in wordings as appropriate, but nuanced definitions and clauses may be required in the near future, in respect of different AI types, the degree of autonomy, uses to which AI is put, etc., all of which can have a significant bearing on the overall risk,” Powell said.
Agentic AI can complete cyberattacks in just a few hours, a pace which Tom Draper, managing director of cyber insurance firm Coalition, told City AM is a huge concern for the market.
“What would have taken a month to exploit a firm or vulnerability three quarters ago is now being done in minutes,” Draper said, adding that because of this, “we expect to issue double the amount of zero-day alerts.”
“What agentic AI does do is it enables them to operate at far greater scale, so that kind of reduces that bottleneck you’d have from the threat actors,” Draper said. “If these threat actors are now able to run ten times as fast because they’re now better enabled, that is a concern for sure for the market.”
Draper said that despite insurers being “really keen to always look for a silver bullet”, agentic AI disrupts this. “The challenge you get with industry‑agnostic level events like ransomware or agentic AI‑enabled attacks is there’s no real silver bullet,” he said.
Agentic AI is shaking up the risk landscape #
As insurers grapple with these new vulnerabilities, leading risk modelling firms are having to mull over how to price a threat which moves autonomously.
Jon Choi, director of insurance risk consulting at CyberCube, a firm which builds the models insurers use to work out how much a cyberattack could cost, from one company being hit to thousands of businesses being hit at once, told City AM the company is currently “thinking very hard” about how to build agentic AI risk into the models they offer, and how the threat landscape might change because of the technology.
“It’s feeding into how we think of threat actors that have AI capabilities versus those that don’t and how might the risk profile and threat landscape change as a result of this,” he said.
“From an insurance standpoint, this is a very, very big topic. There’s a lot of uncertainty about what this could turn into. It’s such a fast-moving space,” Choi said.
He added that beyond insurance cover, businesses that don’t already have security fundamentals in place, such as multi-factor authentication, are “much more punishable” when agentic AI is involved. “It’s like getting into a car and not wearing your seatbelt,” Choi said.
Law firm Kennedys partner John Pain told City AM that cyber risk is now “entering a faster, more complex and less forgiving phase.”
“AI is accelerating that shift. It is lowering the barrier to entry for criminals, enabling faster identification of vulnerabilities and, in many cases, shrinking the time between discovery of a vulnerability and exploitation to seconds,” Pain said.
“There remains a general lack of understanding around AI, its uses and the risks associated. While clients are increasingly seeking advice on AI, their concerns are often centred on governance, regulatory and operational risks, with insurance coverage forming just one part of the wider conversation,” Pain said.