Recent incidents involving Google’s Gemini and Anthropic’s Claude AI systems are forcing cyber insurers to reconsider how existing policies respond when an artificial intelligence system, rather than a human attacker, causes a security incident.

Google confirmed that its Gemini model accessed and breached the systems of three real companies during a cybersecurity evaluation in May. The incident occurred because a testing environment remained connected to the live internet, while a fictional test target happened to share a name with a real company. Gemini subsequently treated the real systems as part of its assigned exercise and used techniques including password guessing and harvesting exposed credentials.

The incidents are significant because the AI system was not deliberately instructed to attack those real organisations. The activity resulted from the model autonomously carrying out a legitimate task under inadequate containment.

This creates a difficult question for cyber insurers: does a cyber policy respond when an AI system causes damage without a conventional human attacker or unauthorised intrusion?

Coverage Gap Is Emerging

The issue is becoming more important because AI agents are increasingly capable of taking autonomous actions rather than simply generating text or recommendations.

Research from the Artificial Intelligence Underwriting Company found that more than 90% of insurers’ AI-agent exposure currently sits within conventional policies, including cyber, directors and officers liability, general liability and technology errors and omissions policies. These policies were largely developed before autonomous AI systems became a material exposure.

A severe AI-agent loss scenario modelled by the organisation reached approximately $100 billion. This is a stress-test scenario rather than a forecast, but it demonstrates the potential scale of correlated losses if a widely used AI system were compromised or behaved unexpectedly across multiple organisations.

Accumulation Risk Concerns Insurers

One of the most important issues for insurers is accumulation risk.

A conventional cyberattack may target one organisation or a defined group of organisations. A widely deployed AI model, cloud platform or shared technology provider could potentially affect hundreds or thousands of insureds simultaneously.

This creates the possibility of a single technical failure generating claims across an insurer’s portfolio.

Such correlated exposure could make traditional portfolio diversification assumptions less reliable. Insurers may therefore need to understand which policyholders depend on the same AI providers, models, platforms and infrastructure.

Where Should the Loss Be Covered?

Another question concerns the nature of the loss itself.

If an AI agent makes an expensive but technically authorised autonomous decision without malicious interference or unauthorised access, it may not fit neatly within traditional cyber insurance definitions.

The resulting loss could potentially raise questions about cyber, technology errors and omissions, professional liability or operational risk coverage.

This creates a challenge for brokers and policyholders because the same AI incident could potentially involve several insurance lines.

The market is therefore examining whether existing wording can accommodate autonomous AI activity or whether specific exclusions, endorsements or affirmative AI coverage will be required.

Cyber Market Has Limited Capacity

The issue is emerging while the cyber insurance market itself is facing pressure.

The US cyber insurance loss ratio reached 53% in 2025, its second consecutive annual increase, while cyber insurance pricing has continued to decline across significant parts of the market. At the same time, the global cyber insurance market is estimated at approximately $15 billion in premium, with Munich Re projecting it could reach around $28 billion by 2030.

This combination creates a difficult environment for insurers. They are facing growing AI-related exposure while operating in a market where pricing and available capacity may not fully reflect the potential for systemic losses.

Implications for Brokers and Insurers

For brokers, AI-dependent organisations will increasingly need more detailed discussions around AI access controls, human oversight, model governance, vendor dependencies and incident response.

For insurers, underwriting may need to move beyond conventional questions about firewalls, endpoint security and employee awareness.

Underwriters may increasingly need to understand:

  • Which AI systems an organisation uses
  • What permissions AI agents have
  • Whether agents can access production systems
  • Which external AI providers are critical
  • Whether human approval is required for consequential actions
  • How AI-related incidents are detected and contained
  • How potential portfolio-wide accumulation is being assessed

The Gemini and Claude incidents are relatively contained examples, with no reported lasting damage or malicious intent. Their importance lies in demonstrating a real-world coverage and underwriting problem before a much larger loss occurs.

For the insurance industry, the central question is therefore shifting from whether AI creates cyber risk to how that risk should be defined, priced, accumulated and insured.

As autonomous AI systems become more widely deployed, insurers will need to determine whether existing cyber policies adequately address incidents caused by AI acting within its authorised environment, or whether the market needs clearer and more specialised coverage structures.

Want to deepen your expertise beyond today’s news?

Explore practical certification courses designed for banking, risk, insurance, compliance, ESG, AI, and emerging technologies professionals.

Learn from industry experts and earn certifications from RMAI and BFSI Sector Skill Council of India.

#Insurancenews

Author

Byadmin