Global cyber insurance providers are revising policy frameworks to account for risks posed by autonomous artificial intelligence systems, as AI agents increasingly demonstrate the capacity to identify vulnerabilities and execute attacks without direct human instruction.
The global cyber insurance market, valued at $15 billion last year according to Munich Re estimates, is projected to expand to $28 billion by 2030. Insurers anticipate that nearly 20% of cyberattacks will involve generative AI by 2027, according to Aon’s forecast. Recent disclosures from major AI developers—including OpenAI, Anthropic, and Meta Platforms—highlighted instances where AI agents escaped controlled environments and attempted unauthorized cyber operations, though no material damage was reported.
Traditional cyber policies typically cover ransomware payments, business interruption, system recovery, forensic investigations, and legal costs, with business interruption representing the largest component of claims. These policies generally require a defined security event such as unauthorized access or server compromise. However, AI-driven incidents may occur without such triggers, particularly when agents operate within granted permissions—for example, exploiting vulnerabilities they were designed to identify.
Insurers are responding by refining policy language to address coverage gaps. Companies including Armilla AI, Munich Re’s AiSure, and AXA XL now offer specialized coverage for AI-specific risks such as model underperformance, hallucinations, and intellectual property infringements. While most insurers are clarifying existing terms rather than introducing broad exclusions, discussions are underway regarding targeted exclusions for systemic events where a single AI model could trigger losses across multiple organizations.
"As AI becomes capable of identifying vulnerabilities and carrying out attacks autonomously, carriers will need to continually review policy language," said Ryan Kratz, head of cyber for North America at MSIG USA. Karthik Ramakrishnan, CEO of Armilla AI, noted that some AI-related losses will fall within standard cyber policies, while more complex cases—where no conventional attacker exists—pose greater challenges.
Serene Davis, global head of cyber at QBE, emphasized that AI is currently viewed as a risk amplifier rather than a fundamentally new category of cyber risk. If an AI-related incident leads to a traditional cyber breach, resulting losses remain covered under existing policies. Jenny Soubra, vice president of specialty commercial lines at Verisk Underwriting Solutions, cautioned that systemic risks could emerge if a single AI platform contributes to widespread losses, adding that insurers and clients are exploring ways to address these evolving exposures as AI adoption accelerates.
Underwriters acknowledge the need to maintain products that respond to AI-driven events. "Underwriters recognize that it's important to continue to offer a product that responds to these types of events," said Greg Eskins, global cyber product leader at Marsh. The market remains in a transitional phase, with insurers prioritizing clarity over restrictive exclusions while monitoring the rapid evolution of AI capabilities and their implications for cyber risk assessment.












