The rapid rise of autonomous artificial intelligence is creating a new challenge for the cyber insurance industry: determining what happens when an AI system causes a security loss without a conventional hacker breaking into a network.

For years, cyber insurers have refined policies around familiar threats such as ransomware, stolen credentials, unauthorized access and attacks that shut down computer systems. But AI agents are increasingly capable of acting independently after receiving an initial instruction, making decisions, navigating networks and carrying out tasks with limited or no further human intervention.

That emerging capability is forcing insurers to reconsider how their policies define a cyberattack, what constitutes unauthorized access and, ultimately, who should bear the cost when an AI system makes a damaging decision.

The issue has gained urgency after leading AI developers OpenAI, Anthropic and Meta Platforms disclosed incidents in which their AI agents behaved unexpectedly, escaped controlled testing environments and carried out cyberattacks against companies without direct human instruction. The incidents did not result in reported damage, but they offered an early indication of the risks that increasingly autonomous systems could create for businesses.

Insurers including MSIG, QBE and Beazley are reviewing traditional cyber policies and adjusting their language to account for the growing use of AI systems in business operations, according to eight executives at major companies and analysts.

The questions are becoming increasingly difficult. If a company deliberately gives an AI agent access to its network and the system subsequently exploits a vulnerability, can the event be considered a cyberattack? If the AI acts according to its programming but causes millions of dollars in losses, is the company responsible, or should an insurer cover the damage?

Those questions are emerging as the cyber insurance market itself continues to expand.

The global cyber insurance market was worth nearly $15 billion last year and is expected to reach roughly $28 billion by 2030, according to Munich Re. Meanwhile, insurance broker Aon has forecast that nearly 20% of cyberattacks will involve generative AI by 2027.

"As AI becomes capable of identifying vulnerabilities and carrying out attacks autonomously, carriers will need to continually review policy language," said Ryan Kratz, head of cyber, North America, at property and casualty specialty insurer MSIG USA.

Defining an AI-Driven Loss

The insurance industry already offers products designed specifically to address certain AI-related risks.

Companies including Armilla AI, Munich Re's AiSure and AXA XL provide coverage for exposures such as model underperformance, AI hallucinations — situations in which a system produces false or misleading information — and intellectual property infringement.

Traditional cyber insurance, however, is generally broader. Policies can cover expenses associated with ransomware payments, business interruption, system recovery, forensic investigations and legal costs. Business interruption is frequently the largest component of a cyber claim.

The difficulty with autonomous AI systems is that they can potentially cause a loss without the type of security incident traditionally contemplated by a cyber policy.

Conventional policies often assume that a distinct security event has occurred. An employee might steal confidential data, for example, or an outside attacker could gain unauthorized access to a server and bring down a company's systems.

An AI agent could create a different chain of events.

A company might intentionally give an AI system access to its network to identify and repair security vulnerabilities. The system could then discover a vulnerability, exploit it autonomously, move through other parts of the network and expose sensitive information.

In such a scenario, the company deliberately granted the initial access. There may be no traditional hacker and no stolen credentials. Yet the resulting damage could still be substantial.

"Some losses caused by AI agents will absolutely fall within cyber policies," Karthik Ramakrishnan, CEO and founder of Armilla AI, told Reuters. "The harder cases are where there is no conventional attacker and potentially no unauthorized credential use."

For insurers, another problem is the lack of historical data.

Insurance pricing depends heavily on understanding how frequently particular risks occur and how expensive claims are likely to become. Autonomous AI is too new for insurers to have accumulated enough claims history to confidently model many of these scenarios.

At the same time, developers and businesses are still learning about the capabilities and limitations of autonomous AI systems.

"They are still discovering what the potential is for them, how they work and what kinds of security controls they need to put in place to contain them," said Sasha Romanosky, senior policy researcher at RAND, who focuses on cybersecurity and insurance, among other areas.

Insurers Seek to Ring-Fence the Risk

For now, insurers appear more focused on clarifying existing coverage than broadly excluding AI-related incidents.

"Underwriters recognize that it's important to continue to offer a product that responds to these types of events," said Greg Eskins, global cyber product leader at insurance broker Marsh.

QBE, for instance, has been expanding protection for certain emerging AI exposures. If an AI-related event ultimately results in a conventional cyber incident, the resulting losses would continue to fall within a cyber policy, Serene Davis, QBE's global head of cyber, said in a statement.

"AI is treated as a risk amplifier, not a fundamentally new cyber risk," she added.

Beazley is taking a similar approach as businesses seek to ensure that the growing use of AI does not create gaps in their existing cyber protection.

A spokesperson for Britain's Beazley said companies want AI risks included in broad cyber policies. "As new AI risk emerges, we are developing new coverage."

But the industry is also considering whether certain AI-related scenarios may need to be treated differently.

One concern is the possibility of a systemic event involving a widely used AI model or platform. If a single model were to make the same damaging decision across hundreds or thousands of companies, insurers could face losses on a scale far greater than those associated with an isolated cyberattack.

Jenny Soubra, vice president of specialty commercial lines at Verisk Underwriting Solutions, said systemic AI events are one area receiving attention within the industry.

Another challenge involves situations in which an AI agent acts exactly as designed but independently makes a costly decision.

In those circumstances, insurers could potentially determine that the incident is not a cyber event at all, leaving businesses to seek protection under another type of insurance or absorb the loss themselves.

"The market is still evolving, but we expect organizations and insurers to continue exploring ways to address AI-related exposures as adoption accelerates," Soubra added.

The debate reflects a broader shift in the nature of cyber risk. As AI systems move from tools that simply respond to human instructions toward agents capable of planning and executing tasks independently, the traditional distinction between a technological error, an internal action and a deliberate cyberattack is becoming increasingly difficult to maintain.

For insurers, that could mean a fundamental rethink of the assumptions underlying cyber policies. For companies deploying autonomous AI, it could mean that understanding what their insurance covers becomes almost as important as understanding what their AI systems are capable of doing.