28 August 2026
Executive Summary
Cyber insurers are beginning to rethink how their policies respond when the damaging actor is not a hacker in the conventional sense, but an autonomous AI agent operating with legitimate access.
Insurers including MSIG, QBE and Beazley are reviewing how policy wording responds to autonomous AI risks as increasingly capable systems create new questions around responsibility, cyberattack definitions and liability. Specialist AI-related insurance products are also beginning to emerge.
Recent incidents and investigations have shown AI agents behaving unexpectedly and, in some cases, acting beyond intended limits. Separately, cybercriminals are increasingly using commercial AI tools to accelerate attacks; Reuters reported this week that Russian-speaking hackers used an AI coding assistant during intrusions affecting seven companies.
The insurance question is unusually difficult:
What happens when the system causing the loss was authorised to enter the network?
UK Impact
UK companies are rapidly deploying AI agents capable of:
- Accessing cloud platforms.
- Reading and sending email.
- Updating databases.
- Writing software.
- Handling customer information.
- Executing workflows.
- Managing financial processes.
- Interacting with operational systems.
Traditional cyber controls frequently assume that harmful activity originates with an unauthorised intruder.
Agentic AI complicates that assumption.
A company may intentionally give an AI system permission to:
- Access files.
- Alter records.
- Execute commands.
- Connect to external services.
If the AI then behaves unexpectedly, it may be unclear whether the resulting incident falls neatly within traditional definitions of:
- Cyberattack.
- System failure.
- Human error.
- Technology error.
- Professional liability.
Global Impact
Insurers are examining how coverage should respond where autonomous systems cause damage without conventional malicious intent.
Potential exposure can extend across:
- System failure.
- Business interruption.
- Contingent business interruption.
- Incident response.
- Data restoration.
- Privacy liability.
- Technology errors and omissions.
The global cyber-insurance market is already substantial and expected to continue expanding rapidly.
But insurers face a fundamental underwriting problem:
There is very little historical loss data for systems capable of independently planning and executing complex actions.
That makes both pricing and policy wording harder.
Our View
Businesses deploying AI agents should review insurance before those agents become operationally critical.
Companies should ask:
- What systems can our AI agents access?
- What actions can they execute without human approval?
- Are financial transactions included?
- Can agents alter or delete data?
- Does the cyber policy expressly contemplate AI-driven incidents?
- Would damage caused by an authorised AI agent be treated as a cyber event?
- Could technology E&O cover apply instead?
- Does the policy contain exclusions relevant to autonomous systems?
- Who approves high-risk AI actions?
- Are logs retained independently of the AI itself?
- Can access be revoked immediately?
- Are insurers aware of the organisation’s AI deployment?
Cyber insurance was built around the distinction between inside and outside the network.
AI agents blur that boundary.
The next coverage dispute may therefore not be about whether somebody hacked into the system.
It may be about what happened after the company deliberately let the system in.
Risk Indicator: ELEVATED – CYBER & INSURANCE
Does This Risk Affect Your Business?
Invictus Risk Solutions helps businesses find practical solutions to insurance, risk and commercial challenges.
From individual businesses to major international organisations, risk is our business.
TALK TO INVICTUS →Disclaimer
The information contained within these Market Alerts is provided for general market awareness and informational purposes only. It does not constitute financial, legal, investment, regulatory or insurance advice. Whilst every effort has been made to ensure accuracy at the time of publication using multiple reputable and independently verified sources, geopolitical events, legislation, regulation and market conditions may change rapidly. Readers should obtain appropriate professional advice before acting upon any information contained herein.
Invictus Risk Solutions LLP – Helping organisations stay ahead of emerging risks through informed insight and independent analysis.
