AI exclusions creep into cyber cover as insurers redraw the line

The investment management industry’s embrace of AI has never been broader, with firms deploying the technology to summarise research, monitor threats, automate workflows and harden cyber defences.

Yet as adoption accelerates, so too do the risks, from autonomous systems straying beyond their intended remit to AI-generated errors, generative AI-powered attacks and murky questions of accountability when things go wrong, said ACA Group.

ACA Group recently discussed how AI is changing the rules of cyber insurance and what it means for the industry. 

That uncertainty is now filtering through to the cyber insurance market. Some carriers are tightening policy wording and introducing AI-related exclusions where risk is deemed too difficult to quantify, while others are dangling discounts for firms that use AI defensively. For investment managers renewing cover in 2026, asking “is AI covered?” is no longer sufficient. The sharper question is which AI, under which policy, and on what terms.

The clearest pullback has emerged in traditional corporate lines, including general liability, D&O and professional liability, where insurers are narrowing AI-related language because losses are hard to predict, trace or price. A Delinea survey found that 42% of companies now have AI-related exclusions written into their cyber policies. Even so, most cyber insurers are not excluding AI-powered attacks outright. If a threat actor uses generative AI to craft phishing emails or scale social engineering, the incident may still qualify as a cyber event provided it meets existing triggers such as unauthorised access or funds transfer fraud.

The harder problem is agentic AI, systems that act with limited or no human intervention. If an AI agent deletes records, alters a database or authorises a payment without any external attacker, there is no traditional breach to trigger the policy.

Researchers at NYU Tandon frame this as a sliding scale: the more independently an AI executes, the less likely a breach-triggered policy is to respond. Some carriers are plugging the gap with narrower products. Chubb now covers certain AI incidents but excludes systemic losses affecting many policyholders simultaneously, while other insurers have launched AI security riders in 2026 requiring proof of red-teaming and documented risk assessments.

Insurers are also wary of underwriting a black box. Cases such as Air Canada being forced to honour a chatbot-generated refund policy, and Wolf River Electric suing Google over false AI Overviews claims, illustrate losses nobody can trace to a clear human decision. Some underwriters are declining AI-output claims entirely.

The flip side is that defensive AI is earning genuine rewards. Some 86% of organisations report premium discounts for AI-based security tools, and firms pairing AI-powered threat detection with phishing-resistant MFA and EDR are seeing premium cuts of 20% to 50%. The market is effectively pricing two different things under one label: a governed defensive asset that earns a discount, or an unmanaged liability that earns an exclusion.

At renewal, firms should be ready to present a current AI tool inventory, documented pre-deployment risk assessments, evidence of adversarial testing for any system that can act on production data, and a clear map of where human oversight sits. Carriers want this evidence before a claim, not after, and the gap is already showing up in premiums.

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2018 RegTech Analyst

Investors

The following investor(s) were tagged in this article.