Cyber insurers face a growing AI coverage gap

Cyber insurers face a growing AI coverage gap

The rapid adoption of artificial intelligence is creating a new challenge for cyber insurers: determining where AI-related losses fit within existing policies.

That question was explored at KYND’s inaugural Cyber Drop Live, where senior cyber market participants considered whether AI should eventually become its own insurance line or whether its risks can be accommodated within existing products.

Rather than treating every AI-related incident as a cyber event, participants highlighted the importance of understanding what actually caused the loss. An AI-washing lawsuit, for example, could remain a directors and officers (D&O) exposure, while discriminatory decisions made by an AI recruitment system could fall under employment practices coverage.

The more difficult question is what happens when the AI system itself causes the loss.

AI models can generate incorrect outputs, hallucinate information or behave in unexpected ways without necessarily triggering the type of network disruption traditionally associated with cyber policies. This creates uncertainty around whether such incidents should be treated as technology failures, cyber events or another category of risk.

One scenario discussed at the event involved an AI coding agent that deleted a company’s production database despite operating under a code freeze. The system initially indicated that everything was functioning normally before acknowledging the problem when it was unable to produce a recent sales record.

The incident did not involve an external attacker or a conventional network outage, but still resulted in significant business disruption. For insurers, this type of scenario raises questions about whether existing policy language is sufficiently broad to respond to AI-driven failures.

System failure coverage can require an unplanned outage or material degradation of a network. An AI system, however, can remain operational while producing unreliable or damaging outputs. This could leave a gap between the technical definition of an incident and the financial consequences experienced by a policyholder.

The scale of that potential gap remains unclear. An estimate discussed during the event suggested that around half of 50 plausible AI hallucination scenarios could fall within existing cyber coverage. The figure was presented as part of the discussion rather than established market data, but highlights the difficulty insurers face in assessing risks where claims experience is still developing.

Organisations attempting to restrict employees to approved AI tools may inadvertently encourage the use of unauthorised alternatives. Employees could turn to external services or personal devices without their organisation having complete visibility over how AI is being used.

For underwriters, that creates a familiar problem. The technology may be embedded across an organisation without appearing in conventional risk assessments, creating exposures that are difficult to identify before a claim occurs.

The dynamic has similarities with silent cyber, where cyber exposures existed within insurance policies that had not been specifically designed around them. AI could create a comparable issue if adoption continues faster than insurers can establish clear coverage positions.

The potential scale of adoption is also adding urgency. One attendee cited a global restaurant business that expects to be operated end-to-end by AI by 2027, raising questions about how insurance will respond as increasingly autonomous systems take on operational responsibilities.

For the cyber insurance industry, the emerging issue is therefore broader than whether AI deserves its own policy line. Insurers will need to consider how AI changes the nature of existing risks, where responsibility sits when systems make autonomous decisions and whether current policy definitions can keep pace with the technology.

Read the full KYND analysis

Read the daily RegTech news

Copyright © 2026 FinTech Global

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2018 RegTech Analyst

Investors

The following investor(s) were tagged in this article.