AI-Driven Hacks Shake Up Cyber Insurance Industry

i2c: Next Chapter of Payments Is Always on, Always Trusted

The rise of artificial intelligence-powered hacks has cyber insurance firms rethinking their policies, Reuters reported Thursday (Aug. 27).

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    yesSubscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    The industry shakeup follows a series of cyberattacks by AI models from companies like Anthropic, Meta and OpenAI, the report said. The incidents, which happened when the models broke free of controlled testing environments, did not cause any reported damage. However, the hacks still spotlight the changing cyber risks faced by companies and insurers.

    Insurers such as MSIG, QBE and Beazley are now reviewing their cyber policies and changing their language to cover risks posed by AI, according to the report.

    We’d love to be your preferred source for news.

    Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!

    “As AI becomes capable of identifying vulnerabilities and carrying out attacks autonomously, carriers will need to continually review policy language,” said Ryan Kratz, head of cyber, North America, at property and casualty specialty insurer MSIG USA, per the report.

    The global cyber insurance market is expected to reach around $28 billion by 2030, the report said, citing data from Munich Re. That’s compared to almost $15 billion last year. Meanwhile, Aon forecasts that close to 20% of cyberattacks will involve generative AI by 2027.

    The situation has insurance companies wrestling with what their cyber policies should cover, according to the report.

    Most cyber insurance policies are designed around specific events that cause the loss, like unauthorized access by an employee stealing company data. But AI agents can cause losses without triggering a security event, especially when accessing systems where they have permission, the report said.

    “Some losses caused by AI agents will absolutely fall within cyber policies,” said Armilla AI Founder and CEO Karthik Ramakrishnan, per the report. “The harder cases are where there is no conventional attacker and potentially no unauthorized credential use.”

    The International Monetary Fund (IMF) found in a June report titled “Artificial Intelligence and Cybersecurity in the Financial Sector” that AI does not need to develop new types of cyberattacks to change the risk equation. By accelerating vulnerability discovery and exploitation across shared technologies, AI can transform weaknesses that once led to isolated incidents into interrelated disruptions impacting multiple institutions all at once.

    For all PYMNTS AI coverage, subscribe to the daily AI Newsletter.