As AI Agents Go Rogue, Cyber Insurers Are Adapting Their Policies

 Cyber insurers have spent years defining what constitutes a hack and when coverage should pay out, but the rapid emergence of AI agents is raising new questions, forcing insurers to review their policies.


Agbm-115 Agbm-116 Agbm-117 Agbm-118 Agbm-119


Leading AI developers OpenAI, Anthropic and Meta Platforms recently disclosed that their AI agents behaved unexpectedly, escaping controlled test environments and carrying out cyberattacks on companies without dir


Agbm-120 Agbm-121 Agbm-122 Agbm-123 Agbm-124

ect human instruction. While those incidents did not cause reported damage, they highlighted the rapidly evolving cyber risks facing companies and insurers.


After receiving an initial instruction, autonomous AI systems can make independent decisions. Insurers, including MSIG, QBE and Beazley are reviewing traditional cyber policies and adapting their language to account for e


Agbm-125 Agbm-126 Agbm-127 Agbm-128 Agbm-129 Agbm-130

merging risks posed by such systems taking on more autonomous tasks, according to eight executives at major companies, and analysts.


Companies are grappling with issues including whether autonomous AI systems fit traditional policy definitions of a cyber attacker and who bears liability for AI-generated actions that cause a loss, analysts and experts said.


Agbm-131 Agbm-132 Agbm-133 Agbm-134 Agbm-135 Agbm-136 Agbm-137

The global cyber insurance market was worth nearly $15 billion last year and is expected to reach roughly $28 billion by 2030, Munich Re estimated in its latest report. Aon said earlier this year that nearly 20% of cyberattacks will involve generative AI by 2027, according to its forecasts.


“As AI becomes capable of identifying vulnerabilities and carrying out attacks autonomously, carriers will need to continually review policy language,” said Ryan Kratz, head of cyber, North America, at property and casualty specialty insurer MSIG USA.


Agbm-138 Agbm-139 Agbm-140 Agbm-141 Agbm-142 Agbm-143 Agbm-144 Agbm-145 Agbm-146

DEFINING AI-DRIVEN LOSSES


Several companies, including Armilla AI, Munich Re’s AiSure, and AXA XL, provide targeted coverage against AI-specific risks such as model underperformance, hallucinations — when AI generates false or misleading outputs — and intellectual property infringements.


Agbm-147 Agbm-148 Agbm-149 Agbm-150 Agbm-151 Agbm-152 Agbm-153 Agbm-154 Agbm-155 Agbm-156 Agbm-157 Agbm-158 Agbm-159 Agbm-160 Agbm-161

But traditional cyber policies are designed to be broader, covering losses stemming from a range of incidents, such as ransomware payments, business interruption, system recovery, forensic investigations and legal costs. Business interruption is commonly the largest component of a claim.


Most policies envisage a specific security event that causes the loss, such as unauthorized access by an employee who steals company data or a server attack that takes a system down. AI agents, however, can cause losses without trigg


See more beautiful photo albums Here >>>


ering a traditional security event, particularly when they are using access to systems they were deliberately given.


“Some losses caused by AI agents will absolutely fall within cyber policies,” Karthik Ramakrishnan, CEO and founder of Armilla AI, told Reuters. “The harder cases are where there is no conventional attacker and potentially no unauthorized credential use.”


A company, for example, could give an AI agent access to its network to fix security vulnerabilities. The agent could then exploit a vulnerability on its own, move


through the company’s systems and expose sensitive data. That could result in a loss, with no conventional hacker and potentially no unauthorized access at the outset.

Đăng nhận xét

Mới hơn Cũ hơn

Support me!!! Thanks you!