Overview
Artificial intelligence has become a major topic across insurance because of its growing influence on operations, underwriting and claims decisions. Insurers are also examining whether broader use of AI increases risks already present across several business lines.
In cyber insurance, AI appears to be changing the scale and speed of existing threats rather than creating entirely separate categories of insured loss.
Attackers increasingly use AI to support phishing, malware development and other established methods, while businesses are deploying AI systems inside their own technology environments.
Commercial cyber policies already respond to some AI-related incidents. AI models often fall within existing definitions of computer systems, meaning losses tied to those systems might trigger coverage under several sections of a standard cyber policy.
Key highlights
- Global cyber insurance premium is projected to reach $16.4 bn in 2026 and $17.1 bn in 2027, even as global rates decline for a fourth consecutive year.
- North America remains dominant with about $10.7 bn in premium, or roughly two-thirds of the global market. Europe follows with $3.42 bn and a 21% share.
- Micro-SMEs and SMEs remain heavily underinsured, with penetration of only 5-10% and 10-20%. Despite low take-up, the segment should generate about $4.9 bn in 2026 premium.
- Large corporates generate about $7.4 bn in cyber premium, yet existing limits might still leave protection gaps. Average limits stand near $120 mn in the US and $90 mn in Europe.
- AI is changing existing cyber exposures rather than creating an entirely separate loss category. Insurers face new questions around autonomous agents, privacy violations, AI model outages and attacks against AI systems.
Coverage still depends heavily on individual policy wording and the circumstances surrounding each incident. Insurers and policyholders therefore need a shared understanding of how existing definitions, exclusions and coverage triggers apply when AI contributes to a loss.
Swiss Re’s latest data shows that the cyber insurance market’s internal growth trends remain broadly similar to last year. The external threat environment, though, continues to change as ransomware activity, supply-chain dependencies and geopolitical tensions reshape corporate cyber exposure.
Rapid technological development adds another source of uncertainty. AI sits prominently within that shift because companies are using the technology across more operational processes while attackers are adopting many of the same tools.

AI also creates competing effects for cyber risk managers. The technology supports faster threat detection and security operations, yet wider deployment increases the number of automated systems interacting with sensitive data and corporate networks.
For cyber insurers, the immediate issue is therefore less about inventing entirely new coverage categories. The more pressing task involves determining how AI-driven cyber incidents fit within existing cyber policy structures and where current wording leaves uncertainty over coverage.
6 AI-driven cyber incident scenarios
| Scenario | Description |
| 1. AI supported cyber attacks (malicious) | AI models allow threat actors to automate cyber attacks and lower the barrier for entry into cybercrime. They accelerate vulnerability discovery, attack execution, and enhance impersonation. |
| 2. Threat actors attack AI models (malicious) | AI models become targets of cyber attacks. Prompt injection, model poisoning, jailbreaking lead to loss of protected data and system outage. |
| 3. AI model outage (malicious / non-malicious) | AI models, whether internal or vendor models, suffer degradation of availability or outage due to cyber attack or operational issues. |
| 4. Erroneous AI agent operations (non-malicious) | Internal AI agents perform faulty operations leading to data loss, data breach and/or system outage (“rogue agents”). |
| 5. AI use violates privacy regulation (non-malicious) | Oversharing of protected data in AI model violates privacy or related regulation, without malicious act. |
| 6. AI generated content infringes copyright (non-malicious) | AI generated content violates copyright or trademark. |
AI is increasingly being used in both cyber offence and defence
For threat actors, it can accelerate vulnerability identification, automated attacks and next-generation phishing capabilities. For organisations, however, it can serve to strengthen their threat detection, automated incident response and cyber resilience.
AI-related cyber insurance claims remain limited today, but insurers will need to monitor how technology, regulation and loss trends develop, and ensure that coverage intent remains clear as exposures evolve.
Against this backdrop, adequate cyber protection is becoming increasingly important to organisations of every size.
Global cyber insurance premium outlook
| Year | Global cyber premium | Market trend |
| 2026 | $16.4 bn | Growth continues despite falling rates |
| 2027 | $17.1 bn | Premium growth remains positive |
| 2026 rate change | -5% | Fourth consecutive annual decline |
| 2025 rate change | -13% | Sharper pricing decline than in 2026 |
New technologies, cited by 44%, and business interruption, at 37%, continue to shape operational planning. PFAS liability also moves into view, cited by nearly 20% of all respondents and 37% of US carriers, according to Global RiskScan 2026.
These findings match wider research on disaster costs, digital exposure and long-tail environmental claims. The issue isn’t one hazard replacing another. It’s the way each one affects the others.
A cyber incident stops operations. A climate event leads to litigation. A new technology exposes supply chains. Environmental liabilities stay on the balance sheet for decades.
Organizations that understand those links and plan around them will move faster than competitors when losses spread beyond the first event.
Global cyber insurance premium by underwriting year

As Swiss Re projects full-year premium to reach $16.4 bn in 2026 and $17.1 bn in 2027, cyber is still producing attractive premium growth compared to other lines of business, although this is being tempered by ongoing rate reductions.
Advanced cyber practices remain out of reach for many issuers, and survey responses raise questions about the effectiveness of some cyber initiatives. Analysts expect cybersecurity spending to continue its run of sustained growth, a trend fueled by the persistent threat of cyberattacks, the demands of hybrid work and increased data privacy and governance regulations, according to Moody’s Cyber survey.
Global cyber insurance rate change

According to Gartner, 50% of C-level executives will have performance requirements related to cybersecurity risk built into their employment contracts by 2026.
The global specialty insurance landscape is entering a period defined less by isolated events and more by interconnected risk. Cyber incidents can trigger business interruptions, according to Munich Re Specialty.
AI, IoT reshape corporate risk and insurance tools
- AI and generative AI lead the technology risk agenda, with 70% of RiskScan respondents naming them as the most impactful technologies.
- Smart devices and IoT are turning digital failures into physical, operational and financial risks as companies connect more systems, assets and workflows.
- Risk managers need broader planning across cyber, property, equipment and liability exposures because technology-related disruption no longer stays in one silo.
Technology has moved from a side issue in risk management to a direct driver of how companies operate, assess exposures and deliver value.
Cyber insurance rates fall globally
Swiss Re data shows global cyber insurance rates declined for a fourth consecutive year in 2026, though the pace of reduction slowed. Average rate movement improved from about -13% in 2025 to roughly -5% this year.
The US market drove much of that moderation as insurers responded to growing pressure on profitability. Pricing has started to stabilize after several years of aggressive competition and substantial rate reductions.
Conditions remain softer elsewhere. European cyber insurance markets continue to experience stronger price competition, with rates declining more sharply than in the US.
Capacity still exceeds demand across much of the cyber market, keeping buyers in a strong negotiating position. Insurers therefore face pressure to expand the overall market rather than compete primarily through further price cuts.
Cybersecurity requirements will also need to keep pace as AI adoption, ransomware activity and supply-chain risk change the loss environment.
For insurers, the challenge is maintaining enough pricing discipline to support profitability while continuing to expand cyber insurance penetration. That balance becomes harder when excess capacity keeps competitive pressure on rates.
Global cyber insurance premium by region
| Region | Premium | Global share | Market position |
| North America | $10.7 bn | ~65% | Largest global market |
| Europe | $3.42 bn | 21% | Expanding through carrier and MGA investment |
| Asia-Pacific | $1.7 bn | 10% | Third-largest market |
| Middle East & Africa | $0.31 bn | ~2% | Early-stage market |
| Latin America | $0.28 bn | ~2% | Early-stage market |
North America leads global cyber insurance
North America remains the largest cyber insurance market in 2026, accounting for roughly two-thirds of global premium. Regional premium volume stands at about $10.7 bn, keeping the US-led market well ahead of every other geography.
Europe holds a 21% share of global cyber insurance premium, equal to approximately $3.42 bn. Its position has strengthened as global insurers and international cyber MGAs invest more heavily in the region and establish new distribution partnerships.
Much of that activity targets relatively low insurance penetration compared with North America. Carriers see room to expand cyber coverage among European businesses as awareness of ransomware, regulatory exposure and supply-chain risk grows.
- Asia-Pacific ranks third with around 10% of global cyber premium, representing approximately $1.7 bn. The region remains materially smaller than North America and Europe, though its premium base gives insurers another sizeable market for future expansion.
- Latin America and the Middle East and Africa remain much smaller cyber insurance markets. Latin America accounts for roughly 2% of global premium at about $0.28 bn, while MEA represents a similar share with approximately $0.31 bn.
Global market premium – insured segment split

The regional distribution shows how concentrated global cyber insurance remains in North America. Europe is gradually taking a larger share, while APAC, Latin America and MEA still account for a comparatively limited portion of worldwide premium.
Cyber and climate risks reshape insurance priorities
- Cyber incidents lead 2026 risk concerns at 55%, followed by business interruption and new technologies at 45% each.
- Natural catastrophes are expected to become the top risk over the next five years, rising to 52% as climate-related losses increase.
- Risk is becoming more connected: cyber events, climate losses, legal pressure and new technologies can spread across operations, supply chains and insurance claims.
Organizations no longer deal with isolated threats. They manage operational, digital, environmental and liability pressures that move across value chains and turn one event into several losses.
Cyber incidents ranked first, cited by 55% of respondents. Business interruption and new technologies followed at 45% each. Natural catastrophes reached 42%, while legal system abuse and related pressures stood at 39%.
The real challenge sits in how these forces connect. A cyber event triggers operational disruption.
Cyber insurance penetration and premium by company size
| Insured segment | Estimated penetration | 2026 premium | Growth opportunity |
| Micro-SMEs | 5-10% | Part of $4.9 bn SME segment | Large uninsured population |
| SMEs | 10-20% | Part of $4.9 bn SME segment | New policy adoption |
| Mid-market | 40-50% | $4.1 bn | New buyers and higher limits |
| Large corporates | 60-70% | $7.4 bn | Higher limit adequacy |
Micro-SMEs and SMEs remain heavily underinsured against cyber risk
Micro-SMEs and SMEs remain heavily underinsured against cyber risk, with estimated penetration of only 5-10% and 10-20%, respectively. Even at those low coverage levels, the segment is expected to generate about $4.9 bn in cyber insurance premium during 2026.
Low penetration leaves insurers with substantial room to add first-time buyers as awareness of ransomware, business interruption and data-related losses increases.
Penetration is considerably higher in the mid-market, reaching an estimated 40-50%. The segment is still far from saturated and should produce about $4.1 bn in premium in 2026.
Growth in the mid-market could come through new policyholders as well as higher limits among companies already insured. Existing buyers are reassessing coverage amounts as their dependence on digital systems and exposure to cyber losses increase.
Large corporations remain the biggest source of cyber premium, generating an estimated $7.4 bn in 2026. Penetration among these companies stands at roughly 60-70%, well above rates recorded among smaller businesses.
Recent attacks against manufacturers and retailers have increased attention on whether large companies carry enough cyber protection for their current exposures. Even with higher penetration, insurers still have room to expand limits and coverage among existing corporate buyers.
Large corporates may face cyber insurance limit gaps
Swiss Re estimates that large corporations purchase average cyber insurance limits of about $120 mn in the US and $90 mn in Europe. Those limits indicate that major companies generally structure cyber programs around severe events rather than frequent, smaller losses.
Claims data suggests the protection might still fall short in extreme cases. Cyber Claims Database shows that an average of 10 losses per year over the past five years would have exceeded the $120 mn US benchmark.
That comparison raises questions about whether large corporate cyber programs carry enough insurance for the events they are specifically designed to absorb. A company might maintain substantial limits and still face a large uninsured portion of a severe cyber loss.
Large corporate cyber insurance limits
| Market | Average cyber limit | Swiss Re assessment |
| US | $120 mn | Severe losses can exceed current limits |
| Europe | $90 mn | Lower average limits than US corporates |
| Severe-loss benchmark | >$120 mn | About 10 losses per year exceeded this level on average over five years |
| Potential future requirement | Up to 2x current limits in some cases | Depends on company exposure and risk profile |
Ransomware and privacy-related incidents account for most losses reaching these levels. Data breaches also produce some of the largest claims, especially when several expense categories accumulate within one incident.
A severe attack on a large corporation often involves prolonged digital business interruption and lost revenue. Restoration expenses can rise alongside supply-chain disruption, while reputational damage adds further financial pressure.
Rapid adoption of AI introduces another variable into limit calculations. Greater reliance on automated systems increases digital dependency and could expand the number of systems exposed to attack or operational failure.
Historical loss experience therefore might become less useful as the sole basis for future limits. Severe losses could move above insurance programs calibrated around earlier benchmarks as corporate technology environments become more interconnected.
Main cyber insurance growth opportunities
| Market segment | Primary opportunity | Main insurance issue |
| Micro-SMEs and SMEs | Increase penetration | Most businesses remain uninsured |
| Mid-market | Increase penetration and limits | Existing coverage often remains below changing exposures |
| Large corporates | Increase limits | Severe losses can exceed current programs |
| Europe | Expand market penetration | Cyber insurance remains less developed than North America |
| APAC | Build premium scale | Regional market remains relatively small |
| Existing insureds | Reassess coverage structure | AI and digital dependency are changing loss severity |
Swiss Re estimates that some companies might need limits roughly twice their current averages. The appropriate amount still depends on each company’s operations and geography, along with its individual cyber risk profile.
Cyber insurance growth therefore looks different across customer segments. Among SMEs, insurers have substantial room to increase basic penetration because most businesses remain uninsured.
FAQ
How big is the global cyber insurance market in 2026?
Swiss Re projects global cyber insurance premium at about $16.4 bn in 2026, rising to $17.1 bn in 2027 despite continued rate reductions.
Which region has the largest cyber insurance market?
North America leads with approximately $10.7 bn in 2026 premium, representing about two-thirds of the global market. Europe accounts for 21%, while APAC holds about 10%.
Are cyber insurance rates falling in 2026?
Yes. Swiss Re data shows global cyber insurance rates declined around 5% in 2026, compared with a roughly 13% decline in 2025. US pricing has started to stabilize, while European competition remains stronger.
How much cyber insurance coverage do SMEs have?
Estimated penetration is only 5-10% among micro-SMEs and 10-20% among SMEs. Their low insurance take-up leaves this segment as one of the largest opportunities for future cyber premium growth.
Are large companies underinsured for cyber risk?
Some could be. Large US corporates purchase average limits of about $120 mn, yet Swiss Re claims data shows an average of 10 losses annually over the past five years would have exceeded that amount.
How is AI affecting cyber insurance?
AI is increasing the speed and scale of established cyber risks while creating more difficult coverage scenarios. Examples include AI-supported attacks, rogue agent activity, model outages and privacy breaches caused without a conventional hacker.
Where is the biggest growth opportunity for cyber insurers?
Growth differs by segment. SMEs offer the largest opportunity through higher penetration, the mid-market offers both new customers and higher limits, while large corporates present an opportunity to increase limit adequacy against severe losses.
…………….
AUTHORS: Dani Tobler – Swiss Re’s Head Cyber Reinsurance, Fabian Willi – Swiss Re’s Head Cyber Key Accounts
Edited by Peter Sonner – Lead Tech Editor at Beinsure









