Traditional cyber policies often assume malicious activity originates with a person or organized group, while an autonomous AI agent might initiate harmful actions after receiving a broader instruction.
Liability creates another problem for insurers. If an AI-generated action causes financial damage, determining responsibility might involve the system developer, the company deploying it or the person who issued the original instruction.
Those distinctions affect whether a cyber policy responds and which exclusions apply. They also influence how insurers assess risk before issuing coverage to businesses using autonomous AI tools.
The issue is arriving as cyber insurance continues to expand. Munich Re estimated the global cyber insurance market at nearly $15 bn last year and expects it to reach roughly $28 bn by 2030.
AI-related attacks are also expected to represent a growing share of cyber incidents. Aon forecast earlier this year that generative AI will be involved in nearly 20% of cyberattacks by 2027.
Insurers therefore face pressure to update policy wording before autonomous systems become more common inside corporate operations. Definitions covering cyber attackers, human involvement and responsibility for automated actions are likely to receive closer scrutiny as underwriting teams assess the next generation of AI-driven cyber losses.
Cyber insurers have spent years defining what constitutes a hack and when coverage should pay out, but the rapid emergence of AI agents is raising new questions, forcing insurers to review their policies.
The cyber threat landscape is evolving rapidly, with nation-state actors and sophisticated criminal groups continuing to target financial institutions.
Financial institutions are lucrative targets because they manage substantial funds, hold sensitive customer data, and can be impacted by operational disruptions.
Although cyber incidents have not resulted in a significant systemic event for the U.S. financial services sector to date, they could pose risks to financial stability given the high complexity and interconnectedness of global financial institutions and their systems.
A cyber incident at a key financial institution, critical infrastructure or significant operation, or in an important market could propagate stress across the financial system.









