How AI Is Changing the Rules of Cyber Insurance

More firms in the investment management industry are using AI than ever before. AI tools are helping teams summarize research, monitor threats, automate workflows, and strengthen cyber defenses. But as adoption grows, so do new risks, including autonomous systems operating outside intended boundaries, AI-generated errors or hallucinations, generative AI-powered attacks, and uncertainty over who is responsible when something goes wrong.

That uncertainty is now showing up in the cyber insurance market. Some insurers are tightening policy language and introducing AI-related exclusions where they believe the risk is too difficult to measure. Others are offering discounts or incentives to firms using AI for detection, response, and cyber defense. For investment managers and financial services firms buying or renewing cyber coverage in 2026, the old question, “Is AI covered?”, is no longer enough. The better question is which AI, in which policy, and under what conditions.

How Does AI Affect Cyber Insurance Coverage?

As organizations adopt AI across business operations, cyber insurers are reassessing how traditional policies respond to AI-related risks. While most policies continue to cover cyber-attacks that use AI, losses caused by an organization’s own autonomous AI systems, weak AI governance, or AI-generated outputs may create coverage gaps or affect underwriting, pricing, and renewal decisions.

How AI Exclusions Are Emerging in Cyber Insurance

You may have seen headlines suggesting insurers are walking away from AI risk altogether. The reality is more nuanced. The clearest pullback so far has appeared in traditional corporate policies, including general liability, directors and officers (D&O), and professional liability (errors and omissions) coverage. In those lines, insurers are narrowing language around AI-related damages because the losses can be difficult to predict, trace, or price.

A Delinea survey found that 42% of companies now have AI-related exclusions written into their cyber policies. But cyber policies are more nuanced. Most cyber insurers are not excluding AI-powered attacks outright. If a threat actor uses generative AI to write phishing emails, automate reconnaissance, or scale social engineering, the incident may still be treated as a cyber event if it meets the policy’s existing triggers, such as unauthorized access, data compromise, business interruption, or funds transfer fraud.

But “still covered” does not mean “fully covered.” The harder question is what happens when AI is not just a tool used by the attacker, but part of the insured firm’s own operations. If an AI agent changes data, deletes records, approves an action, or produces a harmful output without a traditional breach, the loss may not fit neatly into policy language built around hacking, data theft, or system compromise. For investment managers, that is where real coverage uncertainty begins.

Why Autonomous AI May Not Trigger Cyber Insurance Coverage

Most cyber policies are built around one clear moment: a system gets broken into, data gets stolen or encrypted, and a loss follows from that. That’s the “trigger” that makes the policy pay out.

Agentic AI refers to AI systems that can make decisions and take actions with limited or no human intervention, rather than simply generating content or recommendations. Unlike traditional AI assistants, agentic AI can execute tasks, modify systems, or trigger workflows on its own. Consider an AI agent that deletes records, changes a database entry, or authorizes a payment it wasn’t supposed to make. No unauthorized access occurred, and there was no external attacker.

The AI acted outside its intended boundaries, and the loss occurred anyway. One key risk with agentic AI is not only that it could be compromised, but that it can take actions that create loss without a traditional cyber event. Researchers at NYU Tandon describe this as a sliding scale, from AI that only drafts text, to AI that prepares actions for a human to approve, up to AI that independently executes and changes systems. The further up that scale a deployment sits, the less likely a standard, breach-triggered policy is to respond. Cyber insurers generally design coverage around unauthorized access, data compromise, or system intrusion. Autonomous AI actions that occur without those traditional cyber events may not trigger standard cyber insurance coverage.

A few carriers are starting to plug this gap with new, narrower products rather than rewriting their whole policy language:

  • Chubb now covers some AI-related incidents but specifically excludes losses that affect many policyholders at the same time, since one flawed AI model used widely could trigger losses everywhere at once.
  • Some insurers introduced “AI Security Riders” in 2026: add-ons that require proof of red-teaming (deliberately testing your AI for weaknesses) and documented risk assessments before they extend coverage.

Insurers Don’t Want to Underwrite a Black Box

The second gap is different from AI-powered phishing or ransomware. It involves losses caused by the insured firm’s own AI output: hallucinations, inaccurate answers, misleading content, or actions that are difficult to trace back to a clear human decision.

  • Air Canada was required to honor a refund policy generated by its chatbot.
  • Wolf River Electric sued Google after its AI Overviews feature falsely claimed the company was facing legal trouble, costing it a customer.

What links these cases is that nobody, including the insurer, can clearly trace how the AI arrived at its answer. That’s exactly what underwriters need to assess fault and price a policy. As a result, some insurers are simply declining to write coverage for AI-output claims, because they can’t reconstruct the AI’s reasoning path. Cyber insurers are increasingly evaluating AI governance, AI tool inventories, documented risk assessments, red-teaming, and human oversight during underwriting and renewal.

For similar reasons, a lack of basic AI governance, such as an inventory, risk register, or documented oversight, can make coverage harder to obtain.

Defensive AI Is Already Earning Real Discounts

The market is not treating all AI use as a liability. Insurers are increasingly rewarding organizations that demonstrate effective use of AI for cybersecurity.

  • 86% of organizations report getting premium discounts or credits for using AI-based security tools that strengthen their defenses.
  • Companies that pair AI-powered threat detection with phishing-resistant multi-factor authentication and endpoint detection and response (EDR) are seeing premium cuts of 20 to 50%.

In short, the market is pricing two completely different things under the same label, “AI.” One is a defensive asset that earns a discount. The other is an unmanaged liability that earns an exclusion. Which category a firm falls into depends less on whether it uses AI, and more on whether it can show how that AI is controlled, monitored, and documented.

How AI Governance Can Affect Cyber Insurance Renewal

The line between “covered” and “denied” no longer depends only on whether a firm uses AI. The more important question is whether the firm can show how AI is governed, monitored, and controlled.

For investment managers and other financial services firms, demonstrating responsible AI governance is becoming an increasingly important part of cyber insurance renewal discussions. Firms that can document how AI is governed, monitored, and controlled are generally in a stronger position during underwriting.

Good documentation may not solve every coverage gap. If an autonomous AI system causes a loss without a breach, or an AI-generated output creates harm that is difficult to trace, some policies may still respond narrowly or not at all. But strong governance can put a firm in a better position with underwriters, help avoid unnecessary exclusions, support requests for endorsements or riders, and make claim discussions easier if something goes wrong.

At renewal, be ready to show:

  • A current inventory of the AI tools and models your organization uses
  • Documented risk assessments completed before any new AI tool or agent went live
  • Evidence of adversarial testing or red teaming for any AI system that can write to, change, or act on production data
  • A clear explanation of where human oversight occurs within AI-driven processes

Carriers are asking for this evidence before a claim happens, not after. The gap between organizations that have it ready and those that don’t is already showing up in premiums, and in some cases, whether coverage is offered at all.

Key Takeaway

AI is changing cyber insurance in two important ways:

  1. Insurers are rewarding firms that use AI to strengthen cybersecurity while scrutinizing organizations that deploy AI without adequate governance.
  2. Firms should document AI use, maintain AI inventories, test high-risk systems, implement human oversight, and align cyber insurance renewal materials with evidence of responsible AI governance. 

FAQs

Generally, yes. Most cyber insurance policies continue to cover cyber incidents involving AI-powered phishing, ransomware, or social engineering if they meet the policy’s existing coverage triggers, such as unauthorized access or data compromise. Coverage ultimately depends on the policy language. 

Yes. Many insurers now evaluate AI governance alongside traditional cybersecurity controls. Organizations that demonstrate strong AI oversight, documentation, and testing may receive more favorable underwriting outcomes or premium discounts. 

Insurers increasingly request documentation such as AI inventories, risk assessments, evidence of red-teaming, governance policies, and descriptions of where human oversight exists within AI-enabled processes. 

Potentially. If an autonomous AI system causes financial loss without a traditional cyber event such as unauthorized access or data theft, some cyber insurance policies may not respond because the loss falls outside existing coverage triggers. 

Turn AI Risk into a Defensible Position

Strengthen your position during underwriting and renewal with clearer AI governance, testing, and documentation. ACA Aponix can help identify AI-related cybersecurity and data risks before they affect coverage discussions.