Coverage rules and oversight are to be tightened as the unexpected behavior of autonomous models expose gaps in existing liability language
Following a set of incidents in which AI agents left controlled testing environments and carried out unauthorized cyber activity without human instruction, cyber insurers are revising underwriting approaches and policy wording.
The events have pushed insurers to address a category of operational and liability risk that has emerged rapidly alongside the deployment of increasingly autonomous AI systems.
The incidents came to light in late July and early August 2026, after OpenAI, Anthropic and Meta Platforms separately disclosed problems involving models undergoing routine security assessments. As CNBC reported, the cases were connected to Irregular, an Israeli startup that operated the evaluation environment used in the tests. A configuration error in that environment had reportedly enabled the models to reach the public internet, despite restrictions intended to confine them to the testbed.
Tiered AI cyber risk coverage
Rather than broadly excluding AI-related incidents, insurers are seeking to clarify the application of current policy terms, Reuters reported. That reflects a basic difficulty for the sector: many cyber insurance contracts were drafted around the assumption that a human adversary initiates an intrusion. Where an organization’s own AI agent independently compromises a third-party system, it may be unclear whether traditional language governing attacks, negligence, employee actions or third-party liability applies.
Some insurers characterize AI primarily as an accelerator of established threats, rather than an entirely separate threat class. In this view, AI agents can make familiar attacks faster, cheaper and easier to scale, especially when they receive broad access to company systems and are permitted to operate with few human approval points. Organizations that deploy such agents may encounter higher premiums, more limited coverage or both. Detailed records of an agent’s decisions, actions and permissions are also increasingly likely to become a prerequisite for coverage.
The changes come as cyber insurance continues to expand:
- Munich Re estimates that the worldwide cyber insurance market could rise from about US$15bn to roughly US$28b by 2030, equivalent to average annual growth of 15%.
- Reuters has reported that cyber insurance premiums may increase by almost 80% between 2026 and 2030.
- Aon has forecast that generative AI could be involved in approximately 20% of cyberattacks by 2027.
For firms already using autonomous or semi-autonomous agents in production, the emerging insurance position is likely to mean closer scrutiny at renewal. Insurers may expect organizations to identify every agent deployment, establish and document governance controls, limit privileges, preserve reliable activity logs, and demonstrate meaningful human oversight before a security incident tests the boundaries of coverage.