AI risks prompt insurers to review cyber coverages
At least three insurers with a local presence are reviewing their cyber insurance policies in response to emerging artificial intelligence-related risks.
In high-profile incidents this summer, AI models developed by OpenAI and Anthropic bypassed their testing environments during cybersecurity testing, creating a new dimension in cyber risk.
Reuters has reported that the Mitsui Sumitomo Insurance Group, QBE and Beazley are rethinking their established cyber policies in response to the changing cyber risk landscape.
In the case of Anthropic, Claude models entered three organisations’ real systems, extracting credentials, accessing a database and publishing a malicious Python package that extracted a security company’s credentials.
In an incident last month, Meta’s AI model Muse Spark 1.1 — designed for coding and autonomous tasks, accessed the internet due to a mistake by evaluators. It uncovered and exploited a vulnerability in an unidentified third-party service and apparently made changes to the company’s systems.
The testing environment’s set-up was blamed.
In an article posted on LinkedIn, Logan Daley, a cybersecurity and technology executive, outlined the problem saying that AI agents can now cause losses without triggering a traditional security event at all, particularly when they are using access they were deliberately given.
As many policies stand today, an incident involving an AI agent that makes a costly mistake while following instructions, may be classified as a non-cyber event.
Beazley has said it is developing new coverage as new AI risks emerge.
Serene Davis, QBE’s global head of cyber in Los Angeles, told Reuters that her firm is treating AI as a “risk amplifier” rather than a new risk.
Ms Davis also told the Insurance Business website that 29 per cent of businesses have already experienced a cyber incident involving AI, in some form, while only 34 per cent of businesses actually have AI usage policy in place.
Global research firm Gartner has suggested that by next year, 17 per cent of all cyberattacks will involve generative AI.
Meanwhile, Munich Re predicts the cyber insurance market will reach $28 billion by the end of the decade.
