How Generative AI Is Outpacing Cyber Insurance Coverage

How Generative AI Is Outpacing Cyber Insurance Coverage

Simon Glairy stands at the forefront of the insurance industry’s digital transformation, bringing years of expertise in risk management and AI-driven assessment to a sector currently facing its biggest challenge in a generation. As organizations worldwide grapple with the “shadow IT” implications of generative AI, Simon provides a crucial bridge between the technical realities of data leakage and the complex world of cyber underwriting. His insights are particularly timely as the market shifts from a period of cautious uncertainty toward a more structured, albeit fragmented, approach to covering AI-related exposures.

This discussion explores the growing gap between internal corporate AI rollouts and the ability of insurers to accurately price those risks. We delve into the current market split between full affirmative coverage and restrictive sub-limits, the irony of underwriters adopting the very technology they are attempting to regulate, and the shifting regulatory landscape defined by the EU AI Act. Simon also explains why AI should be viewed not as a new category of threat, but as a powerful accelerant for existing cybercrimes like ransomware, necessitating a shift in how incident response is valued.

Many employees use public large language models that sit outside their company’s internal environment to streamline their daily tasks, but what specific dangers does this “copy-paste” culture pose to a firm’s cyber security posture?

The core concern for insurers today is remarkably straightforward yet terrifyingly common: staff feeding sensitive or regulated information into public models that reside outside a client’s own secure environment. When an employee pastes proprietary code or confidential client data into a public chatbot to summarize a meeting or fix a bug, that data is essentially surrendered to a third-party platform where it may be used to train future models. This creates a significant gap between an IT team’s quiet rollout of a tool and the broker’s ability to accurately represent that risk during a renewal submission. The market is currently split, with some insurers offering full affirmative cover while others are capping it at around £250,000 because they simply don’t know where the real losses will land yet. It’s a visceral, sensory experience for a risk manager to realize that the company’s “crown jewels” are just one accidental keyboard shortcut away from being public property.

With some carriers setting coverage limits as low as £250,000 for AI-related risks, how should businesses interpret this caution regarding the maturity of current claims data?

This caution reflects a market that is still working out its approach through specific exclusions and endorsements rather than a settled, standardized question set. Insurers are currently flying blind to an extent, as they haven’t yet seen a sufficient volume of closed claims to understand the true financial gravity of an AI-driven data breach. By setting a £250,000 limit, a carrier is essentially placing a protective barrier around itself until it can observe how litigation and regulatory fines play out in the real world. It isn’t necessarily a statement that the risk is small, but rather a strategic pause while they wait for the “black swan” events to define the new baseline for loss. For a business, this means your policy might not respond the way you expect if you haven’t been transparent about your AI usage during the underwriting process.

How does the irony of underwriters using generative AI to quote submissions themselves influence the way they perceive and evaluate the risks their clients are taking?

There is a fascinating and almost poetic symmetry occurring where the technology creating the exposure is simultaneously being adopted inside the insurance company’s own underwriting process. When an underwriter uses generative AI to help quote a submission, they gain a first-hand understanding of the efficiency gains and the inherent data-sharing risks involved. This internal adoption helps bridge the empathy gap, as insurers realize that “banning” AI is not a viable strategy for their clients if they are using it for their own competitive advantage. It forces a more nuanced conversation about containment—moving away from a total “no” toward asking whether the client is using internal, contained tools versus public LLMs. This shared experience is actually helping the market move toward more realistic affirmative coverage because underwriters can no longer view AI as a distant, theoretical threat.

In light of the EU AI Act’s rolling deadlines, such as the August 2025 enforcement for general-purpose models, how is the changing regulatory landscape complicating the underwriting process?

Insurers are currently underwriting against a regulatory picture that keeps changing shape underneath them, which is an incredibly difficult position to maintain. The EU AI Act entered into force on August 1, 2024, but the most demanding provisions for high-risk systems have already been pushed back to December 2027 due to recent simplification packages. This means that compliance is a moving target, and what looks like a “safe” AI implementation today might be a major regulatory liability by the time a three-year policy matures. Brokers are often expected to volunteer what they judge to be material facts about AI use because there isn’t a consistent set of questions from insurers yet. This regulatory uncertainty is what drives the use of broad definitions in policies, as naming individual risks can inadvertently narrow the coverage in a way that hurts the client later.

Why is it often more beneficial for a policy to avoid overly specific wording and instead rely on broad definitions when addressing the evolving nature of AI threats?

Some insurers have deliberately avoided naming individual AI risks because an “if it’s not listed, then it’s not covered” attitude can severely undermine the effectiveness of a cyber policy. Broad definitions are crucial in this space because the technology evolves so rapidly that any specific list of “covered AI tools” would be obsolete within six months. Clients are increasingly asking the right questions unprompted, wanting to know if their policy would actually respond to an incident involving a tool their staff started using just last week. Maintaining broad, affirmative wording ensures that the policy functions as a comprehensive safety net rather than a fragmented set of specific promises. It allows the coverage to grow alongside the business’s tech stack, rather than forcing a policy update every time a new version of a chatbot is released.

How is AI accelerating the existing threat landscape, particularly for less experienced attackers looking to deploy ransomware?

AI doesn’t necessarily introduce a brand-new threat landscape so much as it acts as a high-octane fuel for the one that already exists. It lowers the barrier to entry significantly, allowing a novice attacker to build sophisticated ransomware strains or write flawless phishing emails in a matter of seconds. This acceleration means that the incident response services bundled into most cyber policies are now more valuable than the actual financial payout. When an attack happens at machine speed, a business needs a response team that can move just as fast to contain the breach before it spirals out of control. We are seeing a shift where the “value” of insurance is less about the check you get after the disaster and more about the expert team that arrives on the scene immediately to stop the bleeding.

What is your forecast for the evolution of AI risk assessment over the next three years?

Over the next three years, I expect the market to move away from the current state of “silent AI” risk toward a world where AI-specific underwriting questions are as standard as asking about a company’s firewall or MFA. As we approach the August 2025 and December 2027 deadlines for the EU AI Act, we will see a surge in specialized “AI liability” products that fill the gaps left by traditional cyber policies. The £250,000 sub-limits we see today will likely vanish as insurers gather enough claims data to feel comfortable offering much higher limits for a higher premium. Ultimately, we will stop talking about “AI risk” as a separate category and instead view it as a fundamental, integrated component of every company’s general operational risk profile.

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later