Does artificial intelligence need its own class of insurance, or is it quietly reshaping risks the market already underwrites? That question was at the centre of a recent webinar hosted by KYND, following the publication of its The Wild West of AI Risk white paper.
On 1 September, KYND brought together senior cyber insurance leaders from around the world to explore how AI is changing the industry’s approach to liability, claims, underwriting and aggregation.
The discussion showed limited support for a standalone AI insurance product for now. Panellists said AI exposure is already covered within existing lines, particularly cyber and technology errors and omissions. One panellist described it as the next stage of technology risk rather than a separate category. The cause of a loss remains important in determining which policy responds. For example, if an AI-powered hiring tool discriminates against candidates, the resulting exposure remains an employment and legal issue, with the business liable as it would be for a human decision. Companies developing AI themselves may face a different set of exposures and could require more dedicated cover.
Human involvement was another recurring theme in the discussion around AI liability. The panel highlighted that someone still selects the technology, creates the prompts and determines how much autonomy an AI system is given. The cases discussed during the webinar were linked to inadequate guardrails or systems being used outside their intended limits, rather than software operating entirely independently.
The panel suggested organisations should treat AI agents in a similar way to employees, with clear rules, controlled access and accountability for their actions. Establishing that responsibility can be more straightforward when AI is developed internally, but becomes more complicated when technology is purchased from a third party or incorporated into a supplier’s product.
The strongest consensus centred on undeclared AI, referring to tools used by employees or suppliers without the organisation’s knowledge or approval. Verizon’s 2026 Data Breach Investigations Report found regular AI use on corporate devices had quadrupled in a year to 45% of employees, with 67% of that activity taking place through personal accounts that businesses cannot monitor. Gartner expects more than 40% of organisations to experience a security or compliance incident linked to unauthorised AI tools by 2030, while Capgemini found 42% of property and casualty insurers had not measured their AI outcomes.
The webinar also highlighted a potential tension between tighter AI governance and employee behaviour. Restricting access to approved tools could encourage some employees to turn to alternatives on personal devices. The panel therefore discussed the importance of providing sanctioned AI tools that meet employees’ needs rather than relying solely on restrictions.
KYND also drew a parallel with shadow IT, noting that its work identifying those risks has informed a forthcoming feature designed to help identify AI technologies being used by businesses.
AI is already appearing in insurance claims, although insurers may not always recognise or record it as an AI-related loss. One issue is that claims systems generally do not have a specific category for AI, while establishing whether AI contributed to an incident can also be difficult. An IBM study cited during the webinar found around one in four malicious breaches were AI-enabled, with an average cost of roughly $6m, approximately $1m higher than a conventional breach.
The panel had differing views on what this means for insurers. Some participants viewed AI as creating a systemic exposure with similarities to catastrophe risk, while others considered the underlying risk largely unchanged, with AI instead making certain capabilities cheaper and more widely available. That could affect the frequency and severity of losses while leaving insurers with the possibility of pricing for the exposure.
The discussion drew comparisons with previous developments in insurance. Motor insurance existed before seatbelts, while the cyber insurance market underwent significant changes during 2018 and 2019 before returning to profitability.
Aggregation emerged as one of the most significant areas of concern. Between 60% and 80% of the market is understood to rely on the same small group of underlying frontier models, meaning a major problem affecting one provider could potentially create losses across a significant portion of an insurer’s portfolio.
The panel called for insurers to develop a more detailed understanding of their exposure to individual models, including dependency and concentration. This would also require pricing approaches capable of distinguishing between different underlying technologies.
Greater visibility, however, only becomes useful if insurers act on the information. The panel noted that insurers already have visibility into areas such as cloud concentration, but that this does not always translate into changes in pricing or underwriting appetite. Identifying AI use at the point of underwriting could nevertheless provide a more detailed picture of exposure than relying on periodic questionnaires.
The webinar did not resolve whether AI will eventually become a standalone insurance class, nor was that the objective. Instead, the discussion highlighted three central issues: AI involvement alone does not determine whether a claim is a cyber claim, undeclared AI represents a significant visibility gap, and insurers cannot properly assess or price an exposure they cannot see.
The scale of that challenge is also changing rapidly. One panellist described a business already running almost all of its operations on AI, illustrating how different the risk profile could become as organisations move from experimenting with AI to making it fundamental to their operations.
Copyright © 2026 FinTech Global









