Cyber insurance leaders are increasingly viewing AI as an extension of existing technology risk rather than a new category that requires its own insurance product. But while insurers are not yet convinced that AI warrants a standalone policy, the growing use of tools that businesses fail to declare is creating a significant visibility challenge for the market.
The issue was discussed during KYND’s Cyber Drop webinar on 1 September, which brought together senior cyber insurance figures to build on the InsurTech company’s white paper, The Wild West of AI Risk. The panel broadly agreed that AI-related exposures can currently sit within existing cyber and technology errors and omissions (E&O) policies. One panellist described AI as the next stage of technology risk. Companies developing AI systems themselves could be a different case, however, as they may require dedicated cover for the risks created by the systems they build rather than simply the risks associated with using third-party tools.
The panel also pointed to human decisions as a key factor in AI-related liability. Businesses decide which tools to use, how they are prompted and how much autonomy they are given. The losses discussed by panellists were linked to weak guardrails or technology being used beyond its intended limits, rather than software acting independently of human decisions. One approach discussed was to treat AI agents in a similar way to employees, with defined rules and controlled access. However, tracing accountability becomes more difficult when AI is supplied by a third party or incorporated into another supplier’s product.
For insurers, one of the biggest challenges is AI that never enters the organisation’s formal systems. Employees and suppliers may use AI tools without declaring them, leaving IT teams with limited visibility over where the technology is being used. Verizon’s 2026 Data Breach Investigations Report found that regular AI use on corporate devices had quadrupled within a year to 45% of employees, with 67% of that activity taking place through personal accounts outside business oversight. Gartner has forecast that more than 40% of organisations will experience a security or compliance incident linked to unauthorised AI tools by 2030, while Capgemini found that 42% of property and casualty insurers had yet to measure their AI outcomes.
The panel also highlighted the potential for stricter internal AI policies to create an unintended problem. If approved tools do not meet employees’ needs, tighter controls could encourage some staff to turn to unauthorised alternatives instead.
AI is also appearing in insurance claims, although its involvement is not always being recorded. Claims systems may not have a specific category for AI-related activity, while identifying the technology behind an incident can be difficult. An IBM study referenced during the session found that around one in four malicious breaches were AI-enabled, with an average cost of approximately $6m, around $1m more than conventional breaches.
There was not a single view among panellists on how these incidents should ultimately be classified. Some considered AI-enabled breaches to represent a systemic exposure with characteristics similar to catastrophe risk, while others argued that the fundamental risk remains the same and that AI is instead increasing the distribution of that risk across the market.
Aggregation was another major concern. Between 60% and 80% of the market is reportedly reliant on a relatively small group of frontier AI models. A failure affecting one provider could therefore have implications across multiple policies and portfolios at the same time.
For insurers, this creates a need for greater visibility into which models businesses depend on and how concentrated that exposure is. Model-level information could ultimately give underwriters a clearer picture of dependency and concentration when assessing and pricing AI-related risks.
The discussion suggests that the immediate challenge for cyber insurers may not be creating an entirely new AI insurance category, but understanding where AI is already being used, how those uses are affecting existing exposures and where common dependencies could create aggregation risk. KYND’s Cyber Drop discussion highlights how this visibility gap could become increasingly important as AI adoption expands across businesses and insurance portfolios.
Copyright © 2026 FinTech Global









