AI ONLINE6 September 2026
The AI News Desk

RelayON THE WIRE

The whole field of AI — read, checked, and explained.
Business & Funding

Your AI agent just wiped the database. Your cyber insurance may not cover it.

When an AI agent acting on its own deletes records or authorises a bad payment, there's no hacker and no break-in — so the breach-triggered policies most firms rely on may not respond at all. Insurers are scrambling to price a risk they've never had to.

Priya AnandBy Priya AnandBusiness Editor
27 August 2026
Listen to this postread by Relay

Picture the incident report. Overnight, an AI agent with access to your systems misreads an instruction, deletes a swathe of customer records and authorises a handful of payments that should never have gone out. By morning the damage is real and expensive. Then your insurer asks the question that decides whether you are covered: who broke in?

Nobody did. And that is the problem.

The policy was written for burglars, not for software

Most cyber insurance is breach-triggered. It responds to an external attacker gaining unauthorised access — a hacker, a phishing haul, ransomware. A misbehaving AI agent is none of those things. It had legitimate access, it was doing what it was told to do, and there is no intruder to point at. The event that hurt you may sit entirely outside the language of the policy you have been paying for.

Insurers have a name for this awkward space: "silent AI" — risks that are neither explicitly covered nor explicitly excluded, sitting unpriced inside policies written before anyone handed software the keys. By one recent industry estimate, more than 90% of insurers' AI exposure is silent in exactly this way. It is not that they have decided to cover it. It is that nobody has decided anything, and the wording predates the question.

It is already showing up in the claims

This is not a thought experiment. Gallagher's 2026 AI Adoption and Risk Benchmarking Survey found that one in five insurance professionals say their insureds have already suffered losses linked to AI risk. The failure modes are varied — the UK engineering firm Arup was tricked out of around US$25 million in 2024 when criminals used a deepfake video call to impersonate its executives, a reminder that "AI risk" already spans both the tools attackers use and the tools companies trust.

As Anat Lior, an assistant professor of law at Drexel University who advises insurers on exactly this, has argued, the hard part is not deciding that AI creates liability — it is working out whose. When an autonomous system acts, the responsibility could land on the company that deployed it, the vendor that built it, or the model provider underneath, and the contracts rarely say.

What the market is doing about it

The response is arriving in two shapes. Some insurers are writing dedicated AI riders that only extend cover once a client can show its homework — documented risk assessments, evidence of red-teaming, proof that the agent was tested against the ways it might go wrong. Others are drawing new exclusion lines, carving out the nightmare scenario of a single flawed model failing across thousands of customers at once and turning one bad update into a systemic claim.

Both moves point the same way: cover for autonomous AI is going to be conditional, priced, and earned, not assumed.

The real shift

For twenty years the defining question after a tech disaster has been "was there a breach?" Agentic AI quietly replaces it with a harder one: "who is accountable when the software decided?" That is a question for insurers, but it does not stop with them — it is the same question a board, a regulator and a court will each ask in turn. The policies being rewritten now are an early, self-interested attempt to answer it, and they are worth watching precisely because the insurance industry has to put a number on risks the rest of us are still describing in adjectives.

Tune your feed
Like to get more stories like this in your For You feed — dislike for fewer.
Sources
Priya Anand — Business Editor. Priya tracks the money and the market: raises, deals, pricing, and the economics shaping where AI goes next. Spot something wrong? Tell me and I'll correct it in public.
Got a question about this?

Ask Relay — he reads every question himself and replies personally by email.

Ask Relay →