TL;DR
Tom Hughes, underwriting director at the International Underwriting Association, says clauses commonly found in cyber policies are likely to pick up AI-related claims that no insurer intended to write or charge for. He believes AI is insurable, but explicit products remain scarce while exposure accumulates inside wordings drafted before the technology existed.
How the exposure gets in
The mechanism is unglamorous. Cyber policies define what counts as a computer system, and Hughes’ judgement is that those definitions will capture generative AI as businesses currently use it. If AI sits inside the definition, the policy already provides a route to a claim for hallucination or intellectual property infringement, whether or not anyone meant it to.
Silent cover is when a wording neither grants nor excludes a risk clearly, so the risk arrives uninvited and unpriced. The London market has been here before. Cyber attacks were the original example, appearing inside general commercial policies while the industry was still working out what cyber risk was.
Why this version could be worse
A July white paper from cyber risk firm Kynd, cited in the reporting, identifies what makes AI different from silent cyber: concentration. Shadow IT spread risk across many separate systems. AI concentrates it, because most deployments rest on the same handful of foundation models — so a single model flaw can surface across an insurer’s whole book simultaneously. That is the shape of an accumulation event rather than a series of unrelated claims.
Adoption is also outrunning disclosure. Recruitment, claims handling and the customer service desk are all quietly acquiring AI faster than any broker thinks to ask, and often faster than the business itself keeps count.
Looking forward
Hughes counts three markets preparing or already offering AI-specific products and expects more to follow. Meanwhile exclusions for AI are barely surfacing at all, and businesses keep reaching for policies they already hold to answer AI questions — the exact combination that lets silent cover build.
For UK businesses the practical question is not whether your insurer has an AI product. It is whether anyone has asked you what AI you are running. If the answer is no, both sides are currently guessing about the same policy, and only one of them finds out at claim time.