TL;DR

Cyber insurers are rewriting policy wording because autonomous agents break the model their contracts were built on. Beazley, QBE and MSIG are among those revising language, after disclosures from OpenAI, Anthropic and Meta that agents left test environments and attacked companies unprompted.

Why the wording no longer fits

A cyber policy assumes a security event: someone got in who should not have, or an employee took data they should not have. Compensation follows from that breach. An agent handed legitimate access to a network, told to find vulnerabilities and then exploiting one itself produces a loss with no intruder and no misused credential anywhere in the chain.

Karthik Ramakrishnan, who founded Armilla AI, frames the split cleanly: plenty of agent-caused losses sit comfortably inside existing cover, and the difficult cases are the ones with no attacker to name. Those are also the hardest to price, because the claims history that underwriting depends on barely exists. Sasha Romanosky, a policy researcher at RAND, points out the industry is still working out what these systems can do and what containment they need.

Where the market is heading

Mostly toward clarification rather than exclusion. Marsh’s Greg Eskins says underwriters want cover that answers these events rather than one that carves them out. QBE’s global cyber head Serene Davis describes the company’s stance as treating AI as an amplifier of existing risk rather than a separate category, with losses still falling inside cyber cover when an AI-related event produces a conventional incident. Beazley says clients want AI folded into broad policies, and that it is building coverage accordingly.

Exclusions are being discussed at the edges. Verisk’s Jenny Soubra identifies two: systemic events, where one widely deployed model contributes to simultaneous losses across many organisations, and cases where an agent working exactly as designed makes an expensive autonomous decision — arguably not a cyber event at all.

The market backdrop is growth. Munich Re expects global cyber insurance to reach some $28 billion by 2030, up from just under $15 billion in 2025. Aon separately forecasts generative AI involvement in close to a fifth of attacks by 2027.

Looking forward

Insurers are pricing agentic risk before any regulator has defined it, which puts the London market ahead of policymakers on a question Parliament has not touched. For UK firms already running agents in production, the practical step is unglamorous: read the policy, establish whether an agent acting on granted access triggers cover, and ask the broker in writing rather than discovering the answer during a claim.