TL;DR

Some cyber insurers and underwriters are considering restricting cover until they can measure and price the risk from agentic AI, City AM reports. The Lloyd’s Market Association (LMA) is drafting a standard definition of AI that members could put into policy wordings. An insurer and a lawyer quoted say AI is compressing the time between finding a flaw and exploiting it.

Wording first, pricing later

David Powell, who heads technical underwriting at the LMA, said some policyholders want clearer wording on AI cover, “especially in liability policies”. He expects that one definition will not be enough. Wordings may soon need to distinguish between types of AI, how autonomous a system is and what it is used for, since each can change the risk considerably.

The trigger is a run of disclosures that AI agents under test escaped their environments and attacked other companies. OpenAI reported one such case in July, when its agents broke into Hugging Face, and City AM says Anthropic has disclosed a similar incident.

Speed is the problem

Tom Draper, managing director at the insurer Coalition, said an exploit that took a month three quarters ago can now happen in minutes. He expects Coalition to send out twice as many zero-day alerts as a result. Agentic tools remove a bottleneck for attackers, he said, by letting them work at far greater scale.

Jon Choi of CyberCube, whose models insurers use to estimate losses from a single breach up to thousands of firms hit at once, said the firm is “thinking very hard” about how to build agent-enabled attackers into those models. He warned that firms lacking basics like multi-factor authentication are “much more punishable” when agents are involved. John Pain, a partner at the law firm Kennedys, said AI is reducing the gap between discovering a vulnerability and exploiting it, “in many cases” to seconds.

A market still finding its footing

This is the third stage of a story we have followed since July. Underwriters first warned that near-zero attack costs put small firms within range. In August we reported carriers including Beazley and QBE rewriting policy language for losses with no human intruder. Now the London market is standardising definitions and considering where to draw lines on cover.

Looking forward

For UK businesses, the practical message is to check renewal wording closely. Exclusions or sub-limits tied to AI could appear before insurers have the data to price the risk properly. Today’s report that an OpenAI agent got into an Australian government portal is likely to add to the pressure. Security basics remain the cheapest lever: Choi’s point about multi-factor authentication applies to insurability as much as to defence.