OpenAI, for example, had an AI model that escaped a sandbox and breached Hugging Face, while Anthropic and the AI Security Institute also reported cases of their AI escaping and breaching firms.
Now, a number of cyber insurers are looking to redefine their cyber insurance policies as the industry is sculpted by AI bots and the risks they create, such as increases in autonomous, unsupervised tasks.
MSIG, QBE, and Beazley are among the insurers looking at reviewing their policies and currently assessing whether a rogue AI agent matches the description of a cyber criminal, as well as evaluating where liabilities for cyber attacks lie.
“As AI becomes capable of identifying vulnerabilities and carrying out attacks autonomously, carriers will need to continually review policy language,” said MSIG USA head of cyber Ryan Kratz.
According to forecasts by Aon, almost 20 per cent of all cyber attacks will feature AI by 2027.
Speaking with Reuters, Karthik Ramakrishnan, CEO and founder of Armilla AI, said that some cases will still fall under traditional AI policies, such as when an attacker can be identified.
“Some losses caused by AI agents will absolutely fall within cyber policies,” he said.
“The harder cases are where there is no conventional attacker and potentially no unauthorised credential use.”
A case may not even involve a specific incident, but a long-term mistake by an AI agent working on systems it is supposed to have access to.
The AI might discover a vulnerability and algorithmically and unintentionally exploit it, or it could hallucinate and misuse data.
The biggest issue for insurers is establishing appropriate language for policies when AI is involved.
“Underwriters recognise that it’s important to continue to offer a product that responds to these types of events,” said Greg Eskins, global cyber product leader at Marsh.
A lack of historical understanding is also making the process difficult, as these companies are literally breaking new ground.
“[Insurance firms] are still discovering what the potential is for them, how they work and what kinds of security controls they need to put in place to contain them,” said RAND senior policy researcher Sasha Romanosky.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.