AI as a risk amplifier: how cyber insurance is evolving
AI is giving threat actors new tools, but the fundamentals of cyber risk remain unchanged
AI as a risk amplifier: how cyber insurance is evolving
CYBER
By QBE Insurance
14 Oct 2006

Artificial intelligence is moving rapidly into everyday business use, from customer service and software development to data analysis and operations. As adoption grows, organizations are asking whether AI creates entirely new risks, whether existing controls remain effective and whether cyber insurance will respond when AI contributes to an incident.

The risk is already materializing. QBE’s 2026 global cyber risk survey found that 29% of businesses had experienced at least one cyber incident in the previous 12 months where AI was believed to have been used as part of the attack. The research, conducted by Opinium, surveyed more than 6,000 business decision-makers across 15 countries.

The discussion becomes less useful when every AI-related event is treated as a separate category of cyber risk. Often, AI changes how an attack is carried out rather than what has occurred. It may help a threat actor create convincing phishing messages, identify vulnerabilities, impersonate trusted individuals or operate faster. The consequences may still be familiar: unauthorized access, data misuse, ransomware or business interruption.

Look beyond the AI label

Cyber risk has always evolved with technology. The insurance market must distinguish between a familiar risk delivered through a new tool and a genuinely new exposure requiring a different response. The phrase “AI-related risk” can describe very different scenarios, from AI-enhanced social engineering to stolen credentials used to access a cloud-hosted AI model to failures in how organizations govern information through an AI system.

The best starting point is not simply whether AI was involved, but what happened, how the organization was affected and which costs or liabilities followed. When AI contributes to unauthorized access, a data breach, ransomware or business interruption, the underlying loss remains recognizable within the established cyber framework.

“We are continuing to support coverage for cyber risks and claims arising from AI, not retreating from them. AI is a risk amplifier, not a fundamentally new cyber risk. Under core cyber policies, losses from system compromise or data breaches are covered in the same way, whether or not AI is involved,” said Serene Davis, global head of cyber at QBE Insurance.

“Coverage developments have focused on enhancing protection for specific emerging exposures rather than narrowing core cover. If an AI-related event leads to a conventional cyber incident, resulting losses continue to fall within a cyber policy.”

Where new AI exposures emerge

Many AI-enabled incidents remain conventional cyber events, but existing policies may not have anticipated every threat associated with the technology. LLMjacking illustrates this change.  A large language model (LLM) can require significant computing resources.  If a threat actor uses stolen credentials to gain unauthorized access to a cloud-hosted LLM, the unauthorized access and related incident-response costs may fit within the established cyber coverages.   However, the resulting increased service charges or the cost to retrain a damaged model may not have been expressly addressed in earlier policy wordings.

Publicly reported LLMjacking incidents have shown that compromised AI credentials and accounts can lead to unauthorized AI usage charges ranging from $50,000 to $100,000. While outcomes vary, these events provide a practical example of the emerging costs associated with the growing use of AI technologies.

This threat did not exist when earlier cyber policies were developed and as such these expenses were not contemplated. Clearer protection for them does not suggest that the underlying unauthorized access falls outside cyber insurance. It reflects the need for policy wording to keep pace with how businesses use technology and evolving tactics employed by threat actors.

AI regulation is another developing area. New governance requirements extend beyond established privacy and cybersecurity obligations and can create exposure to investigations, defense costs and penalties tied specifically to the development, deployment, use or oversight of AI.

QBE has been developing enhancements for certain AI regulatory exposures and LLMjacking costs where a gap may exist. The goal is greater clarity, not narrower core protection. A targeted enhancement can address a particular cost or liability without implying that all other AI-related losses are excluded.

Keeping coverage ahead of change

Cyber insurance has adapted to cloud computing, ransomware, connected devices and complex digital supply chains. AI requires the same discipline. The market should neither assume that every use of AI creates a wholly new insurance problem nor that every possible exposure is already addressed.

Insurers need to understand how organizations use AI, identify the controls that matter and examine how losses emerge in practice. Brokers can help clients distinguish between existing protection and additional coverage they may wish to consider.

For clients, specific questions are more useful than broad statements about whether AI is covered: What happens if an AI system is compromised? What if credentials for an externally hosted model are stolen? Which costs arise from a conventional cyber incident, and which are unique to the AI environment?

That analysis should remain iterative. As AI systems become more autonomous, regulations develop and credible loss scenarios emerge, policy language and underwriting approaches may need to evolve. Future enhancements may be appropriate where evidence shows a distinct exposure, a meaningful customer need and a risk that can be clearly defined, underwritten and managed. Ongoing monitoring and product innovation will be essential to keeping coverage relevant and fit for purpose.

Good cyber controls still matter

Insurance is only part of the response. Organizations need visibility into how AI is used, including tools adopted outside formal procurement, the information employees enter and the systems those tools can access.

Core cyber controls still apply. Credentials must be protected, access appropriately limited and unusual activity monitored. Businesses should know where AI credentials and application programming interface keys are stored, who can use them and how quickly access can be revoked.

QBE’s risk guidance recommends separating credentials across development, testing and production environments, logging API activity, monitoring for unusual use, checking applications for embedded credentials and including AI systems in incident response plans. These are familiar cyber practices applied to technology with different dependencies and cost implications.

A practical response to an evolving risk

AI-related cyber risk will continue to develop. Some incidents will use familiar attack methods more efficiently; others will expose costs or liabilities that need more explicit policy treatment. The insurance market should distinguish between them rather than treating AI as a single exposure.

“We believe cyber insurance should evolve alongside technology. As AI risks continue to develop, coverage must continue to adapt to remain relevant, responsive and fit for purpose while preserving the core protections clients rely on today" said Kevin Casey, lead cyber wordings and product innovation at QBE Insurance.

QBE’s approach is to preserve core cyber coverage when AI contributes to a conventional covered event, use targeted enhancements for specific emerging exposures that provide greater certainty, and to continue evaluating whether future developments warrant additional coverages solutions. This practical approach provides clarity today while leaving room for cyber insurance to evolve alongside technology, regulations and threats.

DISCLAIMER:  QCyber Protect is issued and underwritten by QBE Insurance (Australia) Limited (ABN 78 003 191 035, AFSL 239545). Any advice provided is general only and has been prepared without taking into account your objectives, financial situation or needs and may not be right for you. To decide if this product is right for you, please read the policy wording. QBE makes no warranty or guarantee about the validity, currency, accuracy, completeness, or adequacy of the content in this article not relating to QBE’s insurance products. Readers relying on this content do so at their own risk. It is the responsibility of the reader to evaluate the quality and accuracy of this content. Reference in this article (if any) to any specific product, process, or service, and links from this content to third party websites, do not constitute or imply an endorsement or recommendation by QBE and shall not be used for advertising or service/product endorsement purposes.

This article was produced in partnership with QBE Insurance

Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB AU.