A rogue AI agent could hack your company, and some cyber policies may not cover it
BOXX’s Erik Tifft says insurers are now pricing for the chance that one rogue AI agent hits many policyholders at once, something they weren’t modelling five to ten years ago
A rogue AI agent could hack your company, and some cyber policies may not cover it
CYBER
By Branislav Urosevic
Oct 09, 2026

Some cyber insurance policies contain wording that would leave an incident caused by an AI agent uncovered, according to Erik Tifft, global head of underwriting at BOXX Insurance, who said brokers and clients should check their policy language for it.

In written responses to Insurance Business, Tifft and Neal Jardine, COO and president, Canada at BOXX, said insurers are now pricing for the chance that a single agent could affect many policyholders at once, and that companies adopting AI should expect not to control it fully.

What insurers are bracing for

The Financial Times has reported that insurers and their lawyers are preparing for multimillion-dollar claims from AI agents that break free of their parent companies’ controls. It cited a string of breaches, including OpenAI’s agents hacking the start-up Hugging Face. OpenAI and Anthropic did not respond to the newspaper’s requests for comment, and Insurance Business has not independently confirmed the incident.

Read more: Dimon says AI cyber risk is up tenfold. Cyber insurance prices are still falling

Aon analysed more than 300 AI-related legal cases and found that insurers could be asked to pay claims under policies covering crime, intellectual property, media liability, cyber security and technology errors and omissions, the Financial Times reported. Aki Hussain, chief executive of Hiscox, told the paper it was too soon to know how US courts would treat liability for AI agents, and that a claim could land on “whatever insurance they’ve got.”

Aaron Le Marquer, head of the insurance policyholder disputes team at the law firm Stewarts, told the paper that companies hacked by agents may struggle to find ways to sue model developers, even if they incurred financial losses, because there are not yet public liability laws governing the use of online space.

The risk sits in the wording

Tifft and Jardine were asked how a cyber insurer would see an incident like that, and what companies should do before one happens.

Tifft said an AI agent attack would fall within the general definition of a cyber attack under most cyber policies, whatever the attack vector. The risk, he said, sits in the wording.

“However, brokers and clients should be aware that some cyber carriers may have AI exclusionary language which would result in this type of incident not being covered,” Tifft wrote.

He said many cyber insurers, BOXX among them, have wording broad enough to cover AI-enabled attacks and add affirmative AI cover to make the position explicit. Jardine said BOXX recently added affirmative cover for AI and deepfake-related social engineering and security failure events to its commercial cyber policy, which he said removes ambiguity for customers and brokers.

If a company is hit by an autonomous agent it doesn’t control, Tifft said, the cyber coverage that responds depends on the type of breach, such as ransomware, email compromise or social engineering, unless the policy has AI exclusionary language. He said limits, sublimits and differing waivers of retentions can apply to different coverage types within the same policy.

Coverage can also reach the supply chain, he said. If a partner or supplier is compromised by an AI agent, contingent business interruption cover may respond.

One agent, many policyholders

Tifft said one agent can affect multiple policyholders as a systemic event. The possibility has always existed, he said, but AI-enabled attacks could make it larger.

“Cyber insurers are now pricing systemic exposure into their modelling; 5-10 years ago they were not,” Tifft wrote.

What companies should do first

Jardine said the first thing companies should understand is that if they adopt AI in their operations, they may not be able to control it, and that this applies beyond rogue agents. He said companies should set policies and guidelines that allow AI use while balancing outcomes against risk.

Restricting use too tightly carries its own risk, he said.

“Over policing or restricting AI usage will drive employees to use it outside of dedicated and secure company tools, which can cause more risk through data leaks and privacy breaches,” Jardine wrote.

Read more: OpenAI admits its AI models have learned to cheat, hide their own mistakes

From an insurance standpoint, he said, organizations should find out where AI usage or dependencies exist in their supply chains and have contingencies in place for downtime or systemic outages that could severely affect operations.

He said brokers should look at how their clients use AI, so they can recommend comprehensive cyber policies and judge whether a client also needs a technology errors and omissions policy.

“Companies should ask their brokers if AI is covered in their existing cyber policy,” Jardine wrote.

Related Stories
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB CA.