An AI agent that causes a data breach may trigger a business's cyber policy. One that makes an unauthorised purchase or agrees terms with a customer could leave the same business with a loss that falls between covers.
OpenAI's decision to cancel the October release of GPT-6.1 Astra has sharpened questions about what happens when an agent acts beyond its instructions. The Wall Street Journal reported that the model took actions to complete tasks without asking for permission during internal testing, and OpenAI has confirmed it will not proceed with the planned release. The Observer has also reported that insurers are assessing the risk of providing cover for damage caused by AI cyberattacks, with liability for rogue agents still unresolved.
George Grimshaw, divisional head of cyber and technology at Clear Group, said an agent acting outside its instructions does not automatically put the resulting incident beyond existing cover.
"Most cyber policies are triggered by what happens, not by who or what caused it," he said. "If an AI agent goes beyond its instructions and that leads to a data breach, a system outage or a regulatory investigation, there's a good chance a standard cyber policy responds."
That depends on the wording not excluding the event, he said, and on the event fitting a defined trigger such as a security failure or system failure. It also depends on what affirmative AI language has been added to the policy. Grimshaw said insurers have moved to add that language across the market this year. He questioned whether naming AI exposures could introduce conditions that narrow cover which might otherwise have responded.
The picture becomes trickier when an agent does something commercially damaging, such as making an unauthorised purchase, agreeing terms with a customer or sending the wrong information to thousands of people.
"Those losses can fall between cyber, crime and professional indemnity policies," he said. "Crime cover typically needs a dishonest person or third party deception. Professional indemnity responds to claims from third parties rather than the business's own losses. That gap is where businesses should be looking hardest at their programmes right now."
When a client suffers harm, Grimshaw said the business deploying the agent will usually be first in line. To the client, the agent is acting on that business's behalf, and the business chose to deploy it. Whether it can then recover from the developer depends largely on the contract, and many AI providers cap their liability tightly or exclude it for how outputs are used.
Tim Johnson, partner and head of insurance and business and professional risk at Browne Jacobson, said courts have yet to provide clear answers on how liability will be divided between developers and the businesses deploying their agents.
“So it would depend on what loss has arisen and what's actually caused it,” he said. “Is it a defect in the model itself, or is it a defect in the way it's been used?”
Johnson suggested liability could rest with the developer where a model is used as designed, without modification. Where tools, prompts or other changes cause the loss, responsibility could instead fall on the user.
In some business-to-business arrangements, Johnson said, customers might accept an element of risk in return for a lower price.
“But equally, there are contractual mechanisms you may be able to deploy in some circumstances to mean that if the AI does go wrong, actually, you know, some of that risk may be laid off elsewhere.”
Johnson said prompts and other relevant inputs would ordinarily be disclosed and scrutinised in a claim, helping courts assess whether the user had acted negligently or breached an obligation. How the model reached its output could be harder to establish.
"Was it the prompt that was wrong, or was it the AI itself going wrong?" he said. "And without having the ability to open the bonnet metaphorically [speaking] and see the thought process, I could see there being some really tough disputes over that."
A cyber policy may respond to the breach an agent causes and leave an unauthorised purchase outside cover. If the developer's contract also limits recovery, the business could retain that loss despite having insurance in place.