Aon has called for stronger cyber risk management practices following an April 2026 open letter from the UK government warning that AI is now capable of finding software weaknesses and writing exploits at a speed and scale that would have been impossible even a year ago. The government's own assessment puts a number on that acceleration: the AI Security Institute found frontier AI cyber-offence capability is now doubling roughly every four months, twice the rate seen previously, with recent testing finding Anthropic's Mythos model substantially more capable at cyber offence than any system assessed before it. Rob Kemp, CEO of Commercial Risk in the UK for Aon, said the firm's Global Risk Management Survey found cyber attacks and data breaches remain the top enterprise risk in 2026, expected to continue into 2028, with many businesses describing themselves as only somewhat prepared - citing fragmented governance and limited testing of AI-driven incident scenarios. Some organisations are still treating AI as a future issue and delaying critical cyber risk management strategies, Kemp said.
Aon said AI has not changed the fundamentals of cyber risk management but has significantly increased the scale and likelihood of attacks. It is encouraging businesses to focus on core controls - patching, vulnerability remediation, staff training on phishing and social engineering - and stress-test them against AI-enabled scenarios, including checking whether existing policies respond to AI-related incidents.
The same AI capabilities accelerating attacks, faster reconnaissance, automated exploitation, harder-to-trace attack chains, also make it harder to quickly attribute an attack to a specific actor. All three threads in this story are really the same problem seen from different angles: governance, policy wording, and pricing all still assume attacks move at a pre-AI pace, and each is now being forced to catch up on its own timeline.
The wording problem has real legal scars behind it. Insurers spent years relying on traditional "hostile/warlike action" exclusions to deny cyberattack claims, until Merck & Co. v. ACE American Insurance Co. tested that approach against the 2017 NotPetya attack — a Russia-linked cyberattack that caused Merck more than $1.4 billion in losses. US courts sided with Merck, finding that a Cold War-era war exclusion couldn't be stretched to cover a cyberattack with no formal declaration of war behind it; the dispute ended in an undisclosed settlement in early 2024 rather than a final Supreme Court ruling, but the underlying finding stood. That's the backdrop against which London's own model wordings for excluding state-backed cyberattacks were rebuilt. The LMA's LMA5567A/B clauses shift the exclusion test away from attributing an attack to a state and toward whether it caused significant impairment at a national infrastructure level - refining exclusions first introduced in 2022 following the Russia-Ukraine war, rather than retreating from writing the class. In plain terms: instead of insurers and policyholders arguing over who was behind an attack before cover kicks in or drops out, the newer wording asks a more answerable question - how much damage did it actually do to critical national infrastructure. That's a practical response to a world where attribution is becoming harder to establish quickly, if at all - and where a fight over "who did this" can no longer be assumed to settle a claim the way it once could.
The UK cyber insurance market remains highly competitive despite the evolving threat environment. Cyber premiums fell by an average of 11% across 2025 even as incident volumes rose to unprecedented levels, according to broker Lockton, which also found the number of insurers underwriting cyber risk in the London market has grown from around 25 in 2020 to roughly 45 in 2025 — a big part of why rates keep softening even as the threat gets worse. Marsh's 2026 UK cyber outlook similarly describes rising demand and expanded insurer capacity keeping premiums relatively low, with new products addressing AI-specific risk beginning to emerge.
That pricing environment sits awkwardly alongside a tightening regulatory picture. The Cyber Security and Resilience Bill, currently before the House of Lords, is expected to expand mandatory security and incident reporting requirements to a wider range of managed service providers, data centres and critical suppliers — broadening the population of organisations with formal cyber obligations at the same moment AI is making the underlying threat more severe. High-profile incidents including the 2025 cyberattack on Jaguar Land Rover have driven rising cyber insurance awareness among UK businesses — yet a GlobalData survey of UK commercial insurance brokers found more than 60% of UK SMEs still carry no cyber cover at all, even as over half of brokers surveyed expect cyber to be the strongest-growing product in their book.
For brokers, the practical takeaway sits underneath all three threads above: a soft market makes this a good moment to push clients toward broader cover rather than just cheaper cover. That means checking whether a client's existing wording actually responds to an AI-enabled incident rather than only a conventional data breach, understanding where the LMA5567A/B threshold would leave a client exposed if a state-linked attack fell short of "significant impairment" of national infrastructure, and using the current buyer's market to negotiate broader terms while capacity remains this abundant - because that leverage tends to disappear quickly once a market-changing loss event resets pricing.
The gap between rising AI-enabled threats and still-developing governance - in both corporate risk management and insurance market exclusion wordings - suggests insurers and risk managers alike are still catching up to a threat moving faster than either side's frameworks.