Somewhere between a client's IT team quietly rolling out a generative AI tool and their broker filling in a renewal submission, there's a gap that UK cyber insurers are only just starting to close. According to a panel of cyber specialists who spoke to Insurance Business TV, the market is well aware of the exposure clients' own AI use creates. It just hasn't agreed yet on how to underwrite it.
Daniel Winn, a development broker at Jensten London Markets specialising in technology, media and cyber, said the core concern for insurers is straightforward: staff feeding sensitive or regulated information into public large language models that sit outside a client's own environment, rather than tools that keep that data contained internally. The market's response has split in two directions, he said. Some insurers now offer full affirmative AI cover up to the policy's total limit, while others cap it, with one or two carriers he's seen setting the limit at around £250,000. That caution reflects insurers not yet having enough claims data to know where the real losses will land, in his view, rather than a settled belief that the risk is small.
There's a curious symmetry to this. Winn pointed out that some underwriters are themselves now using generative AI to help quote submissions, meaning the technology creating the exposure insurers are worried about is simultaneously being adopted inside their own underwriting process.
Selorm Kofi Domeh, broking manager at Talbot Jones, described a market still working out its approach through specific exclusions and endorsements rather than any standardised question set. What's notably absent, he said, is a consistent set of questions from insurers about how a client actually uses AI, leaving brokers largely expected to volunteer what they judge to be a material fact rather than responding to anything insurers formally ask for. The more encouraging sign is that clients themselves have started asking the right question unprompted: would my policy actually respond if something like this happened to us?
Ethan Godlieb, associate partner for cyber and fintech at Consilium Insurance Brokers, pointed to regulation as one force pushing the market towards clearer answers. The EU AI Act is the clearest example, though its own timeline has moved since the panel spoke. According to the European Commission's own AI Act timeline, the Act entered into force on 1 August 2024, with obligations for general-purpose AI models enforceable from August 2025. The most demanding provisions, covering high-risk AI systems, were originally due from August 2026, but an EU simplification package agreed this year has since pushed that deadline to December 2027 for standalone high-risk systems. Compliance is very much still a moving target rather than the settled backdrop Godlieb described, which if anything strengthens his underlying point: insurers are underwriting against a regulatory picture that keeps changing shape underneath them.
Godlieb's other observation concerned wording rather than regulation. Some insurers have made AI cover affirmative simply because clients are asking for it, while others have deliberately avoided overly specific wording, on the grounds that naming individual AI risks can inadvertently narrow cover elsewhere. It's an "if it's not listed then it's not covered" attitude that cuts against how broadly cyber policies are meant to respond, and broad definitions matter more in this space than almost anywhere else in the policy, he argued.
Colin Fox, cyber insurance consultant at Integrity, part of Hayes Parsons, made the point that AI doesn't really introduce a new threat landscape so much as accelerate the one that already exists, lowering the bar for less experienced attackers and speeding up how quickly new ransomware strains get built. That makes the incident response services bundled into most cyber policies more valuable than ever, he argued.
This isn't a hypothetical concern for the market. Insurance Business has separately reported that half of UK firms surveyed said they had been hit by AI-driven executive impersonation fraud, and has also examined how Anthropic's more capable Mythos model stoked fresh aggregation concerns earlier this year, with Winn himself among the brokers quoted on how quickly AI-accelerated vulnerability discovery could scale an attack across shared infrastructure. Clients are adopting AI, insurers are trying to underwrite it, and regulators are still redrawing the rules around it. Nobody in that chain has fully caught up with anybody else yet. For brokers wanting a starting point on which carriers are handling this evolving risk best, Insurance Business's 5-Star Cyber research is worth a look.