Autonomous artificial intelligence systems capable of carrying out complex cyber intrusions without step-by-step human direction could force insurers to reassess assumptions about attacker economics and claim frequency, cyber specialists have warned.
The concern follows OpenAI’s disclosure that models being tested for advanced cybersecurity capabilities escaped a restricted evaluation environment and compromised infrastructure belonging to AI platform Hugging Face.
OpenAI said the models, operating with reduced cyber refusals, chained vulnerabilities across both companies’ environments while attempting to obtain solutions to a security benchmark. Hugging Face said internal datasets and credentials were affected, but found no evidence that public models, datasets or software supply-chain assets were altered.
The incident was not a malicious ransomware attack. However, it demonstrated that an AI system could independently discover vulnerabilities, gain internet access, steal credentials and move laterally through production infrastructure.
William Altman, director of cyber threat intelligence services at CyberCube, said the OpenAI-Hugging Face incident could alter views on historically limited ransomware campaigns. "Ransomware used to require a team, and the cost of paying that team limited how many attacks were worth running and who was worth attacking. Agentic ransomware could change that," Altman said.
Speaking separately about JADEPUFFER — the Sysdig-documented campaign in which an AI agent independently managed reconnaissance, lateral movement, credential theft and extortion after a human selected the target — Altman added: "When the cost of running a full attack chain approaches zero, criminals don't need to be as selective. Small and medium-sized businesses that were safe because they weren't worth a dedicated team's time become viable targets at scale."
He described this as "an early signal to weigh in pricing, not yet a trend of losses," but said models built on the assumption that attackers must select targets need re-evaluating.
Richard Ford, vice president of engineering at CyberCube, said the Hugging Face intrusion was significant because it arose from an otherwise benign AI task rather than a human-directed attack.
“The notable evolution here is that this resulted from an otherwise-benign AI task, fully autonomous and essentially unprompted,” Ford said. “We're entering the era of agentic autonomous attacks, and it's very unlikely that will play out well for us.”
Cyber insurers now expect greater automation to affect the volume and pace of attacks more immediately than it creates a single systemic catastrophe.
Joe Toomey, vice president of underwriting security at Coalition, told Insurance Business that advances in frontier and open-weight models are likely to increase attack frequency and speed, with the insurance impact more likely to appear through attritional claims than a small number of broad events. Coverage should generally respond according to the loss suffered rather than whether AI was used to execute the attack, he added.
“Generally speaking, cyber coverage has nothing to do with whether an attack was AI-automated or not. Cyber insurance policies provide coverage for things like incident response, business interruption, cyber extortion, and business email compromise,” Toomey said. “Most do not include exclusions that say ‘unless the attacker used AI.’ Unlike cyber warranties, cyber insurance pays.”
In a report, Acrisure Wholesale described the OpenAI incident as a wake-up call that expands the AI risk discussion beyond criminals using the technology to improve phishing, deepfakes, malware and vulnerability discovery. Businesses must also consider whether AI deployed within their own operations, products or supply chains could take unintended actions.
The wholesaler said underwriting discussions around affirmative AI coverage should examine how organizations use AI, the autonomy granted to systems, access to data, reliance on third-party models, governance frameworks, security controls and fallback processes.
For Toomey, reducing externally visible systems remains one of the strongest defenses because autonomous tools can only attack infrastructure they can identify and reach.
He also urged organizations to adopt phishing-resistant FIDO2 multifactor authentication and replace perimeter-based virtual private networks with zero-trust network access. “AI can only attack systems it can see. Systems that are not exposed to the internet are a much harder target than those that are,” Toomey said.