Cyber underwriters have spent the past year debating a hypothetical: what happens when an AI system runs an entire attack on its own, with no human directing each step? Suspected Chinese hackers appear to have just supplied a real example, and the details expose two gaps that show up directly in how US cyber policies are written today.
Over four days at the start of July, researchers at Dream, an Israeli cyberdefense firm, say a hacking tool built from two open-source AI agent frameworks, Hermes and OpenClaw, ran largely on its own inside Taiwanese government systems. According to Dream's findings, first reported by the Financial Times, up to eight agents worked at the same time, mapping 21 government systems, probing for weaknesses, and switching tactics when blocked. The operation reportedly compromised at least 85 government accounts, took more than 2,500 personnel records, and expanded into Taiwan's nuclear safety agency and at least seven energy companies.
Dream has not confirmed the target on the record, citing company policy, though a person familiar with the matter identified it as Taiwan. Researchers said internal messages tied to the operation were written in simplified Chinese, the script used on the mainland, while the data taken from the target was written in traditional Chinese, the standard in Taiwan, Hong Kong and Macau. That contrast is part of why analysts suspect a China-linked operator. No formal attribution has been made, and Beijing has not responded publicly to the allegations.
That gap between strong suspicion and formal attribution is the first problem for insurers.
Cyber policies increasingly carve out war and nation-state activity, but those exclusions depend on someone being able to say, with confidence, who was behind an attack. Dream's own researchers stopped short of formally pinning the Taiwan operation on Beijing despite the circumstantial evidence. In a related dispute over attacks on US water utilities, one lawyer noted that coverage outcomes can turn on whether an incident is ultimately traced to a state-backed group, and that mixed signals or incomplete forensics can leave that question open for months. Insurers have been tightening war and nation-state language for exactly this reason, even as analysts at Conning have argued that systemic, state-driven cyber losses may be beyond what the private market can absorb alone, pointing toward a public-private backstop similar to terrorism risk pools.
The second problem is more basic: a number of cyber forms still define a "hacker" as a person. Tim Johnson, head of insurance at law firm Browne Jacobson, has pointed out that this leaves open whether an autonomous AI attacker even triggers coverage as written, an ambiguity that could cut either way for a policyholder depending on how it is eventually tested in court. Five Eyes intelligence agencies have separately warned that AI-driven attacks of this scale could become common within months.
Some carriers are already responding. Caspar Rogers, a senior broker at Assured, expects language similar to Chubb's earlier Widespread Vulnerability Exclusion to be revisited across the market as underwriters try to limit exposure to a single AI-enabled event affecting many policyholders at once. Christopher Keegan, cyber practice leader at Brown & Brown Risk Solutions, has described the broader market as holding steady for now, competitive and profitable and not yet repriced for this specific risk, though he has also warned that once an attacker gains an initial foothold, AI is unusually effective at moving that access laterally toward an organization's most sensitive systems. On a recent industry panel, Marsh Specialty's Kelly Butler noted that the list of top-tier cyber threats no longer has one clear leader, with AI-enabled social engineering and nation-state activity against operational technology both rising fast.
Taiwan is the third publicly disclosed incident of an AI system running an attack with minimal human involvement inside about a year, and the pace is accelerating. Anthropic disclosed in a November 2025 report that a suspected Chinese state-sponsored group had manipulated its Claude Code tool in September 2025 to target roughly 30 organizations, with AI handling an estimated 80 to 90 percent of the operation. That followed an earlier case Anthropic disclosed in August 2025, in which a different actor used Claude to automate data theft and extortion against at least 17 organizations. And in late July 2026, Palo Alto Networks' Unit 42 reported that a Chinese-speaking individual had wired the DeepSeek model into the same Hermes framework used in the Taiwan attack, then set it loose over Telegram against more than 460 internet-facing systems, breaching 14 by chaining together known, unpatched vulnerabilities.
None of these campaigns relied on novel hacking techniques. What changed is speed: work that would once have taken a skilled team days or weeks is now compressed into hours of largely unsupervised activity, running around the clock. At the Black Hat security conference in early August, OpenAI staff called this kind of autonomous, collaborating attack agent a watershed moment for the industry, and warned that criminal groups will likely build their own coordinated agent networks rather than relying on single tools.
Taiwan is already living with the consequences of that shift more than most. Its National Security Bureau reported an average of 2.6 million Chinese-origin cyberattacks a day in 2025, up 6 percent on the year before, against the backdrop of Beijing's continuing claim to the island and its stated willingness to take it by force.
Underwriters evaluating risk in critical infrastructure or government-adjacent sectors now have three documented examples, not one, of what an autonomous or near-autonomous intrusion looks like from start to finish: reconnaissance, credential theft, lateral movement, all compressed into a fraction of the usual timeline. Whether that changes pricing, exclusion language or claims handling will likely come down to two questions the market has not fully answered yet: who counts as the attacker when the tool did most of the work, and who was actually directing it.