The AI you can't see: Key takeaways from our Cyber Drop webinar
Sell more cyber policies
Make better underwriting decisions
Reduce investment risk
Cyber risk insights for pools and executives
By KYND
When we released our The Wild West of AI Risk white paper, we set out to explore a question that’s becoming increasingly important for the insurance market: does AI need its own line of insurance, or is it simply changing the risks the market already covers?
On 1 September, KYND brought together a panel of senior cyber insurance leaders from around the world to take that conversation further and explore some of the other challenges AI is creating for the industry.
Read on for the key takeaways from our webinar.
Very few on the panel saw a case for a standalone AI product today. AI already sits within the lines being written: mostly cyber and technology errors and omissions, and it is affirmatively covered. One panelist called it the next stage of technology risk rather than something separate.
What matters is that the cause of a loss still decides which policy responds. If a hiring tool discriminates, that is an employment and legal matter, and the company is liable just as it would be for a human decision. The exception is businesses that build AI rather than use it, which may need dedicated cover for the exposure they create.
On AI liability, the panel kept returning to the fact that a person is always involved. Someone chose the tool, wrote the prompt, and decided how much freedom to give it. The cases they had dealt with came from poor guardrails or systems tested outside their limits, not from software acting alone.
Their suggestion was to treat an agent like an employee: clear rules, controlled access, and the organization responsible for what it does. That is easy to trace when the AI is built in-house, and much harder when it is bought in or embedded in a supplier's product.
The clearest consensus was around the AI nobody has declared: the tools staff and suppliers use without telling anyone, often without IT's knowledge. Verizon's 2026 Data Breach Investigations Report found regular AI use on corporate devices quadrupled in a year, to 45% of employees, and 67% of it ran through personal accounts businesses cannot monitor. Gartner expects more than 40% of organizations to face a security or compliance incident from unauthorized AI tools by 2030, and Capgemini found 42% of property and casualty insurers have not measured their AI outcomes.
Stricter AI governance rules can make this worse, because people blocked from approved tools reach for unapproved ones on their own devices. The better approach, the panel felt, is a sanctioned option good enough that nobody looks elsewhere.
The parallel was also drawn to shadow AI, and KYND shared that just as it helped identify that risk, it now has a forthcoming feature that enables identification of AI technologies.
AI is already showing up in claims, even if it is rarely recorded that way. As one underwriter put it: if they have had an AI claim, they might not know it. This is because claims systems have no category for it, and attribution is hard. One IBM study cited in the session found around one in four malicious breaches were AI-enabled, at an average cost of roughly $6 million, about $1 million more than a conventional breach.
The panel split on how to treat it. Some saw a systemic exposure closer to a catastrophe risk. Others felt the risk itself has not changed, only its distribution, with cheaper capability in more hands raising frequency and severity that can be priced. Both drew on the same history: the market wrote motor cover before seatbelts existed, and cyber rebuilt itself through 2018 and 2019 before returning to profit.
Aggregation was the exposure the panel was least comfortable with. 60% to 80% of the market builds on the same small group of underlying frontier models, so a serious problem at one provider could hit much of a portfolio at once. They wanted a model-by-model view of dependency and concentration, and pricing granular enough to tell those models apart.
Visibility only helps if the market acts on it, and insurers can already see heavy cloud concentration without it always feeding into pricing or appetite. Even so, nothing can be priced or placed until it can be seen, and identifying where AI is used at the point of underwriting does more than another annual questionnaire.
The session did not settle whether AI becomes its own class, and that was not the aim. The panel largely agreed on three things:
1. AI does not make a claim a cyber claim by itself
2. the exposure to worry about most is the one nobody declared
3. and none of it can be properly priced until it can be seen.
And the scale of the exposure is growing rapidly. One panellist described a business already running almost all of its operations on AI, a very different risk from one just starting out.
You can watch the full session back below, and check out our white paper The Wild West of AI Risk, for an in-depth perspective.
If you’d like to learn more about how you can see the AI tools a business runs, get in touch.
The AI you can't see: Key takeaways from our Cyber Drop webinar
PRESS RELEASE: KYND joins Anthropic Cyber Verification Programme to advance AI-driven cyber risk assessment for insurers
The Wild West of AI risk: key takeaways from our first Cyber Drop Live
Accreditation & Features