The Wild West of AI risk: key takeaways from our first Cyber Drop Live
Sell more cyber policies
Make better underwriting decisions
Reduce investment risk
Cyber risk insights for pools and executives
By KYND
Put a room of senior cyber market leaders together and ask whether AI deserves its own line of insurance, and you might expect a shouting match.
Instead, our inaugural Cyber Drop Live delivered something far more useful: genuine disagreement about where AI cover should sit, and striking consensus about where the real risks lie.
The discussion centred on one question:
Does AI need its own line of insurance, or is it simply changing the risks the market already covers?
Across the room, opinions differed. But several themes emerged again and again.
Putting ‘AI’ in front of a risk does not automatically make it cyber.
The biggest exposure may be the AI nobody knows is being used.
Claims are arriving before reliable loss data.
And whatever shape AI insurance eventually takes, visibility has to come first.
Only a handful of people in the room backed a standalone AI line today.
One of the clearest messages from the discussion was that the presence of AI in a claim does not necessarily change where that claim belongs. The underlying cause of loss still matters.
An AI washing lawsuit, where a company is accused of overstating its AI capabilities to investors, remains a D&O issue. A biased recruitment tool creates an employment practices exposure, just as a biased human decision-maker would have done before it. AI may change how the loss occurs, but not necessarily the insurance product that should respond.
Nobody argued that the existing insurance map covers everything, though.
Work through the exposures and a residual layer remains: first-party loss caused by the technology underperforming because probabilistic software can produce the wrong answer by design. A drifting or hallucinating model may not represent a conventional controls failure, which leaves cyber underwriters asking a reasonable question: what does that have to do with cyber?
The unresolved issue is whether that residual exposure justifies a completely new product, or whether it should become part of an expanded risk horizon for the underwriters already closest to it, particularly in cyber and technology E&O.
One warning from the room resonated strongly. Clients have little appetite for buying ‘a gap filler of a gap filler’. Responding to every emerging technology by telling businesses they need another policy may do little for the industry's credibility.
The research behind our new white paper, The Wild West of AI Risk, points to a pattern that the room returned to repeatedly: most AI losses will not look like a traditional cyber breach.
In many cases, the technology will work exactly as intended. It will simply make the wrong decision.
That exposure can play out across several areas:
Discrimination in hiring and lending
Copyright and intellectual property infringement
Confidential information being entered into public AI tools
Hallucinations that cause financial loss
Physical harm or property damage caused by incorrect advice
A sixth issue also surfaced during the event: business interruption. What happens when a company has built critical processes around AI systems and those systems suddenly fail or become unavailable?
The stories shared in the room made the risk more tangible.
One story made the risk tangible. An AI coding agent operating under an explicit code freeze deleted a company's production database, kept reporting that everything was fine, and only admitted what had happened when it could not produce a sales record from the previous 30 minutes. No attacker, no conventional outage, and a business at a standstill all the same.
That example led to one of the sharpest technical discussions of the day.
System failure cover under a cyber policy will typically require an unplanned outage and a material interruption or degradation of the network. A hallucinating model may produce neither. The network remains healthy, but its outputs are unreliable or actively harmful.
One estimate offered in the room captured the uncertainty well. Imagine 50 plausible AI hallucination scenarios and instinct suggests that around half might fall within cyber cover, while half might not.
For brokers and others representing buyers, that ambiguity is difficult to explain and even harder to sell.
Then came proximate cause. A data poisoning attack may fall within a cyber policy. A hallucinating model, in isolation, may not. So when a poisoning attack causes a hallucination that causes the loss, which link in the chain counts for coverage? Unresolved, and a sign that AI risk will not fit neatly inside a single product or peril definition.
One of the more counterintuitive findings from the discussion was that imposing more controls does not always reduce AI exposure.
The more tightly an organization restricts approved AI tools, the more likely employees may be to reach for an alternative on a personal device. Shadow AI can thrive on prohibition.
That led to perhaps the strongest consensus of the day. The greatest AI risk is not necessarily the sophisticated system surrounded by governance, controls, and monitoring. It is the silent AI that nobody owns, nobody monitors and, in some cases, nobody knows is being used.
The comparison the room repeatedly returned to was silent cyber.
The market only fully confronted that exposure after NotPetya in 2017, when malware spread far beyond its intended target and generated losses under policies that had never been written with cyber events in mind.
The danger is that the market repeats the same pattern with AI: waiting for a major event before pricing the exposure, measuring it or gathering the data needed to understand it.
The room broadly agreed that claims involving AI are already being paid, but they are not necessarily being identified or recorded as AI-related losses.
Claims coding struggles with much simpler causes, and attribution is difficult. Even people who build AI models cannot always prove that a particular output was generated by AI.
That creates an immediate challenge for underwriters. The market is being asked to assess, price and manage an exposure before it has a reliable loss history.
The conversation also distinguished between losses caused by AI systems and fully AI-automated attacks. A review of recent claims data discussed during the session found roughly one visible example of an end-to-end attack automated by AI. Today, running an entire attack chain through frontier models may still be uneconomic or impractical.
Nobody in the room expected that position to hold. The prudent assumption is that the capability will reach malicious actors, which means the market's immediate task is to capture the right signals now, before the claims data becomes mature enough to guide it.
The session closed with a thought experiment.
Imagine that tomorrow you had complete visibility of every AI model, every insured, every dependency and every area of concentration across your portfolio.
What would you do first?
Most groups began in the same place: accumulation. They wanted a model-by-model view of dependency, single points of failure and market concentration. They also wanted more granular pricing, recognising that different models may present materially different levels of risk.
There was also an important note of realism. Insurers can already see significant cloud concentration across their portfolios, yet that information is not always reflected in pricing or appetite decisions.
Visibility, therefore, is not the whole answer. It only becomes valuable when the market acts on it. But it remains the prerequisite for pricing AI exposure, assessing accumulation and deciding where the risk belongs.
We did not leave the room with consensus on whether AI should become a standalone class of business.
In many ways, that was not the point.
What we did leave with was a clearer view of where the market currently agrees: AI is not automatically a cyber risk, the most dangerous exposure may be the AI nobody knows is being used, and whatever the future shape of AI insurance looks like, visibility has to come first.
The market may also have less time than it thinks. One attendee described a global restaurant business that expects to be operated end to end by AI in 2027 and is already asking whether its existing insurance arrangements will still respond.
That is exactly why we created Cyber Drop Live. Not to force consensus, but to bring the market together to debate the questions that will shape what comes next.
Our white paper, The Wild West of AI Risk, is out now. And if this discussion has left you with views of your own, good. Cyber Drop Live returns in October. Bring them with you.
The Wild West of AI risk: key takeaways from our first Cyber Drop Live
PRESS RELEASE: Hidden AI exposure could leave insurers facing growing accumulation risk, warns KYND
PRESS RELEASE: Insurers look beyond exposure assessment with new insight into risk remediation
Accreditation & Features