ICAEW.com works better with JavaScript enabled.

Cyber: assessing your insurance for the AI age

Author: ICAEW Insights

Published: 05 Oct 2026

AI is intensifying the scale and frequency of cyber attacks against businesses. Experts tell us what this means for insurers and the companies that will be seeking their protection.

Key takeaways

  • UK cyber insurance and AI: The growth of generative AI is affecting cyber insurance in two ways: its use by threat actors to make attacks faster and more convincing, and the risk of business’s AI systems taking unauthorised actions with no attacker involved.
  • Assessing cyber maturity: UK cyber insurers are asking more questions when writing policies to incorporate AI governance alongside areas such as multifactor authentication and employee training.
  • AI liability insurance: To address the risks of AI systems and agents acting outside of controls and causing breaches, the global insurance market is developing AI liability insurance, although it is currently very new and not available in all jurisdictions. 

Artificial intelligence (AI) is spurring a dramatic shift in how businesses must think about cyber security and relevant insurance coverage.

In its 2026 Data Breach Investigations Report, telecoms giant Verizon stressed that malware fuelled by generative AI (Gen AI) “is now a common occurrence”. In tandem, businesses face growing concerns around impersonation. For example, in June 2026, the Amsterdam District Court sentenced a 34-year-old man to 30 months in jail – with six suspended – for using a string of AI deepfakes based on illegally sourced ID documents to open dozens of fraudulent bank accounts at ABN Amro.

Prefer to listen?

Allow SoundCloud audio

This audio player is provided by Soundcloud, a third-party service. We ask for your permission before anything is loaded as SoundCloud places cookies on our site. For more information on how we handle cookies, please see our privacy policy and cookies policy. To listen to this content on the website, please accept Statistics cookies and continue. Alternatively, you can access ICAEW podcasts on Spotify, Apple podcasts or YouTube.

Disclaimer

This audio file was produced by AI and has been adapted from the original article for audio purposes.

“AI is changing the threat landscape,” says Charlotte Hill, Deputy Chair at specialist body the Cyber Insurance Association. “Mainly, it’s changing the scale of attacks. Criminals no longer need to target one organisation at a time – they are now able to target a vast amount in one go. And while SMEs were once protected to an extent by the fact that they were thought too small to be attractive targets, AI has slashed the attack costs.”

Hill warns that gangs of cyber criminals are increasingly working in office-style setups: a dark-side version of professional services. “It’s their day job,” she says. “Small businesses often won’t have the budget to fund protection from such organised types of attacks in the first place, let alone the right level of cyber insurance and incident recovery planning.”

Insurers are assessing clients’ cyber maturity

“AI affects insurance in two different ways,” says Peter Wedge FCII, the Cyber Insurance Association’s Chair. “First, threat actors can use it to make familiar attacks faster and more convincing. At the same time, businesses’ own AI systems can disclose data, generate erroneous outputs or take unauthorised actions with no attacker involved.”

In that context, it has never been more vital for businesses to purchase cyber insurance. But it is equally important for that insurance to evolve. Based on what Hill has seen as Partner at law firm Pennington Manches Cooper, where she leads a dedicated Cyber Security Team, she believes that insurers are becoming much more sophisticated in their assessment of clients’ cyber maturity.

Expect more questions from insurers

The core principles, she notes, have not changed: insurers are still focused on areas such as multifactor authentication, incident report logs, employee training, access management, privileged documents, third-party risk, data protection and the regularity of attack tests. But when underwriting policies, they are asking more questions, and so are brokers when trying to determine which policies are most suitable for their clients.

Looking at how that could develop, Hill says: “I think insurers will become much more interested in the AI governance controls that organisations deploy internally. Right now, it’s still very much about cyber security and ensuring we’re all resilient as businesses. But there will have to be growing scrutiny of AI matters, because claims are going to be made. Insurers will need to test where on those issues cyber security policies respond, and where they do not.”

Check the wording of your policies

On the other side of the coin, Hill notes, businesses will have to pay much more attention to how their policies are devised.

“There’s a greater emphasis now on businesses understanding their policies’ wording, in terms of what coverage they actually have, and checking the definitions of what qualifies as a cyber incident,” she says. “What are the notification requirements? Are they any different because you’re going down an AI route? What are the exclusions or sub-limits? Make sure the risks you’re anticipating are covered. If you think they’re not, speak to your broker.”

In that sense, Hill points out, insurance fundamentals remain the same, but clients will need to be more proactively invested in reviewing their policies.

Wedge agrees. “AI marks a gradual move from what’s known as silent cover to affirmative cover,” he says. “Up to now, policies didn't say whether AI-driven losses were covered or excluded. For peace of mind, clients now want it mentioned. If it’s written down, there’s nothing to argue about later.”

AI liability might become necessary

Turning to the sorts of things a client would need to demonstrate to receive a payout, Wedge says: “In principle, it doesn’t really matter, as long as the policy deals with whether or not an incident is caused by AI. If your policy defines a cyber attack as unauthorised access to your computer system, you're home and dry. But it goes back to my earlier point: do you want your policy to explicitly state that it covers unauthorised access driven by AI?”

However, it is becoming clear that AI matters are testing the limits of the capabilities of traditional cyber insurance. In recent months, three of the world’s biggest AI firms – Meta, Anthropic and OpenAI – have all confirmed that AI agents they built went rogue during testing. 

The need for insurance to address the types of corporate incidents that could arise from those and other AI-specific flaws and risks is pressing. But standard cyber insurance is not cut out to do so, because it does not cover the liability of a company’s own AI agent(s).

As such, businesses should keep a close eye on the nascent field of AI liability insurance, which is aiming to fill the gaps. Alongside his role at the Association, Wedge serves as General Counsel at Testudo, a Lloyd’s-backed managing general agent that provides businesses with coverage for harms stemming from their deployment of Gen AI tools. 

“We cover Gen AI errors leading to financial loss, unauthorised data disclosure, AI regulatory violation, intellectual property infringement, property damage and bodily injury.” he explains. “But AI liability insurance is still very new. We’re only offering it in the US so far.”

Cyber security awareness

Each year ICAEW marks global Cyber Security Awareness month with a series of resources and a podcast addressing the latest issues and how to protect your business.

More support Listen to our podcast
Cyber security button with lock on top

Further resources

Resources
Laptop and tablet on a desk displaying a lock icon with the words “Privacy Policy,” while a person holds a smartphone showing a security-related graphic.
Cyber security

Our cyber security resource centre provides a focal point for ICAEW members looking for support in managing cyber risks.

Browse resources
Support
Computer screen with text relating to generative AI
Artificial intelligence

Browse ICAEW resources aimed at helping members to build their understanding of AI, including opportunities and challenges it presents.

Support on AI Masterclass videos
ICAEW support
A person holding  a tablet device displaying various graphs
Training and events

Browse upcoming and on-demand ICAEW events and webinars focused on making the most of the latest technologies.

Events and webinars CPD courses and more
Open AddCPD icon