Insurance firms have always had to look to the future and prepare for potential outcomes. However, amid growing instability, that task has become much harder.
As Matthew Twist, vice president, EMEA at Earnix, stated, “Risk has always been about trying to see what’s just over the horizon. The challenge today is that the horizon is shifting faster than ever.”
Whether it is an evolving technology landscape ready to be exploited by illicit players, the increasing frequency of major climate events or growing geopolitical uncertainty, instability is rising across the board. Even areas that once felt dependable have started to falter, leaving insurers to conside where new risks could emerge.
Twist noted, “Insurance has never been about predicting the future with certainty. It’s about reducing uncertainty enough to make confident decisions. The difficulty today is that emerging risks no longer develop over decades. They can materialise in months, sometimes weeks, and they rarely arrive in isolation.”
This environment has left businesses carrying risks they may not truly understand, know how to quantify or even perceive. Twist emphasised that many will be carrying risks that don’t fit historical models simply because the world generating the risks is changing faster than the data behind them. For instance, cyber threats evolve daily, supply chains are reshaped by geopolitical events and climate risk are becoming increasingly localised and interconnected.
“The issue isn’t that businesses are ignoring these risks; it’s that traditional approaches struggle to keep pace with them. That makes continuous assessment far more important than periodic review.”
Adding to the complexity is the fact that much of the risk a business carries now sits outside the business itself, whether through suppliers, shared platforms or external software. Melanie Hayes, co-founder at KYND, noted, “That is accumulation risk, and it is concentrating rather than dispersing. The same handful of technologies sits behind thousands of businesses, so a single flaw can surface across many of them at once.”
The growing power of AI is making these risks even more difficult to manage. These tools are giving illicit players power they have never had before, scaling their efforts to find weaknesses at unprecedented speed. With each new model, their ability to uncover niche gaps grows. For instance, a recent high-profile example of this was Anthropic’s Claude AI, which escaped a closed test and hacked three systems.
These models can give someone the ability to run advanced attacks simultaneously with little input. Hayes noted that these tools can compress the time between a vulnerability being discovered from days to hours, while most organisations remediate over weeks, or even months.
Another cause for concern is the increased use of AI across hiring, customer service and everyday decision-making. This is all happening quicker than most businesses can track, increasing the level of risk exposure without proper controls.
Hayes said, “The encouraging part for insurers is that a lot of this is now externally observable. The exposure a business struggles to see in itself is increasingly visible from the outside, and that is where the opportunity sits: to help organisations identify cyber risks before the worst happens, and to stay on top of them so resilience holds up through a landscape that keeps shifting.”
Identifying emerging risk
As risks continue to evolve rapidly, more insurers could look to provide additional support to help their clients identify emerging risks before they become claims.
As such, Earnix’s Twist noted there is a growing role for strategic risk advisory alongside traditional intermediary functions. In practice, this gives greater value through risk insight and mitigation by helping clients understand changing exposures, sharing market intelligence, stress-testing assumptions and using live data to support decisions.
He said, “Prevention, preparedness and resilience are becoming just as valuable as indemnification.”
Hayes shared the same vision of the future: one where insurers provide clients with greater support to protect themselves in a changing environment. However, the best way to support them, according to Hayes, is through continuous monitoring across the policy lifecycle.
She said, “Placement is where the risk begins, not where it ends. A policy is bound at a single moment, but the exposure behind it changes every week after that. Continuous monitoring across the policy lifecycle changes what underwriters and MGAs can do: instead of pricing a risk once and looking again only at renewal, they can see exposure shift in-life and respond while there is still time to act on it.
“That matters most for the fastest-moving risks: newly disclosed zero-day vulnerabilities, software flaws attackers are exploiting before a fix exists, and known exploited vulnerabilities, the CVEs (Common Vulnerabilities and Exposures) already being used in live attacks.”
Earlier this week, over 100 tech giants, as well as several financial institutions, came together to issue a warning about the rising threat of AI on cybersecurity. They called for a defensive surge to help counter increasingly sophisticated attacks, which they warn are on the horizon. The group, which includes Microsoft, Anthropic and OpenAI, state current “status quo” security measures will not stop AI-powered attacks and called for governments to support the development of technology to help firms boost defences.
With this increased risk from online threats, insurers need to move to a proactive approach for their policyholders. Hayes added, “When AI collapses the window between disclosure and exploitation to hours, an annual questionnaire or a point-in-time risk assessment can only tell you so much. Watching for critical posture changes, as well as zero-day and CVE exposure across a book as it emerges, lets an underwriter identify a materially exposed insured before an incident becomes a claim.
“The value moves from pricing at a single point in time to managing risk continuously. An underwriter who can see ‘this insured is exposed to this, today’ is doing something a risk snapshot cannot. It turns the policy from a static contract into proactive risk management: an early warning system that moves the focus from premium to loss prevention and lets both insurer and insured act before an exposure becomes a claim.”
Closing the gap with technology
Central to insurers’ ability to close the risk blind spot is technology. Both Hayes and Twist emphasised its importance to solving the challenge.
Hayes explained, “Technology’s job here is narrower, and more useful, than it is often sold as. It makes exposure visible before a loss, not after. The blind spot is fundamentally a visibility problem, and much of it is externally observable.
“You do not need to be inside a business to see which AI services it runs, which software is out of date, or where its cyber hygiene controls are missing.”
A recent survey from KYND of nearly 9,000 SMBs found that 54.9% of North American SMBs lacked basic email security controls and around half had outdated software. “These are not exotic AI-era risks. They are basic, measurable and preventable, and they still sit unaddressed across most books.”
AI simply raises the stakes on the same problem. In another study from KYND, The Wild West of AI Risk, it spoke to carriers, brokers and MGAs. They all disagreed on many things surrounding AI, apart from one area: the biggest gap is visibility and most of AI’s exposure can be seen externally. “That is exactly where technology earns its place, turning a fast-moving and largely undeclared exposure into something measurable before it becomes a loss.”
“That gap is also the growth story.” She explained that SMBs are the largest underserved segment within cyber, with estimates putting less than 10% of firms with this insurance. This market is where better data can make a real difference.
“Fresh, accurate insight lets insurers write cover they would otherwise decline or guess at and supports the segment’s growth rather than treating it as a risk to avoid. That is also the honest limit of technology. Data, analytics and AI can surface exposure with precision, and adapt as new AI-driven risks emerge, but they cannot set risk appetite, price a loss with no claims history, or act for the insured. The role for InsurTech is not to replace judgement. It is to give underwriters fresh, decision-ready insight, so that judgement rests on current, confirmed facts.”
Twist described technology as “indispensable”. Its ability to process the volume of data required for modern insurance decisions is not possible by an individual. AI can identify patterns, surface weak signals and collate data that would have remained disjoined. However, this does not mean technology replaces people; it is an assistant to trained professionals that can help make the right decisions. “In insurance, decisions carry financial, regulatory and human consequences. That’s why AI in our sector needs to be purpose-built for insurance, governed and transparent, with experienced underwriters and brokers remaining firmly in the loop.”
Looking ahead
As risks continue to evolve, insurers will increasingly look to address the risk blind spots, and the winners and losers will be defined by how effectively they respond.
For Twist, the gap will be defined by those helping clients make better decisions before a loss occurs.
“The best brokers and MGAs will combine specialist expertise with technology that gives them a clearer, more dynamic view of risk, pricing and exposure. They’ll use AI and data to augment experience, not substitute for it. Those businesses will become trusted partners in resilience, rather than simply distributors of insurance products. That’s where the market is heading, and clients will increasingly expect nothing less.”
Hayes, on the other hand, believes the differentiator will depend on whether firms can see the risk and not just place it.
“Distribution alone is becoming a commodity. What is scarce, and getting scarcer, is the ability to tell a client something about their exposure they did not already know. The brokers and MGAs that pull ahead will be the ones who bring visibility to the table: continuous, confirmed, current data on where a client is exposed and how that is changing.”
Copyright © 2026 InsurTech Analyst










