Artificial intelligence is creating new challenges for insurers, from understanding where AI is being used to assessing liability and identifying potential aggregation risks. While the technology is already finding its way into existing insurance lines, the industry is still working out how to identify and price the exposures it creates.
According to KYND’s analysis, the biggest challenge may not be AI itself, but the AI that insurers cannot see. The cyber risk intelligence provider explored the issue during a 1 September webinar that brought together senior cyber insurance leaders from around the world, following the publication of its The Wild West of AI Risk white paper.
The discussion found limited support for creating a standalone AI insurance product at this stage. Panellists noted that AI-related exposures already sit within existing lines, particularly cyber and technology errors and omissions, where AI use is affirmatively covered. One panellist described AI as the next stage of technology risk rather than a completely separate category.
The cause of a loss remains an important factor in determining which policy responds. If an AI-powered hiring tool discriminates against candidates, for example, the resulting exposure would still be an employment and legal issue, with the business carrying liability in much the same way as it would for a decision made by a person. Businesses developing AI themselves could face a different set of exposures and may require more specific cover.
Human involvement also featured heavily in the discussion around AI liability. Panellists highlighted that someone still selects the technology, creates the prompts and determines how much autonomy an AI system receives. The cases discussed during the webinar were linked to weak guardrails or systems being used beyond their tested limits, rather than software operating entirely independently.
The panel suggested organisations should approach AI agents in a similar way to employees, establishing clear rules, controlling access and retaining responsibility for what the technology does. That accountability can be easier to establish where AI is developed internally, but becomes more complicated when the technology is purchased from a third party or incorporated into a supplier’s product.
The clearest area of concern was undeclared AI, referring to tools used by employees or suppliers without the organisation’s knowledge or approval. Verizon’s 2026 Data Breach Investigations Report found regular AI use on corporate devices had quadrupled in a year to 45% of employees, with 67% of that activity taking place through personal accounts that businesses cannot monitor.
Gartner expects more than 40% of organisations to experience a security or compliance incident linked to unauthorised AI tools by 2030, while Capgemini found 42% of property and casualty insurers had not measured their AI outcomes.
The webinar also highlighted how stricter AI governance could potentially create another problem if employees unable to access approved tools turn to alternatives on personal devices. Rather than relying solely on restrictions, panellists discussed the importance of giving employees sanctioned AI tools that meet their needs.
KYND also drew a comparison with shadow IT, noting that its work identifying those risks has informed a forthcoming feature designed to help identify AI technologies being used by businesses.
AI is already appearing in insurance claims, although insurers may not always know when it has contributed to a loss. Claims systems generally do not have a specific category for AI-related incidents, while establishing whether AI played a role in an event can also be difficult.
An IBM study cited during the webinar found around one in four malicious breaches were AI-enabled, with an average cost of roughly $6m. This was approximately $1m higher than the average cost of a conventional breach.
The panel differed on how insurers should interpret the exposure. Some participants viewed AI as creating a systemic risk with similarities to catastrophe exposure, while others considered the underlying risk largely unchanged, with AI instead making certain capabilities cheaper and more widely available.
That increased accessibility could affect both the frequency and severity of losses, while still leaving insurers with the possibility of incorporating the exposure into pricing. The discussion also drew comparisons with previous developments in insurance, including motor cover before seatbelts and the changes experienced by the cyber insurance market during 2018 and 2019.
Aggregation was another significant concern. Between 60% and 80% of the market is understood to rely on the same small group of underlying frontier models. A serious problem affecting one provider could therefore potentially create losses across a significant proportion of an insurer’s portfolio.
Panellists called for insurers to develop a more detailed understanding of their exposure to individual models, including dependency and concentration. This would require greater visibility into which models businesses are using, alongside pricing approaches capable of distinguishing between different underlying technologies.
However, visibility only becomes useful if insurers act on the information. The panel noted that insurers already have visibility into areas such as cloud concentration, but this does not always translate into changes in pricing or underwriting appetite. Identifying AI use at the point of underwriting could provide a more detailed picture of exposure than relying on periodic questionnaires.
The webinar did not settle whether AI will eventually become a standalone insurance class. Instead, the discussion highlighted the difficulty insurers face in understanding an exposure that can be embedded throughout an organisation, including through tools that have never been disclosed to risk teams.
KYND’s analysis highlights that AI alone does not determine whether a loss is a cyber claim, while undeclared AI creates a significant visibility gap for insurers. As businesses increasingly move from experimenting with AI to relying on it across core operations, understanding where the technology is being used could become increasingly important to underwriting, claims and portfolio risk management.










