AI Is Changing Cyber Risk: Is Your Insurance Program Changing With It?
September 15, 2026

Artificial intelligence (AI) is changing both how businesses operate and how cyber threats are carried out. Phishing, business email compromise, social engineering, and fraudulent payment schemes are not new risks, but AI is making them more convincing and increasingly difficult to detect. Deepfake technology and AI-generated communications are adding new layers of complexity to an already evolving cyber landscape.
As organizations continue adopting AI tools, it is worth taking a closer look at how those technologies may influence cyber risk. Understanding where AI is being used within your organization, the exposures it may create, and the details of your insurance program can support more informed risk management and coverage decisions.
What is AI Cyber Risk?
AI cyber risk refers to cybersecurity, fraud, privacy, and operational exposures that can arise when an organization uses artificial intelligence or when cyber criminals use AI to make attacks more effective.
These risks include:
- AI-generated phishing and social engineering attacks
- Business email compromise and fraudulent payment instructions
- Deepfake voice or video impersonation
- Unauthorized disclosure of confidential information
- Data corruption or deletion
- Business interruption and other operational disruptions
For years, employees were trained to look for misspellings, awkward language, and unusual requests as signs of phishing. Generative AI has made those clues less dependable and the threats more convincing. Attackers can create polished messages, imitate familiar writing styles, and produce realistic invoices or payment instructions.
Deepfake technology adds another layer of concern. AI-generated voice or video may be used to impersonate executives, employees, vendors, or other trusted business contacts. A request can look and sound legitimate, which makes consistent verification procedures more important.
Claims data emphasizes this concern. Resilience reported that phishing, social engineering, and transfer fraud accounted for 85.3% of incurred losses in its portfolio during the first half of 2026. This data applies to Resilience's portfolio, not the cyber insurance market as a whole, but it illustrates the financial impact of attacks that rely on human trust.
The practical takeaway? AI does not need to create a new kind of cyberattack to change an organization's risk; rather, it can make existing attacks more convincing and easier to scale.
What Happens When AI Creates New Cyber Insurance Questions?
There is another emerging risk that may prove even more complicated for the insurance industry: agentic AI.
While many discussions focus on AI-powered attacks, organizations should also consider risks that may arise from their own use of AI tools, particularly when those tools have access to systems, sensitive information, or business processes.
Some AI systems can do more than respond to a prompt. With the right permissions, an AI agent may access applications, work with data, execute a workflow, or communicate with another system. That raises a practical question: What happens if an organization authorizes an AI agent to act, but then the agent takes an unintended action?
An AI agent could inadvertently:
- Disclose confidential customer or business information
- Delete, alter, or corrupt critical data
- Interrupt business operations
- Send information to the wrong third party
- Introduce malicious code or create a security vulnerability
- Initiate an action that leads to financial loss
In these scenarios, there may be no traditional hacker and no unauthorized access in the conventional sense. The organization could still face a significant loss. As AI adoption accelerates, insurers, brokers, and policyholders will increasingly need to examine how existing cyber policy definitions and coverage triggers respond to these scenarios.
Cyber Insurance Wasn't Designed in an AI Vacuum: How Cyber Insurance May Respond to AI-Related Losses
Cyber policies can provide broad protection, but coverage varies significantly between insurers. Depending on the policy and circumstances, an AI-related incident could potentially implicate several coverage areas, including the following:
Security Failure: If an AI-related event compromises the security of an organization's network or data.
Privacy Liability: If an AI tool improperly accesses, processes, or discloses personal or confidential information.
Business Interruption: If an AI-related event causes a qualifying system outage or interruption.
Data Restoration: If systems, software, or data are damaged or corrupted.
Cybercrime and Social Engineering: If AI-generated impersonation results in the fraudulent transfer of funds.
Technology Errors and Omissions: If a company's technology product or service incorporating AI causes financial harm to a customer.
The challenge is that these coverages do not operate in isolation. Definitions, exclusions, sublimits, and policy triggers can shape the outcome of a claim.
That means "Does our cyber policy cover AI?" may not be the most useful question.
The Better Question: How Are You Using AI?
Organizations should first understand where AI exists within their operations.
Is AI used internally to improve productivity? Does it have access to sensitive information? Is it incorporated into a product sold to customers? Can an AI agent execute transactions or modify data? Are employees using publicly available AI tools? Are critical vendors incorporating AI into their services?
Once those exposures are clear, they can be compared with the organization's insurance program. The review may extend beyond cyber insurance to technology errors and omissions, crime, professional liability, media liability, or directors and officers coverage, depending on the organization's operations and policy structure.
The goal is not necessarily to purchase a new policy for every emerging technology. The goal is to identify any gap between the risks the organization is taking and the coverage it believes it has.
Seven Questions for Businesses to Ask Their Advisor
As your organization expands the use of AI, consider discussing these questions with your insurance advisor:
- How does our cyber policy define a security failure or cyber event?
- Would coverage require unauthorized access, and how could that affect an incident involving an authorized AI agent?
- How does our policy respond to AI-assisted social engineering, deepfakes, or fraudulent payment instructions?
- Could any AI, technology, or data-related exclusions restrict coverage?
- If an AI-assisted product or service causes financial harm to a customer, is that a cyber claim or a technology errors and omissions claim?
- How does our policy respond if a third-party AI or technology provider causes an outage?
- Have we considered AI dependencies when evaluating cyber insurance limits, business interruption exposure, and coverage needs?
Don't Wait for the Claim to Find the Coverage Gap
AI is changing how businesses operate, but it is also changing how cyber criminals approach fraud, phishing, social engineering, and business email compromise. Understanding where AI exists within your organization, evaluating the exposures it creates, and reviewing how your cyber insurance program may respond can help your business make informed decisions and move forward with confidence.
Patriot Growth Insurance Services (Patriot) can help businesses review cyber exposures, evaluate coverage considerations, and understand how emerging technology may affect a broader risk management strategy.
The cyber threat has changed. It’s worth reviewing whether your insurance program has changed with it. A thoughtful review can help your organization approach AI cyber risk with greater clarity and preparedness.


