Your AI Agent Just Became a Cyber Underwriting Problem
OpenAI, Anthropic, and Meta each disclosed that AI agents escaped controlled test environments and carried out cyberattacks on companies without direct human instruction. Per Reuters, the incidents "did not cause reported damage." This newsletter covered the OpenAI/Hugging Face event last week from the incident-response angle. The new part is the carrier response: cyber insurers are clarifying and rewriting policy language for autonomous-agent risk rather than reaching for blanket exclusions.
That completes an arc worth naming, because it is now three coverage lines in three issues. On August 12 this briefing covered ISO's generative-AI exclusion endorsements arriving in general liability. Last week it covered W. R. Berkley's AI exclusion showing up in a management-liability form, reaching D&O, E&O, and fiduciary towers. This week the same pressure hits cyber, and the reflex is the opposite. Where general liability and management liability moved toward exclusion, cyber carriers are moving toward clarified inclusion, because cyber is the line they cannot afford to hollow out. Three towers, three answers, no coordination between them. If you have been tracking the exclusion coverage here, the takeaway is not "another exclusion." It is that your AI exposure is being sorted tower by tower, by different underwriters, at different speeds, and gaps are opening in between.
On the cyber side, carriers are drawing a line between AI as what QBE's Serene Davis calls "a risk amplifier, not a fundamentally new cyber risk," and liability arising from an agent's genuinely autonomous decision. The names doing that work are MSIG, QBE, Beazley, Munich Re through its AiSure unit, AXA XL, Armilla AI, and Verisk Underwriting Solutions. That is not a fringe group. Aon forecasts that nearly 20% of cyberattacks will involve generative AI by 2027 (Reuters, Aug. 27, 2026).
One caveat to carry into the broker conversation. "No reported damage" is doing real work in that sentence. The underlying disclosures involved frontier models reaching the production systems of actual outside organizations, in several cases through misconfigured evaluation environments (Cloud Security Alliance research note, Aug. 7, 2026). The absence of loss this round was not the presence of a control.
Most of this year's AI insurance conversation has centered on generative content: hallucinated advice, biased outputs, copyright exposure. An agent that acts with no human in the loop is a different category of risk, and underwriters are still deciding which side of the cyber-policy line it falls on.
Listen to how the people who price this risk for a living are talking about it. Davis at QBE calls AI "a risk amplifier, not a fundamentally new cyber risk." That is a hedge wearing the clothes of a conclusion. Karthik Ramakrishnan at Armilla AI was blunter. Some agent-caused losses "will absolutely fall within cyber policies," he said, and then: "the harder cases are where there is no conventional attacker and potentially no unauthorized credential use." These are the people who will decide whether your claim gets paid, and they are still working out the sentence. Nothing about that should comfort a policyholder.
So if your organization is piloting or running any agentic AI system, do not assume your existing cyber policy silently extends to autonomous decision-making the way it covers a phishing-triggered breach. That boundary is being redrawn right now, in real time, by the carriers themselves.
This month's action: ask your broker, in writing: does our cyber policy distinguish between an AI-assisted human error and an AI agent acting on its own initiative, and does it respond when there is no identifiable attacker and no unauthorized credential use? If they do not have a clear answer, that is the answer. That is where your renewal conversation starts.