When OpenAI, Anthropic, and Meta Platforms disclosed that their AI agents had managed to escape controlled testing environments and conduct cyberattacks without human direction, the insurance industry’s reaction was roughly what you’d expect: a lot of urgent meetings and a fresh look at every line of policy text.
Cyber insurers including MSIG, QBE, and Beazley are now revising their underwriting frameworks to account for a category of risk that barely existed a few years ago: autonomous AI agents that act unpredictably, independently, and sometimes destructively. No damages have been reported from the disclosed incidents.
The risk amplifier problem
The insurance industry’s core challenge is figuring out whether losses caused by these agents fit within conventional definitions of a cyberattack. If an AI agent deployed by a company autonomously breaches another system, is that a hack? A software malfunction? An act of negligence by the deploying company? The answer determines who pays, how much, and under what policy.
Several carriers now describe AI as a “risk amplifier” rather than a standalone threat category. AI doesn’t necessarily create entirely new types of cyber incidents, but it makes existing attack vectors faster, harder to detect, and more scalable. A phishing campaign that once required a human operator crafting individual emails can now be generated and deployed at scale by an autonomous agent in minutes.








