MICKAI®ArticlesDoes cyber insurance cover AI inc…
Article · 22 July 2026

Does cyber insurance cover AI incidents?

It depends on wording written for human-triggered incidents, and silent AI risk is becoming the new silent cyber.

Author
Micky Irons
Published
22 July 2026
Follow Micky Irons
LinkedInX
sovereign aicyber insuranceai riskinsuranceregulated ai

It depends on wording that is changing right now, and the honest answer for most organisations is that they do not yet know how their existing policy would respond to an AI incident, because nobody has tested it. Silent AI risk, cover that exists or does not exist depending on how a definition written before generative AI is stretched to fit it, is becoming the new silent cyber, the same problem the market spent years fixing for ransomware and supply-chain attacks.

The question matters because AI incidents are no longer hypothetical: staff pasting client data into consumer tools, agentic systems taking harmful autonomous actions, and outages at AI vendors that stop a business process are all now real categories of loss, and boards are asking whether their existing cover reaches them.

Does a data leak through a staff member using a consumer AI tool count as a covered privacy event?

It may or may not, depending entirely on how the policy defines a privacy event and a security failure. Some wordings are broad enough to catch any unauthorised disclosure of personal or confidential data regardless of mechanism; others are tied more narrowly to a malicious actor breaching a system, which a staff member voluntarily pasting data into a chatbot does not resemble at all. This is exactly the kind of gap that only becomes visible when a claim is made, which is the wrong time to discover it.

Does a policy written for human-triggered incidents cover an autonomous agent's harmful action?

This is genuinely untested ground in most policies. Traditional cyber wordings assume an incident is triggered by a human actor, internal or external, acting deliberately or negligently. An agentic system that takes a harmful action autonomously, with no single human decision point to point to, sits awkwardly against language built around that assumption, and how an insurer would characterise the trigger is not yet settled market practice.

Does business interruption cover extend to an AI vendor outage?

Only where the vendor counts as a covered dependency under the policy's contingent business interruption wording, and many policies list specific dependencies rather than covering any third-party service the business happens to rely on. An organisation that has quietly become dependent on an AI vendor for a core process should check whether that vendor appears, or could be added, to its contingent BI schedule, rather than assuming general cover extends automatically.

Are insurers starting to write AI-specific terms into policies?

Reporting and market commentary describe insurers beginning to introduce AI-specific exclusions and questionnaires as emerging practice; this should be treated as a direction of travel rather than a settled market standard, and no specific exclusion wording, product name or premium figure is asserted here. The practical implication either way is the same: AI use is becoming something insurers ask about explicitly, rather than something that quietly falls inside or outside cover by accident.

What happens if we do not disclose our AI use accurately at proposal?

Non-disclosure risk. Insurance proposals typically require accurate disclosure of material facts, and an organisation that understates or omits its AI use, deliberately or through simple lack of internal visibility into what AI is actually running, risks the insurer avoiding the policy or a specific claim later on non-disclosure grounds. An organisation that cannot accurately describe its own AI estate at proposal stage has a governance problem before it has an insurance problem.

What should a buyer do before renewal, not after a claim?

Read the definitions of computer system and security failure against the organisation's actual AI estate, not against what the policy was originally drafted to describe. Disclose AI use accurately, including shadow AI where it is known. And build evidence of controls, because underwriters price what they can verify: an organisation that can show a sealed, verifiable record of what its AI did is giving the underwriter something concrete to assess, which tends to support better underwriting outcomes, though no specific premium or coverage promise can be made here.

A policy written for human-triggered incidents does not automatically know what to do with an incident nobody triggered.

How a sealed, independently verifiable record of AI activity gives both a claims process and an underwriter something checkable is set out at /sovereign-ai, and the film at /film shows the interface in operation.

Frequently asked questions

Will our existing cyber policy definitely cover an AI data leak?

Not automatically. Whether it does depends on how the policy defines a covered event, and many wordings were drafted before generative AI created this specific loss scenario, so the answer requires reading the actual definitions rather than assuming general cyber cover extends to it.

Should we disclose shadow AI use we only recently discovered?

Insurance proposals generally require accurate disclosure of material facts known to the organisation, so once shadow AI use is discovered it should be reflected honestly at the next renewal or proposal, since non-disclosure risk applies to what should reasonably have been known, not only what was formally documented.

Does business interruption cover an AI vendor going down?

Only if that vendor is captured within the policy's contingent business interruption wording as a covered dependency, which is not automatic. Reviewing the schedule of covered third parties against actual AI vendor dependency is a practical step before assuming cover exists.

Are insurers adding AI exclusions to standard cyber policies?

Market commentary and reporting describe this as an emerging practice; no specific exclusion wording or timeline is confirmed here, and buyers should check their own renewal terms directly rather than assume a market-wide standard has already settled.

Does better AI record-keeping actually reduce premiums?

No specific premium outcome can be promised. What can fairly be said is that underwriters price what they can verify, so an organisation able to evidence its AI controls with a verifiable record gives the underwriting process better information than one that cannot, which is generally favourable to how risk gets assessed.

Should we tell our broker about AI use even if the current policy does not ask?

Yes. Volunteering accurate information about material AI use, even where a proposal form has not caught up with a specific question, reduces the non-disclosure risk that arises if a claim later reveals AI use the insurer was never told about.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/does-cyber-insurance-cover-ai-incidents. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles