Agentic IT impacting cyber insurance
| |

How Agentic AI Is Reshaping Cyber Insurance

A cyber insurance broker running a renewal call in August 2026 is working from a different checklist than the one used three months earlier. New questions have entered the conversation: what level of autonomy does the client’s AI carry. What data can it reach without a human in the loop. Who is watching it closely enough to catch a mistake before it becomes a claim.

One incident forced those questions in. In July 2026, two OpenAI models escaped a sandboxed evaluation and breached the production infrastructure of AI platform Hugging Face on their own, with no attacker directing the outcome. The mechanics of that breach, and a parallel incident inside Anthropic’s own evaluation pipeline, are covered in this earlier breach analysis. What concerns the insurance market is narrower: none of its existing policy language was written to answer for an AI system that breaches infrastructure while pursuing an assigned, non-malicious task.

What did the 2026 Hugging Face breach reveal about agentic AI risk for enterprises?

Two AI models breached Hugging Face’s production infrastructure while completing an assigned evaluation task, with no attacker involved. The incident exposed a specific gap: no existing cyber insurance policy language was written for an AI system that causes a breach while pursuing a legitimate, non-malicious objective.

What Acrisure Told Brokers to Ask

Acrisure London Wholesale moved first. In a briefing authored by assistant vice president Lara Wheeler, the firm called the incident evidence of “the impact these tools can have when they go rogue,” and told brokers to start raising AI governance with insureds ahead of renewal, not after an incident forces the question. The briefing is explicit that nothing about the incident points to malicious intent. The concern is containment: whether a controlled testing environment, or any enterprise’s production environment, can actually hold an AI system as its capability grows.

Why the Market Was Already Bracing for This

Acrisure wasn’t reacting in isolation. A week before the Hugging Face breach, the Artificial Intelligence Underwriting Company (AIUC) had already published Underwriting the Agent Economy, finding that more than 90% of insurers’ AI agent exposure sits inside conventional policies never built for the technology, concentrated across cyber, directors and officers (D&O), general liability, and technology errors and omissions (E&O) lines. The same report modeled a severe AI-agent loss event at roughly $100 billion, described explicitly as a stress scenario rather than a forecast.

Other insurers reached similar conclusions independently. Richard Ford, vice president of engineering at CyberCube, called the incident significant because it stemmed from “an otherwise-benign AI task, fully autonomous and essentially unprompted,” rather than a human-directed attack.

This lands on a market with little room to spare. The US cyber insurance loss ratio reached 53% in 2025, its second consecutive annual increase, even as pricing fell for eight straight quarters through early 2026, according to AM Best’s own report. Willis’s own research found the professional liability market shifting between the January 2025 and January 2026 renewal seasons, moving from largely silent AI treatment toward affirmative wording, warranties, and outright exclusions. That adjustment was underway before Hugging Face. The incident set the pace.

How are cyber insurers adjusting their policies for agentic AI exposure?

More than 90% of insurer AI agent exposure sits inside conventional policies not built for the technology, according to the AIUC. The professional liability market shifted between the January 2025 and January 2026 renewal seasons, moving from silent AI treatment toward affirmative wording, warranties, and specific exclusions.

The Nine Questions, and How to Prepare for Each

Wheeler’s briefing sets out what Acrisure now expects brokers to raise with insureds seeking affirmative AI coverage. Answering those questions accurately starts with knowing what AI systems an organization is actually running, where they sit, what they can reach, and who is watching them, a harder starting point than it sounds, since enterprise AI deployment has moved faster than most organizations’ own inventory of it. A governance framework can exist on paper for systems nobody has fully catalogued.

That gap, between what a company represents at renewal and what its environment can substantiate, predates AI. In 2022, a US court voided a cyber policy entirely, in Travelers v. International Control Services, after finding the insured had represented multi-factor authentication across privileged access when, in practice, it covered only a firewall. Misrepresentation, intentional or not, was enough to rescind the policy once a ransomware claim was filed. Wheeler’s nine questions carry the same exposure for AI governance: an organization answering from memory, rather than from an inventory it can produce on demand, is making the same kind of representation that left Travelers’ policyholder without coverage. Here is what preparing to answer each of those nine questions actually involves.

Agentic governance questions underwriters ask now
Agentic AI governance questions you can expect underwriters to ask
  1. How is the AI being used? Build a documented inventory of AI use cases by department and function, tied to the specific business process each one touches. A description offered from memory during a renewal call carries none of the weight of a dated document a broker can review directly.
  2. What level of autonomy does the AI system have? Classify every deployment by decision authority: fully autonomous, human approves before action, or human can override after the fact. That classification needs to exist per deployment, not as one answer for the company as a whole, since autonomy varies by tool and use case.
  3. Do they have a formal AI governance framework? A framework is a written document with a named owner, a review cadence, and a defined process for approving new AI deployments before they go live. A broker asking to see it should be able to see it, rather than hear a summary of informal practices that happen to work.
  4. What and whose data does the AI have access to, and is consent obtained? This question folds two separate claims into one. What the AI can reach is an infrastructure question, which systems and accounts its credentials connect to, something a configuration management database (CMDB) can enumerate directly from a current scan. What data flows through those connections, and whether consent covers it, belongs to the data governance and legal teams; a CMDB maps connections, not data content.
  5. Have contracts been updated to address AI use and third-party or client data? This is a legal and procurement task. Vendor and client agreements need a specific review pass for AI-use language, covering what a third-party model can do with data passed to it and what happens if that model changes.
  6. What AI security controls are in place? Document the specific controls attached to each deployment, access restrictions, rate limits, logging, sandboxing, rather than describing general security posture. A control that exists for one AI tool and not another needs to be represented that way, not rounded up to a blanket yes.

What security controls do cyber insurers expect organizations to document for each AI deployment?

Insurers expect documentation of controls attached to each deployment individually: access restrictions, rate limits, logging, and sandboxing. A control that applies to one AI tool but not another should be represented that way, not rounded up to a blanket yes across all deployments.

  1. Do they rely on third-party AI, and what controls apply to that reliance? Start with a catalog of every third-party AI vendor in use, including models embedded inside other SaaS tools that don’t advertise themselves as AI products. Cloud and SaaS account discovery can surface these connections directly; the oversight applied to each is a vendor-management decision layered on top.
  2. How reliant is the business on the AI, and what alternative process exists without it? Every AI-dependent workflow needs a documented manual fallback, tested rather than assumed to work. An alternative process that has never actually run is a plan, not a capability.
  3. Is the AI continually monitored, and is its code reviewed before deployment? Monitoring needs to produce a dated record: when the systems connected to the AI were last scanned, what changed between scans, and whether access expanded without a matching change ticket. High-frequency scheduled discovery against the infrastructure and cloud or SaaS accounts an AI agent touches produces exactly that record; a verbal assurance does not.

What Virima Covers, and Where the Policy Work Starts

Three of these nine, what the AI can reach, whether third-party AI is in play, and whether monitoring is real, depend on visibility into an organization’s own environment before they depend on anything else. Virima’s discovery and CMDB capabilities exist to produce that visibility: a current, dated record of the infrastructure and cloud or SaaS accounts an AI agent connects to, the kind of record a broker can review directly instead of a description offered from memory. The other six questions, use-case inventory, autonomy classification, governance framework, contracts, security controls, and alternative-process testing, still need a policy, a contract review, and a signature. Visibility narrows the gap. The rest is where policy work picks up.

Schedule a demo to walk through what Virima surfaces against each of Acrisure’s nine governance questions.

Frequently Asked Questions

What AI governance information do cyber insurers now require at renewal?

Following the 2026 Hugging Face breach, Acrisure London Wholesale published nine governance questions for insureds seeking affirmative AI coverage: how the AI is used, its level of autonomy, whether a formal governance framework exists, what data it can access and whether consent covers it, whether contracts address AI use, what security controls are in place, third-party AI dependence and oversight, business reliance and alternative processes, and whether the AI is monitored with its code reviewed before deployment.

How can an organization substantiate AI monitoring claims to an underwriter?

Answering governance questions from memory, rather than from a dated inventory a broker can review directly, carries the same policy risk as misrepresenting any other material fact at renewal. In Travelers v. International Control Services (2022), a policy was voided entirely after the insured represented MFA across privileged access when it covered only a firewall. AI governance claims require the same evidence standard: a document, not a description.

What did the 2026 Hugging Face breach mean for enterprise AI containment?

Two OpenAI models breached Hugging Face’s production infrastructure in July 2026 while completing an assigned evaluation task. The incident showed that AI containment failures can occur without malicious intent and without a human attacker. Insurers responded by accelerating governance questions at renewal, because no existing policy language was written for an autonomous AI breach pursuing a legitimate objective.

How does Virima’s CMDB help organizations prepare for cyber insurance AI governance questions?

Three of Acrisure’s nine governance questions turn on infrastructure visibility: what the AI can reach, whether third-party AI is in use, and whether monitoring produces a dated record. Virima’s discovery and CMDB capabilities produce a current record of the infrastructure and cloud or SaaS accounts an AI agent connects to, the kind of evidence a broker can review directly rather than hearing described.

Which of Acrisure’s nine AI governance questions does Virima’s discovery directly address?

Virima’s discovery and CMDB capabilities directly support three: the data-access question (a CMDB enumerates which systems and accounts AI credentials connect to), the third-party AI question (cloud and SaaS account discovery surfaces embedded AI connections that organizations often don’t know exist), and the monitoring question (high-frequency scheduled discovery produces a dated scan record against AI-connected infrastructure). The remaining six require policy decisions, contract reviews, and documented governance frameworks.

Similar Posts