AI fuels cyber claims as 40% of large firms remain underinsured

AI was a factor in one-quarter of cyber breaches in H1 2026, and 40% of large firms are underinsured, according to Swiss Re. Business email compromise claims rose 57% year over year in Q2 2026, with attackers shifting from ransomware to account takeovers, Travelers reported.

Categorized in: AI News Insurance
Published on: Sep 11, 2026
AI fuels cyber claims as 40% of large firms remain underinsured

AI-driven cyber threats reshape the insurance market

AI was a factor in one-quarter of cyber breaches during the first half of 2026, pushing claims frequency and severity upward while exposing a coverage gap: 40% of large firms are underinsured, according to Swiss Re. Business email compromise claims rose 57% in Q2 2026 year over year, with attackers shifting tactics from ransomware to account takeovers, Travelers reported.

The pressure is forcing insurers to rethink policy limits, underwriting assumptions, and incident response guidance. It is also opening a growth channel: small and midsize enterprises, most of which carry no cyber coverage at all.

Underinsurance among large firms

Large U.S. corporates average $120 million in cyber coverage limits, but 10 losses per year over the past five years have exceeded that threshold, according to Swiss Re's latest cyber report. The reinsurer warns that as AI amplifies ransomware, data breach, and business interruption exposures, policy clarity on AI-related claims will become critical.

The SME segment represents the market's largest untapped opportunity. Only 5% to 20% of micro-SMEs and SMEs carry cyber policies, yet together they are projected to generate nearly $5 billion in premium by year-end. Global cyber market premium is forecast to reach $16.4 billion in 2026.

BEC claims surge as attackers shift tactics

Business email compromise claims jumped 57% in Q2 2026 compared to a year earlier, driven largely by attackers stealing authentication tokens rather than passwords, according to Travelers' Q2 2026 Cyber Threat Report. Ransomware claims dipped 5% from Q1 as fraudsters redirected their efforts.

Phishing kits augmented by AI are increasingly used to hijack enterprise platforms such as Microsoft 365 and Google Workspace. Travelers recommends treating identity - not devices - as the primary unit of compromise. Insurers should monitor for unexpected token issuance, new application consents, and anomalous sign-ins, and build token-specific response protocols into incident plans rather than defaulting to password resets alone.

Operational lessons from carriers

Banner Life's rise to the largest U.S. term life insurer - 13% market share in Q1 2026 and $239 million in annualized premiums - came from consolidating data before layering in AI. The carrier cut costs per application 27% over three years and dropped underwriting and operations expenses 23% by end of 2025, projecting another 16% reduction by year-end. Instant underwriting decisions grew from 67 to 109 per underwriter monthly.

CEO Mark Holweger credits mandatory human oversight at every rule-implementation stage and early, continuous customer input. Excluding end users, he said, produces systems that "don't work how people expected."

HappyRobot CEO Pablo Palafox, whose voice-AI platform has raised approximately $200 million in total funding, warns insurtech leaders against leading with technology rather than solving concrete workflow problems. For insurers, the near-term opportunity lies in deploying AI against manual coordination bottlenecks - intake, follow-ups, document collection - and demonstrating measurable ROI in production environments.

Outdated core systems remain a barrier. Applying Amdahl's law, a system's speed is constrained by its slowest component - for most insurers, that's the policy administration system. Stacking AI agents on a flawed foundation accelerates inconsistencies rather than fixing them. Smaller carriers and MGAs face additional resistance due to budget constraints, but practical, workflow-integrated use cases can build momentum.

Why this matters for insurance professionals

Underwriting teams should review cyber policy language now for ambiguity around AI-enabled attacks, because Swiss Re's data shows claims are already crossing coverage thresholds at large firms. Claims and incident response teams should update protocols to address token theft and account takeover scenarios, not just password-based compromise. And product leaders eyeing growth should look to the SME segment, where penetration remains in the single digits to low double digits despite nearly $5 billion in projected premium.


Get Daily AI News

Your membership also unlocks:

700+ AI Courses
700+ Certifications
Personalized AI Learning Plan
6500+ AI Tools (no Ads)
Daily AI News by job industry (no Ads)