Adoption of AI across the investment management industry has never been higher, with firms deploying the technology to summarise research, monitor threats, automate workflows and strengthen cyber defences. But those same tools are now opening gaps in cyber insurance coverage that could leave policyholders exposed. By 2026, autonomous AI systems that modify data or authorise payments without human approval may fall outside standard policy triggers, forcing a rethink of what cyber cover actually protects.
That uncertainty is filtering through to the AI for Insurance market, with some carriers tightening policy wording and introducing AI-related exclusions where they judge the risk too difficult to quantify. Others are rewarding firms that deploy AI for detection and defence with premium discounts. For investment managers and financial services firms renewing cyber cover in 2026, asking whether AI is covered is no longer enough. The sharper question is which AI, in which policy, and under what conditions.
Insurers pull back on broad AI language
The clearest retrenchment has appeared in traditional corporate lines, including general liability, directors and officers, and professional liability cover. Insurers are narrowing AI-related language because losses are hard to predict, trace or price. A Delinea survey found that 42% of companies now have AI-related exclusions in their cyber policies. Even so, most cyber insurers are not excluding AI-powered attacks outright. If a threat actor uses generative AI to craft phishing emails or scale social engineering, the incident may still qualify as a cyber event provided it meets existing policy triggers such as unauthorised access, data compromise, business interruption or funds transfer fraud.
The split is creating a two-speed market. Some 86% of organisations report premium discounts or credits for using AI-based security tools. Firms that pair AI-powered threat detection with phishing-resistant multi-factor authentication and endpoint detection and response are seeing premium reductions of 20% to 50%. The discounting reflects a bet that AI-boosted defences lower the overall risk, even as the same technology introduces new liabilities elsewhere.
When AI agents cause losses without a breach
The real uncertainty begins when AI is part of a firm's own operations rather than the attacker's toolkit. Most cyber policies hinge on a traditional breach, but agentic AI-systems capable of executing tasks and modifying systems with little or no human intervention-can create losses without one. An AI Agents & Automation system that deletes records, alters a database entry or authorises an errant payment involves no external attacker and no unauthorised access. A standard breach-triggered policy may simply not respond.
Researchers at NYU Tandon describe a sliding scale from AI that merely drafts text up to AI that independently executes changes. Policy response becomes less likely the further up the scale a deployment sits. Some carriers are plugging the gap with narrower products. Chubb now covers certain AI-related incidents but excludes losses hitting many policyholders simultaneously, guarding against a single flawed model triggering systemic claims. Other insurers have launched AI security riders in 2026, demanding proof of red-teaming and documented risk assessments before extending cover.
The black-box problem: AI-output errors
A second gap concerns losses caused by a firm's own AI output. Air Canada was forced to honour a refund policy invented by its chatbot, while Wolf River Electric sued Google after its AI Overviews feature falsely claimed the firm faced legal trouble. Because underwriters cannot reconstruct how an AI reached its answer, some are declining to write AI-output cover altogether. The opacity of large language models makes it nearly impossible to price the risk in advance, and traditional liability frameworks struggle to assign fault when a model's reasoning cannot be audited.
What underwriters demand at renewal
The dividing line at renewal is governance. Underwriters increasingly expect a current inventory of AI tools and models, documented risk assessments completed before deployment, evidence of adversarial testing for any system that can act on production data, and a clear map of where human oversight sits. Carriers want this evidence before a claim occurs, and the gap between firms that have it and those that do not is already visible in premiums. In some cases it determines whether cover is offered at all.
Why this matters for insurance professionals
Cyber insurance underwriters, brokers and claims handlers must now look beyond traditional breach narratives. A policyholder's own AI deployments-especially autonomous agents-can generate liabilities that standard wordings never contemplated. The smartest question at renewal in 2026 is not whether the policy mentions AI, but whether the insured can produce an up-to-date model inventory, pre-deployment test results, and a documented chain of human accountability. Firms that cannot answer those questions will face higher premiums, narrower cover, or outright declinature. For professionals placing or assessing cyber risk, AI governance is becoming a first-order underwriting factor.
Your membership also unlocks: