Silent AI cover risk emerges in cyber policies, IUA warns

Standard cyber insurance policy wordings likely already cover AI risks, exposing insurers to losses they never priced for, warns IUA underwriting director Tom Hughes. Silent AI coverage is emerging as adoption outpaces disclosure, following the same trajectory as the costly silent cyber problem.

Categorized in: AI News Insurance
Published on: Aug 22, 2026
Silent AI cover risk emerges in cyber policies, IUA warns

Common clauses in cyber insurance policies could unintentionally cover artificial intelligence risks, exposing insurers to losses they never priced for, according to Tom Hughes, director of underwriting at the International Underwriting Association (IUA). Speaking at the Airmic Conference in Birmingham, Hughes said AI insurance risks such as hallucination and intellectual property infringement are following the same trajectory as silent cyber - where policies written before cyber attacks became widespread implicitly covered them.

Silent cover happens when a policy's wording does not clearly state whether a risk is covered or excluded. The cyber market took years to recover from this problem, and Hughes sees similar signs appearing as businesses adopt AI tools at a faster pace than insurers can track.

"We're certainly talking about the risk of silent AI," Hughes said.

A July 2026 white paper from cyber risk firm Kynd echoes that concern. The report, It's The Wild West of AI Risk, said: "Silent AI is forming the same way, one undeclared tool at a time. Adoption is running ahead of disclosure. Businesses are wiring AI into hiring, customer service, claims handling and a hundred other workflows faster than their insurers can ask about it - and often faster than they are tracking it themselves."

Policy wordings already cover generative AI

Hughes noted that standard definitions of computer systems in cyber policies are "certain [to] encompass generative AI in the way that we're using it today". That means policies already contain mechanisms to manage AI risk - whether anyone intended them to or not.

The exposure is more concentrated than shadow IT, according to the Kyndryl report. The same handful of underlying AI models sit behind most activity, so a single flaw or failure can surface across many insureds at once. Risk that was once spread across separate systems now runs through a few shared ones.

Hughes said three leading markets have prepared or brought AI products to market, with more expected to follow. However, AI policy exclusions are "not appearing in any meaningful way", and corporates are relying on existing siloed insurance products to cover AI risk instead. That opens the door for silent coverage.

Reading how companies use AI

Hughes said the main challenge is the technology's scope, akin to how "not everyone in the insurance market is a cyber insurance expert, but cyber risk appears in almost every class of business". Though he believes AI "is an insurable core risks with the topic of AI for Insurance training, coverage is more likely to be front of mind for technology developers and businesses using AI to make decisions or engage with clients, rather than companies only using the technology for back-office functions.

Directors' and officers' insurers are already evaluating how well companies understand AI, and applying that to risk profiles.

"When I speak to D&O insurers, they have an interesting view about the impact that AI will have on their markets," Hughes said. "If they're thinking about AI and understanding it, the risk profile is so much different to if they sit in front of someone who doesn't know the difference between a generative AI tool and level of AI. That will be a red flag. They'll be thinking 'hang on, how is this business going to put the right controls and the right checks and balances in place?'"

Building insurability for AI risk

Hughes sees several routes forward. Companies need to understand their legal obligations, particularly if AI is engaging with customers or running other processes on their behalf.

"It's going to be down to companies to put the right parameters in place, the right controls," he said.

Another option is exploring "a captive approach to incubate a risk that we don't have much data around", he added. "You can work around smaller limits, gain a good understanding and then, off the back of that, work towards a fuller insurance model.

Hughes also called for insurers to get involved in product surveying or testing processes as early as possible, moving from being reactive to becoming "a proactive partner for the client of the process".

He gave an example of how this works: insurers are already talking to builders of new flight aircraft - the flying taxis - about their systems, battery technology, and vulnerabilities while trials are still underway.

"Where risks exist, that's an opportunity for the insurance market [that is] in the business of risk, so risk brings opportunity [and] allows [insurers] to think carefully about the types of new products that they might want and to put on the table," Hughes said.

Why this matters for insurance professionals

The risk that your existing book policies already cover AI exposures - even if they were never priced for - is no longer theoretical. Underwriters and brokers should audit their current cyber policy wordings, definitions of computer systems, and exclusions with AI in mind, to determine where silent cover could arise. Conversations with clients will also matter: how they use a company level using AI will increasingly affect the risk profile. Those are the analyses that will prevent claims that nobody priced.


Get Daily AI News

Your membership also unlocks:

700+ AI Courses
700+ Certifications
Personalized AI Learning Plan
6500+ AI Tools (no Ads)
Daily AI News by job industry (no Ads)