What the Gemini and Claude hacking incidents mean for cyber insurers | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Most insurer AI agent exposure still sits inside policies never built for autonomous systems, one industry report found

Google has confirmed that its Gemini AI model accessed and breached the systems of three real companies during a cybersecurity evaluation in May — in what is being described as the first known instance of Google’s AI autonomously carrying out this kind of intrusion. 

The confirmation of the breach has landed squarely in the middle of a live debate in the cyber insurance market: What happens when an AI system, rather than a human attacker, is the thing that causes a breach?

In all three cases, the mechanics were broadly similar. A testing partner’s environment was left connected to the live internet when it should have been sealed off, a fictional test target happened to share a name with a real company, and the AI model treated the real company’s systems as part of its assigned exercise. In some cases, it used basic techniques such as password guessing or harvesting exposed credentials to gain access. 

Each lab reported the model stopped, or in Anthropic’s case, explicitly did not attempt to deliberately escape containment, once the situation became clear.

Why insurers are treating this as more than a technology curiosity

Richard Ford, vice president of engineering at CyberCube, described the pattern as significant because it stemmed from what he called an otherwise-benign AI task, fully autonomous and essentially unprompted, rather than a human-directed attack. That distinction is exactly what’s forcing cyber insurers to reconsider how their existing policy wording actually applies.

Standard cyber cover has always been built around a human attacker exploiting a vulnerability; these incidents involve no attacker at all, only an AI system executing a task it had been given, under conditions its operator failed to properly contain.

The Artificial Intelligence Underwriting Company published research shortly before these disclosures finding that more than 90% of insurers’ AI agent exposure currently sits inside conventional policies, cyber, D&O, general liability and technology errors and omissions, that were never built with autonomous AI activity in mind.

The same report modelled a severe AI-agent loss event at roughly $100 billion, explicitly framed as a stress-test scenario rather than a forecast, but the exercise underlines how far behind existing wording sits relative to what a genuinely large-scale AI-driven incident could look like.

The specific coverage questions insurers are working through

Jenny Soubra, vice president of specialty commercial lines at Verisk Underwriting Solutions, has pointed to two areas of particular focus.

The first is accumulation risk: because a single AI model or shared platform could plausibly contribute to incidents across many companies simultaneously, in exactly the way Irregular’s testing infrastructure connected to multiple AI labs simultaneously, a single technical failure has the potential to trigger claims across a far larger portfolio than a conventional, targeted cyberattack would.

The second is a harder philosophical question: whether an AI agent’s costly but technically authorised autonomous decision, made without any unauthorised access, malicious interference or security breach, should sit inside cyber insurance at all, or whether it belongs more naturally under an operational or professional liability policy instead.

A spokesperson for Beazley said companies increasingly want AI risks folded into their broad cyber policies rather than carved out separately, and that the insurer is developing new coverage as AI-specific risk emerges, a position that reflects most of the market’s current approach: refining and clarifying existing wording rather than excluding AI activity outright. Targeted exclusions remain under active discussion in specific areas, particularly systemic, cross-portfolio losses and autonomous decisions that fall outside what would traditionally count as a cyber event.

A market with limited room to absorb a genuinely large AI-driven loss

These questions are landing on a cyber insurance market that isn’t flush with spare capacity to absorb a shock. The US cyber insurance loss ratio reached 53% in 2025, its second consecutive annual increase, even as pricing has continued falling across large parts of the market.

Munich Re has estimated the global cyber insurance market at close to $15 billion in premium, projecting growth to around $28 billion by 2030, with AI-related activity expected to account for a growing share of incidents over that period. That combination, rising loss ratios, falling prices and a genuinely novel exposure that existing wording wasn’t written for, is the setup that tends to force faster policy language changes than insurers would otherwise choose to make on their own timeline.

CFC has separately framed the underlying accountability problem plainly: when an autonomous AI system causes harm without malicious intent, established lines between technology, cyber and professional liability cover start to blur, and third-party risk becomes a live question in a way it rarely was for traditional professional liability claims, since an AI agent acting unexpectedly can affect parties entirely unconnected to the business that deployed it.

The Gemini and Claude incidents are useful because they’re relatively contained, no lasting damage, no malicious intent, and a clear technical explanation for how each occurred. That makes them a comparatively low-stakes real-world test of exactly the coverage gap the AIUC’s $100 billion stress scenario and Verisk’s accumulation-risk concerns are trying to anticipate before a genuinely damaging version of the same failure occurs.

For brokers advising clients on cyber and technology E&O cover, particularly clients building or heavily reliant on agentic AI systems, the practical question these incidents raise isn’t whether a policy would respond to a human hacker exploiting a vulnerability – that’s well understood, but whether it would respond to an AI system that caused identical damage while operating exactly as designed, a question the market itself has not yet fully answered.



Click Here For The Original Source.

——————————————————–

..........

.

.