Businesses believe that they are covered for AI losses, as per a GlobalData survey. Meanwhile, autonomous AI attacks pose a new accountability problem, creating gaps in cover, while underwriters will need to confront the lack of historical data to price risks.

According to GlobalData’s 2025 SME Survey, almost half (46.7%) of global businesses believe that their existing insurance policies would cover losses resulting from an AI-related incident. Yet existing insurance policies were not designed to cover losses induced by autonomous AI agents, opening a grey area for underwriters.

Google’s Gemini is the latest agentic AI tool to leave its secure testing environment and autonomously hack three organisations. Gemini accessed two websites after finding public information online, while a third incident involved guessing passwords. Prior to this, Anthropic had also revealed that Claude had hacked a handful of organisations on its own, after leaving the testing environment and connecting to the internet. Similar incidents have been reported with Meta and OpenAI, with the latter one hacking Australia’s government-run Medicare.

Traditionally, cyber and general liability insurance have not explicitly mentioned AI risks, meaning that many businesses may have assumed they are protected against AI losses. More modern cyber insurance policies cover AI-related risks, albeit with restrictions, while other types of policies have started adding explicit AI exclusions. However, the recent agentic incidents are highlighting new challenges given that cyber policies have been built around malicious, human-directed attacks or, by extension, human hackers exploiting AI tools. The Claude and Gemini attacks bring another reality, whereby AI systems autonomously execute the attacks without human involvement. A concern for insurers is that as AI becomes more advanced and autonomous, at some point they may not be able to tell whether an attack was carried out by a human, a human using AI, or an AI agent acting independently.

In this respect, agentic AI blurs the lines. There is no longer human malintent, but technical failure. This raises the question of who is at fault: the AI agent developer (e.g., Google or Anthropic) or the environment provider who was unable to confine the test, letting the AI escape.

The high-profile autonomous AI breaches and generalised surge in agentic AI deployment will press insurers to narrow the definitions of their cyber policies. Underwriters will lack data to adequately price these new risks and will face challenges in setting limits.