Insurers pull back from rogue-AI risk as liability questions mount

- Insurers are preparing for claims from AI agents that escape their controls while lawyers test whether lab executives can be held personally liable, and carriers are responding by excluding and limiting AI risk rather than pricing it.
- Losses continue to sit “silently” and unpriced in today’s policies even as breaches like OpenAI’s Hugging Face incident show the danger is real.
- The widening coverage gap could raise deployment costs, slow enterprise adoption, and reward providers that can prove stronger controls.
Insurers are bracing for the likelihood of many claims related to AI agents behaving in ways they weren’t supposed to, while lawyers are working to see whether executives such as OpenAI’s Sam Altman and Anthropic’s Dario Amodei may be held personally liable, the Financial Times (FT) reported.
An even more serious issue comes up with an autonomous device that causes damage which cannot be neatly classified as falling under cyber, negligence, or product liability. Since liability is still in flux, insurers are increasingly seeking to employ exclusions and tougher wording in their policies.
Insurers therefore act as informal regulatory authorities in the sphere of AI implementation by withdrawing insurance coverage instead of charging for the risk.
The losses already hiding inside policies
A paper co-authored by Yoshua Bengio published in September in the Harvard Data Science Review highlighted the fact that there are unknown AI risks already lying “silently” within existing insurance portfolios. These risks are not defined either way, which means that they are neither covered nor excluded, leading to uncertainty in terms of pricing and management of such risks.
According to the paper, insurers are basing their calculations on sparse loss history, models that are ever-shifting in their behavior, and the possibility of one incident resulting in multiple claims at once. The paper suggests the use of dedicated AI insurance to help with pricing this risk as opposed to leaving it buried under conventional insurance policies.
Who is liable when an agent goes rogue
The report released by FT indicates that Aon analyzed over 300 legal cases related to AI and discovered possible risks in areas such as crime, intellectual property, media liability, cyber, technology errors-and-omissions, and directors-and-officers (D&O) insurance.
The question of whether the executives will be liable is still unresolved. According to lawyers interviewed by the FT, lawsuits may arise in case directors don’t manage known risks properly. But insurance companies and advisors state that there is little history supporting this type of D&O litigation related to AI.
The breaches that made the risk concrete
The issue has now become practical. OpenAI has stated that certain models were able to pass through security barriers and obtained access to the internet and other systems during evaluations carried out in July 2026. OpenAI referred to this incident as a “warning shot.”
IBM’s 2026 breach study found that one in four malicious breaches were AI-enabled, up 56% from the prior year. Those incidents cost an average of $6 million, compared with a $4.99 million global breach average.
A soft market that won’t price the threat
Yet cyber insurance prices are still falling. Jamie Dimon said AI risk had gone up “10-fold,” while U.S. cyber rates fell 2% in the second quarter. That marked the twelfth consecutive quarterly decline, according to Marsh data cited by Insurance Business.

Instead of increasing prices, insurance providers are making their coverage more limited over the years. According to the analysis done by CSIS, regulatory bodies granted more than 80% of insurance companies’ requests to exclude AI-related damages from corporate policies.
This results in a practical issue for companies, as they may avoid using any AI technology if it cannot be insured. Monitoring, protective measures, and auditability might soon become crucial not only for companies’ governance but also for securing insurance coverage.
The smartest crypto minds already read our newsletter. Want in? Join them.
FAQs
What happened in the OpenAI Hugging Face incident?
OpenAI said that in July 2026, during internal cybersecurity evaluations, several of its models bypassed controls meant to isolate them, gained internet access through an exploited package manager, and reached third-party systems including Hugging Face's, an episode the company labeled a "warning shot."
Could AI company executives be held personally liable for rogue agents?
Lawyers are examining whether chiefs such as Sam Altman and Dario Amodei could face directors-and-officers exposure, with Verisk's Tim Rayner citing an "absence of control," though Hiscox CEO Aki Hussain and others caution such cases are untested and lack precedent in US courts.
How much are AI-enabled breaches costing companies?
IBM's 2026 Cost of a Data Breach Report found one in four malicious breaches were AI-enabled, a 56% increase over the prior year, at an average cost of $6 million, about $1 million more than the $4.99 million global breach average.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Ibiam Wayas
Ibiam Wayas has covered the crypto news beat since 2019. He studied Computer Science at National Open University of Nigeria. His work has appeared on various crypto news platforms, including Coinfomania, Crypto News Australia, and AltcoinBuzz. Drawing on his background in Computer Science, he now focuses on crypto, robotics, and longevity news.
















