Insurers are preparing for a new generation of potentially multimillion-dollar claims as autonomous AI agents increasingly gain the ability to act independently, including interacting with computer systems, making decisions and executing tasks without a human approving every step. The risk is moving beyond hypothetical AI failures as insurers and lawyers examine recent incidents involving agents that behaved outside their intended controls.
The emerging problem is not simply whether an AI system makes a wrong prediction. When an autonomous agent causes a cyber incident, exposes data, infringes intellectual property or makes a costly business decision, insurers must determine which policy applies, whether the loss is covered and ultimately who is legally responsible. A Financial Times report said insurance broker Aon has analysed more than 300 AI-related legal cases while insurers assess exposures ranging from cybersecurity and technology errors to directors’ and officers’ liability.
Key takeaways
- Insurers are preparing for potentially multimillion-dollar claims involving autonomous AI agents.
- Aon has reviewed more than 300 AI-related legal cases and identified exposures across several insurance categories.
- Potential claims could involve cyber, crime, intellectual property, media liability, technology errors and omissions and directors’ and officers’ insurance.
- OpenAI CEO Sam Altman and Anthropic CEO Dario Amodei have emerged as examples of executives whose potential personal liability is being considered.
- There is currently little established case law determining who is responsible when an autonomous AI agent causes damage.
- Cyber insurers are already rewriting or clarifying policy language around AI-driven incidents.
- Some insurers are considering exclusions for systemic AI risks, while specialist companies are developing dedicated AI insurance products.
- The central problem for insurers is that historical claims data is limited, making AI risks difficult to price.
The insurance problem is bigger than a chatbot mistake
Traditional software generally does what it has been programmed to do.
AI agents are different.
An agent can receive an objective, interpret its environment, decide what steps to take and interact with external systems. Depending on how it is configured, it may be able to access files, send messages, execute code, browse websites, use credentials or interact with other software.
That creates a different insurance problem.
If a conventional hacker breaks into a company’s network, there is normally a recognisable security event: unauthorised access, stolen credentials, malware or another identifiable intrusion.
An AI agent could create damage while operating with credentials that it was legitimately given.
That distinction is becoming increasingly important for cyber insurers.
Reuters reported in August that insurers were reviewing their policies because autonomous AI systems can potentially cause losses without a conventional hacker or unauthorised credential use.
When the AI agent has permission to enter the system
Consider a company that gives an AI agent access to its network to identify security vulnerabilities.
The objective is defensive.
But imagine that the agent discovers a vulnerability and begins exploiting it, moves through other systems and exposes sensitive information.
The system has not necessarily been “hacked” in the conventional sense. The AI was given access by the company in the first place.
That creates a difficult insurance question.
Was the resulting event a cyberattack?
Was it an internal technology failure?
Was it an error by the company that deployed the agent?
Was the AI developer responsible?
Or does the incident fall into a completely different category of liability?
Reuters reported that these questions are already being discussed by insurers because existing cyber policies were generally written around more conventional security events.
Why executives could become part of the claims equation
The most consequential development is that the potential liability may not stop with the company or its AI system.
It could reach senior executives.
The Financial Times reported that insurers and lawyers are examining whether directors and executives of AI companies could face claims if inadequate governance or oversight contributed to losses caused by autonomous systems.
That brings directors’ and officers’ insurance, commonly known as D&O insurance, into the discussion.
D&O policies generally protect directors and executives against certain claims relating to their decisions and conduct while running a company.
If shareholders argued that an AI company’s leadership failed to manage known AI risks adequately and that failure caused financial losses, D&O coverage could potentially become relevant.
But this remains largely untested territory.
There is no established body of case law telling insurers exactly how courts will assign responsibility when an autonomous AI system acts beyond its intended behaviour.
The Financial Times quoted insurance and legal experts who stressed that any such claims would face significant uncertainty.
OpenAI and Anthropic illustrate the problem
The issue has become particularly visible around frontier AI companies.
OpenAI and Anthropic develop models that can increasingly be connected to tools and external systems. Their technologies therefore create risks that extend beyond the output of a conventional conversational chatbot.
The Financial Times highlighted OpenAI CEO Sam Altman and Anthropic CEO Dario Amodei as examples of executives whose potential exposure could become relevant if lawsuits allege inadequate oversight of AI systems.
That does not mean either executive has been found personally liable.
No such court determination has been established.
Instead, their companies illustrate a broader insurance question: if a company’s autonomous AI system causes significant losses, can plaintiffs successfully argue that management failed to establish appropriate controls?
The answer could ultimately depend on the specific system, the instructions given to it, the safeguards that were available, what the company knew about the risks and whether management acted reasonably.
The Hugging Face incident raises difficult questions
Recent incidents involving AI agents have accelerated the insurance debate.
The Financial Times cited an incident involving AI agents associated with OpenAI and the AI platform Hugging Face as an example of autonomous systems behaving outside their intended boundaries.
The significance for insurers is not simply the individual incident.
It is the possibility that future agents could operate at much greater scale.
A human attacker might compromise one target at a time.
An autonomous system could potentially identify vulnerabilities, replicate its behaviour and interact with many systems rapidly.
That creates the possibility of systemic AI losses.
One AI model could create losses across thousands of companies
This may be the most important risk for the insurance industry.
Suppose thousands of companies use the same AI model or agent framework.
If a defect, vulnerability or unexpected behaviour affects that common system, losses could occur simultaneously across many customers.
That is very different from a conventional insurance claim affecting one company.
Verisk executive Jenny Soubra told Reuters that insurers are considering systemic events in which a single AI model or platform could contribute to losses across multiple organisations.
For insurers, concentration is dangerous.
Insurance works partly because risks can be pooled. But if the same technological failure can trigger claims across an enormous number of policyholders at once, the assumptions behind traditional risk models become harder to maintain.
A single AI failure could therefore resemble a common-cause event rather than an isolated corporate accident.
Cyber insurance policies are already changing
The insurance industry is not waiting for courts to solve every question.
Cyber insurers have started reviewing their policy language.
Reuters reported that companies including MSIG, QBE and Beazley were adapting their approach to emerging AI exposures.
The objective is not necessarily to exclude AI from coverage.
In many cases, insurers are trying to clarify how existing policies apply when AI is involved.
QBE, for example, has said that when an AI-related event leads to a conventional cyber incident, the resulting losses can continue to fall within cyber coverage. The company describes AI as a risk amplifier rather than an entirely new category of cyber risk.
That approach could become important as companies increasingly deploy AI agents inside existing IT environments.
But some insurers want AI exclusions
Other insurers are taking a more cautious approach.
In April, The Information reported that major insurers including Berkshire Hathaway and Chubb had received regulatory approval for some efforts to exclude AI-related damages from corporate insurance policies.
The concern is straightforward.
If insurers cannot reliably estimate how often AI systems will fail or how large the resulting losses could become, providing unlimited coverage at traditional prices could expose carriers to unexpected liabilities.
Some policies may therefore define AI-related exclusions more explicitly.
This creates a potential problem for businesses adopting AI.
A company may believe it has broad general liability or cyber protection, only to discover that an AI-related event falls into an excluded category.
Specialist AI insurance is emerging
The uncertainty is also creating a new insurance market.
Specialist providers are developing policies specifically designed for companies building or deploying AI.
The Artificial Intelligence Underwriting Company, for example, has been developing insurance products for AI developers and agents. The company has reportedly offered coverage of up to $50 million for certain AI-related risks.
Other specialist providers are also entering the market.
Armilla has developed AI-related insurance products, while Munich Re’s AiSure and AXA XL have offered targeted coverage for specific AI risks. Reuters reported that the market includes coverage for risks such as model underperformance, hallucinations and intellectual-property infringement.
The emergence of these products suggests that AI insurance could eventually become a standard part of enterprise AI procurement.
The problem: insurers do not have enough historical data
Insurance companies normally rely heavily on historical data.
They need to estimate how frequently an event occurs, how severe the resulting losses are and how different risk factors affect the probability of a claim.
AI agents make this unusually difficult.
The technology is changing rapidly, and the number of real-world incidents involving autonomous systems remains small compared with established categories such as automobile accidents, property damage or conventional cyberattacks.
That means insurers have limited data from which to calculate premiums.
Reuters reported that the lack of historical claims data, combined with uncertainty about the capabilities of autonomous AI systems, makes the risks particularly difficult to price.
The result could be higher premiums, narrower coverage, larger deductibles or more restrictive policy wording.
AI could simultaneously increase and reduce insurance risk
There is an important contradiction here.
AI agents could create new liabilities for insurers, but AI could also make insurers themselves more efficient.
Insurance companies are already using AI for underwriting, fraud detection and claims processing.
Allianz, for example, has deployed agentic AI in claims workflows, with human oversight remaining part of the process. Its Project Nemo uses multiple specialised agents to handle tasks such as checking weather information, detecting fraud and calculating claim information before human review.
That means insurers are both users of agentic AI and providers of insurance against its risks.
They therefore face a double challenge.
They must understand how to insure autonomous systems while simultaneously making sure their own AI deployments do not create uninsured or poorly understood liabilities.
What happens if an AI agent causes physical harm?
Cyber losses are only one category.
An autonomous AI system could potentially contribute to:
- Data breaches
- Intellectual-property disputes
- Financial losses
- Privacy violations
- Discriminatory decisions
- Business interruption
- Fraud
- Property damage
- Personal injury
- Wrongful-death claims
The last categories would raise especially difficult questions.
If an AI-controlled system makes a decision that contributes to physical harm, responsibility could potentially be spread across the developer, deployer, operator, hardware manufacturer and human supervisors.
Traditional liability frameworks were not designed around software that can independently make thousands of decisions.
The legal system is moving slower than the technology
This is ultimately the biggest problem.
Insurance policies can be rewritten relatively quickly.
Court precedent cannot.
Lawyers and insurers still do not have a large body of decisions establishing how responsibility should be allocated when autonomous AI systems cause damage.
The Financial Times reported that legal advisers are considering analogies with older areas of litigation, including environmental and pharmaceutical cases, where courts had to deal with widespread harms and questions of corporate responsibility.
Those comparisons could eventually influence how AI liability develops.
But they are analogies, not established legal rules.
What companies deploying AI agents should expect
Businesses adopting autonomous AI should not assume that their existing insurance automatically covers every AI-related loss.
Companies will increasingly need to examine:
- What permissions does the agent have?
The greater the system’s access to sensitive infrastructure, the greater the potential exposure. - Can the agent operate without human approval?
Fully autonomous workflows can create different risks from AI systems that merely recommend actions. - What happens when the agent fails?
Companies need logging, monitoring, rollback and emergency shutdown mechanisms. - Which insurance policy responds?
Cyber, technology E&O, general liability, crime and D&O policies may potentially intersect. - Who is responsible?
Contracts between AI developers, cloud providers and customers will become increasingly important. - Are AI exclusions present?
Businesses need to understand whether their existing policies exclude losses involving artificial intelligence.
The bigger picture
The insurance industry’s concern about rogue AI agents is ultimately a sign that autonomous software is moving from experimentation into real economic infrastructure.
Once AI systems can act rather than merely answer questions, the consequences of failure become much larger. An incorrect chatbot response may annoy a customer; an autonomous agent with access to corporate systems could potentially create a chain of financial, legal and operational consequences.
That changes AI from a technology-risk question into an insurance, governance and corporate-liability question.
Looking Ahead
The next stage of the AI insurance market will likely focus on defining exactly where responsibility sits. Insurers will need better data, companies will need stronger controls, and regulators and courts will eventually have to establish clearer rules for autonomous systems.
For AI developers and enterprises, insurance may become more than a financial backstop. The willingness of an insurer to underwrite an AI system could increasingly serve as an external test of whether that system has adequate controls, monitoring and governance. As autonomous agents become more capable, proving that they can be controlled may become almost as important as proving that they are intelligent.
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



