Skip to content
Tech News
← Back to articles

Insurers Search for Answers to Rein in Rogue AI

read original more articles
Why This Matters

The rise of rogue AI incidents highlights the urgent need for the insurance industry to adapt policies and establish liability frameworks for autonomous AI failures. As AI-driven attacks and malfunctions become more prevalent, understanding who is responsible—whether enterprises or AI providers—is crucial for managing risks and protecting consumers. This evolving landscape underscores the importance of robust AI safety measures and clear legal accountability in the tech industry.

Key Takeaways

When Maria Long heard about OpenAI's rogue model attacking AI-model service provider Hugging Face, her first stop was to review her firm's technology errors and omissions (Tech E&O) policy.

As the chief underwriting officer for cybersecurity insurance services firm Resilience, she understood that rogue AI agents causing inadvertent compromises could result in significant losses to insurers in the future. This incident showed that the future wasn't that far off. For Hugging Face, the incident would almost certainly be covered by cyber-liability insurance as a classic security breach. However, if AI agents routinely escape containment, insurers have to consider that the volume of policy claims could grow.

Even more concerning is the view from an insured company that uses agentic AI. In the July rogue-agent incident, OpenAI was the user; future incidents could involve an enterprise deploying agents from one of the major model providers. If those deployed agents go rogue, questions remain about who would be responsible for the badly behaving programs, she says. Would it be the enterprise or the model provider?

Related:Stronger Security Drives Ransomware Groups to Recruit From Within

"Typically with a Tech E&O policy, the intent of that policy is to cover the organization if there were to be a financial loss to a third party that is their client," Long says. "But the gap that's so interesting is, well, [an affected firm such as Hugging Face] is not a client — you may have created a financial loss to a third party."

As the insurance industry attempts to determine who is liable when autonomous agents go rogue, AI has already become a major factor in cyber insurance losses. While Resilience did not have a single claim stemming from a fully automated AI attack chain, insured losses from AI-powered social engineering have surged, contributing to 85% of losses in the first half of 2026, up from 18% in the first half of 2024. More professional lures and deepfakes created using AI models are to blame, Resilience stated in its 2026 Midyear Cyber Risk report.

As Incidents Grow, Liability Remains a Question

While attackers' use of AI is certainly a major problem facing corporate security teams, a bigger problem is that companies' own AI agents keep going rogue. In addition to OpenAI, both Meta and Anthropic have acknowledged that AI agents have escaped research sandboxes and taken offensive cyber actions against third parties. At the end of July, for example, the United Kingdom's AI research policy center, the AI Security Institute, discovered that during a cybersecurity challenge run 122 times, two advanced models — Anthropic's Mythos 5 and OpenAI's GPT-5.6-Sol with cyber classifiers— took 19 unsanctioned actions on the live Internet. Overall, 8% of cases resulted in rogue behavior.

Related:The Guardrails Debate: Security Researcher Changes His Mind

"These attempts were unsuccessful, and our investigations have not evidenced any resulting real-world harm," the institute stated in an analysis. "But this is the first time we have seen risks around autonomy and deception manifest this clearly, without specific prompting, in the real-world."

... continue reading