
Industry participants at NetDiligence’s Philadelphia summit found no common framework for insuring AI-related risks. They discussed cyber security, corporate liability and emerging exposures for which suitable coverage remains unclear.
Insurers have yet to agree on which policies should cover risks related to artificial intelligence. Participants said so at a panel during the NetDiligence Digital Risk Summit in Philadelphia on October 6. The discussion highlighted how the consequences of AI use can cross several lines of insurance.
Gail Arkin, senior vice president and chief legal officer at Berkley Cyber Risk Solutions, said some cases could involve directors’ and officers’ liability. A cyber policy may not address whether a company violates third-party rights, uses data without permission or embeds bias in its programs, she said. Boards are drawing up AI policies and hiring teams to monitor its use, making the issue broader than a conventional technology or cyber risk.
Tim Nazzaro, global digital products manager at Hartford Steam Boiler, divided AI risks into three categories. The first covers security and privacy, such as personal data being exposed by an AI tool. He said a company’s responsibility for such an incident should be clearly covered by a cyber policy. The second category could involve other insurance lines: for example, discrimination in hiring caused by an AI tool might fall under employment-practices liability coverage.
The third category, Nazzaro said, consists of emerging risks that have no clear place in existing coverage. He warned insurers against expanding coverage automatically without underwriting. Fines for violating AI regulations that are not privacy laws, for example, may not be covered by a standard cyber policy.
Danielle Roth, AXA XL’s North American practice leader and head of cyber claims, urged insurers not to treat AI as a single, uniform risk. They should instead examine the specific policy: who is insured, what the claim concerns, whether the agreement responds and whether exclusions apply. In a breach investigation, it may be impossible to determine whether AI was used, she said.
The panel also discussed how AI is changing cybercriminals’ work. Michael Brunetti, MOXFIVE’s vice president of incident response, said his company had been busier than ever since around July 4. Traditional ransomware and double extortion remain common, but he said attacks on cloud services and software-as-a-service applications are changing.
Brunetti said groups such as ShinyHunters use AI to search stolen data for the most sensitive material, craft more targeted extortion messages and quickly build profiles of executives. Work that once took days or weeks can now take minutes or hours, he said.
Roth added that AXA XL had a busy summer, including attacks on law firms, which in her view have become a preferred target in place of the health sector. Most attacks relied on phishing rather than new AI techniques, she said. Employees remain both a company’s important line of defence and a potential weak link.
