28 Jul 2026
by Scott Mewse

As AI becomes increasingly sophisticated, the threat it poses should not be underestimated. A report from Accenture found that 90% of companies lack the maturity to effectively counter advanced AI-enabled threat.

It’s easy to see why. Over the course of 2025, the average time in which an attack was executed shortened from three days to just 12 minutes. Now, attacks are being executed at machine speed, outpacing human triage.

And it’s not just the speed at which attacks are being executed that is of concern. With AI comes new threats such as deepfakes, synthetic media and polymorphic malware.

Multiple risks of AI

It may sound like science fiction, but the risks are very real. Here are some examples of what can go wrong:

  • Attackers use real-time, AI-generated voice synthesis to impersonate a C-level executive on a videocall. As the deepfake is so convincing, the employee might not question a request to release money or confidential information. 
  • Hackers corrupt an organisation’s AI training data, causing it to malfunction and behave erratically. But, unless the change is obvious, errors could continue for months, even years. 
  • An AI agent writes faulty code or hallucinates legal precedents, potentially causing disruption to services and financial loss. Similarly, autonomous AI shuts down operations after it hallucinates a phantom risk.
  • Employees use GenAI to create assets that turn out to inadvertently infringe intellectual property, leaving the organisation open to legal action.
Cover conundrum

The novelty of these risks means there are lots of questions around the insurance response. For example, would an organisation be covered where a deepfake uses social engineering to get an employee to make a payment? Or, where autonomous AI shuts down operations, would that be considered business interruption due to system failure, or would the claim be rejected as the technology is working as designed?

Neither is it an easy risk to cover. Mapping the coverage landscape shows there’s no single policy that covers all AI perils. As examples, an AI-aided data breach might fall under cyber insurance; a deepfake fraud under crime insurance; and a chatbot error under technology error and omissions.

Governance playbook

Against this backdrop, robust AI governance is essential. To minimise risk, organisations need to be clear about AI policies and ensure the right rules and frameworks are in place.

Organisations should consider:

  • Listing approved AI tools: Where employees use any AI tools, there is a risk of data leakage, regulatory non-compliance and breach of copyright. Additionally, in the event of a breach, an insurance claim could be declined due to ‘unauthorised use’ exclusions. Providing employees with a list of approved AI tools will enable tighter control.
  • Using out-of-band verification: A biometric marker such as a fingerprint, face or voice can be stolen and shouldn’t be trusted as a sole factor of authentication. Out-of-band verification – where a user’s identity is confirmed through a separate independent communication channel such as their phone or email – can reduce the risk of deepfake attacks.
  • Switching on AI-driven cybersecurity: AI-driven endpoint detection and response (EDR) use behavioural analytics to identify and respond to cyberthreats in real-time. This can stop attacks before damage occurs and reduce breach costs and lifecycles. It can also lead to more favourable terms on insurance.
Insurance shift

As AI introduces new and potentially systemic risks, the insurance market will change too. Insurers are already looking to create more certainty for both themselves and their insureds by replacing silent AI with affirmative endorsements and specific exclusions.

Products could change too. Traditional cyber insurance is likely to be superseded by digital risk insurance, and, in time, standalone AI products may also emerge to cover more specialist risks. It may also be necessary for the government to step in with an insurance pool for catastrophic AI events.

With so much set to change, it’s important to work with experts to ensure your organisation understands and manages the risks associated with AI.

AI will bring efficiencies and innovation, but it will also shift the risk and insurance landscape. The winners won’t be the organisations with the best AI, but the ones with the best governance of their AI.

Related topics