Artificial intelligence has rapidly shifted from a niche innovation to a foundational component of modern business operations.  Organizations across industries are integrating AI into workflows, decision-making, customer engagement, and automation.  For example, financial institutions use AI for fraud detection and credit modeling; healthcare organizations deploy AI for diagnostics and patient triage; retailers rely on AI for dynamic pricing and customer analytics; manufacturers integrate AI into robotics, supply chain forecasting, and quality control; and professional services firms use AI to draft documents, analyze contracts, and support client work. This transformation promises efficiency, speed, and competitive advantage.  Yet from an underwriting standpoint, AI also introduces a new class of risks that expands the attack surface, amplify existing vulnerabilities, and create systemic exposures that traditional Cyber Liability frameworks were not designed to address.

This essay provides background on how threat actors are using AI to target companies, examines how AI is reshaping cyber risk, why it expands the attack surface, and what this means for the future of Cyber Liability underwriting.  It approaches the topic through the lens of an underwriter tasked with evaluating emerging threats, anticipating loss scenarios, and ensuring that coverage, pricing, and portfolio management evolve in step with technological change.

Background: How AI Is Transforming the Threat Landscape

AI is not only expanding the attack surface; it is transforming how attackers operate.  Threat actors are leveraging AI to scale, automate, and personalize attacks in ways that were previously impossible.

AI-Enhanced Social Engineering

Social engineering remains the leading cause of cyber incidents.  AI supercharges it.  Threat actors can now generate perfectly written phishing emails, deepfake audio mimicking executives, synthetic identities, personalized lures based on scraped data, and real-time conversational fraud.  The barrier to entry has collapsed.  What once required linguistic skill, cultural fluency, and time now requires a few prompts.

Autonomous Malware and Adaptive Threats

AI-driven malware can mutate its code to evade detection, learn from defensive responses, identify the most valuable assets in a network, prioritize attack paths, and operate without human oversight.  This represents a fundamental shift.  Traditional signature – based defenses are increasingly ineffective against threats that evolve dynamically.

Model Manipulation and AI-Specific Attack Vectors

AI introduces entirely new classes of vulnerabilities: prompt injection, model poisoning, model theft, inference attacks, and hallucination exploitation.  These are not theoretical.  They are being actively weaponized.  Underwriters must now consider exposures that did not exist even a few years ago.

Data Exposure at Scale

AI systems ingest massive datasets – often far more than traditional applications.  A single misconfiguration can expose PII, PHI, proprietary algorithms, customer records, internal communications, and intellectual property.  The scale of potential loss is exponentially larger.

The Expanding Attack Surface: A Structural Shift

Employees increasingly adopt AI tools – and oftentimes without formal approval, governance, or security review.  This includes generative AI chatbots, browser extensions, automation tools, unvetted APIs, and personal AI assistants.  Each introduces new data flows, new dependencies, and new potential points of compromise.  This “shadow AI” expands the attack surface faster than organizations can map it. In other words, the attack surface is no longer defined by endpoints, networks, and applications, but rather, it is now defined by models, data flow, interactions, APIs, third-party dependencies, and user behavior.  This shift requires a new mental model for risk assessment.  AI expands the attack surface in four primary ways:

  1. Increased Complexity – More components, more integrations, more data flows, and more opportunities for misconfiguration.
  2. Increased Interconnectivity – AI systems often sit at the center of workflows, touching multiple systems simultaneously.
  3. Increased Data Sensitivity – AI models require large, diverse datasets, often containing sensitive or regulated information.
  4. Increased Autonomy – AI systems make decisions without human oversight, amplifying the impact of errors or manipulation.

From an underwriting standpoint, this means the traditional control – based approach – MFA, EDR, backups, segmentation – is necessary but insufficient.  AI introduces risks that are behavioral, systemic, and dynamic.

Implications for Cyber Liability Underwriting

Underwriting AI-driven risk requires a shift in how we evaluate organizations.  The goal is not to penalize AI adoption, but to understand how it governed, secured, and integrated into operations.

Governance as the First Line of Defense

Strong AI governance is emerging as a leading indicator of resilience.  Key questions that underwriters must consider include the following:

  • Who owns AI risk within the organization?
  • Whether an AI governance committee exists
  • How AI deployments are inventoried and reviewed
  • Whether policies govern employee use of generative AI
  • How third-party AI vendors are evaluated.

Organizations that threat AI governance as a core security function – not an innovation afterthought – are better positioned to manage risk.

Data Management as a Central Underwriting Factor

AI is only as secure as the data it touches.  Underwriters must assess data classification practices, minimization strategies, access controls, encryption standards, retention policies, and vendor data – handling agreements.  A breach involving AI systems can expose exponentially more data than a traditional incident.

Model Security and Monitoring as Emerging Controls

Organizations must demonstrate model validation, monitoring for drift or manipulation, access controls for training and inference, logging of model interactions, and testing for prompt injection vulnerabilities.  These controls are still maturing, but they will become standard underwriting questions within the next few years.

Third Party AI Risks as a Deep Supply Chain Exposure

AI supply chains are more complex than traditional cloud services, and most organizations do not build AI models from scratch.  They rely on cloud-hosted large language models, third party training datasets, open-source libraries, pre-trained embeddings, and external inference APIs.  This creates a layered supply chain where a single vulnerability – or a single compromised vendor – can cascade across thousands of insureds simultaneously.  From an underwriting perspective, this represents a potential accumulation event hiding in plain sight. Underwriters must understand which models the organization relies on, where those models are hosted, what data is sent to third – party providers, whether indemnification exists, whether sensitive client data is comingled with other, outside datasets, and whether the organization can operate if the model becomes unavailable.  This is critical for assessing business interruption exposure.

AI-Driven Loss Scenarios in Pricing and Modeling

AI introduces new loss vectors, including incorrect automated decisions, privacy breaches from training data, reputational harm from hallucinations, operational disruption from model failure, and fraud enabled by deepfakes or synthetic identities. There has been a significant investment by regulatory authorities to ensure that AI usage and outputs do not violate individual rights or statutory frameworks, and increased oversight in this area could result in regulatory enforcement actions that target companies using certain types of “high risk” AI solutions. These scenarios must be reflected in underwriting guidelines, pricing models, and portfolio management strategies.

The Future of Cyber Liability in an AI – Driven World

AI will reshape Cyber Liability in three major ways.

  1. Coverage Evolution
    Policies will need to address model manipulation, AI-driven fraud, liability for automated decisions, data exposure through AI training, intellectual property risks related to model outputs, and business interruption from AI system failure.  Carriers that adapt quickly will differentiate themselves.
  2. Increased Focus on Accumulation Risk
    AI supply chains create systemic exposure.  A single compromised model provider could impact thousands of insureds across multiple industries simultaneously.  This resembles cloud concentration risk – but with deeper interdependencies.
  3. A Shift Toward Continuous Underwriting
    Static, point – in – time underwriting is insufficient for AI – driven risk.  The future will involve continuous monitoring, dynamic risk scoring, real-time data feeds, and automated underwriting augmentation.  AI will eventually help underwriters manage AI risk – a full-circle evolution.
What Organizations Can Do Today

To remain insurable and resilient, organizations should focus on five foundational pillars:

  1. Build a Formal AI Governance Framework – Define ownership, policies, and review processes.
  2. Inventory All AI Systems – You cannot secure what you cannot see.
  3. Strengthen Data Security – Classify, minimize, encrypt, and monitor.
  4. Evaluate Third Party AI Vendors – Demand Transparency, contractual protections, and security attestations.
  5. Implement Model Security Controls – Test for vulnerabilities, monitor for drift, and restrict access.

Organizations that take these steps will be better positioned to secure coverage, negotiate favorable terms, and maintain operational resilience.

Conclusion: AI as Both Enabler and Threat Multiplier

AI will be one of the most transformative business enablers of the next decade.  But it will also be one of the most powerful threat multipliers.  As underwriters, brokers, and risk leaders, we must evolve our frameworks just as quickly as the technology evolves.

The attack surface is no longer defined by endpoints and networks.  It is defined by interactions, models, data flows, and the governance structures that surround them.  Organizations that treat AI governance as a strategic imperative – not a technical afterthought – will be the ones best positioned to thrive in this new era.

Cyber Liability underwriting must evolve accordingly.  The future belongs to those who understand that AI is not just a tool.  It is an ecosystem – on that demands visibility, discipline, and an innovative approach to risk.

Meet the Author

Headshot of John ButlerJohn Butler

Cyber/Tech E&O Product Leader, E-Risk Services

John Butler is a Cyber/Tech E&O Product Leader at E-Risk Services, a Nationwide Company, with 24 years of experience in specialty insurance and underwriting and RPLU+ and CPLP designations.  He writes on the underwriting implications of artificial intelligence and the fast-changing world of Cyber and Technology E&O – from the frameworks and policy language insurers need to price AI-driven exposures, to the practical realities of building coverage for risks the market is still learning to define.  In his role, John develops AI underwriting strategy, drafts forward-looking policy endorsements, and helps translate emerging technology risk into defensible, real-world coverage.  His writing brings a pragmatic, product-minded lens to one of the Industry’s most pressing questions: how insurers can underwrite emerging AI risk with discipline and foresight.

News Type

PLUS Blog

Business Line

Cyber Liability, Professional Liability

Contribute to

PLUS Blog

Contribute your thoughts to the PLUS Membership consisting of 45,000+ Professional Liability Practitioners.

Related Podcasts

Related Articles