Security News

Cybersecurity news aggregator

INFO News Dark Reading

Insurers Search for Answers to Rein in Rogue AI

  • What: Insurers are addressing risks from rogue AI incidents
  • Impact: CISOs and insurance firms are evaluating policies and responses to AI-related harm
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBER RISK APPLICATION SECURITY CYBERSECURITY OPERATIONS INSIDER THREATS Cybersecurity In-Depth: Feature articles on security strategy, latest trends, and people to know. Insurers Search for Answers to Rein in Rogue AI As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout. Robert Lemos,Contributing Writer September 4, 2026 5 Min Read SOURCE: DIGINEER STATION VIA SHUTTERSTOCK When Maria Long heard about OpenAI's rogue model attacking AI-model service provider Hugging Face, her first stop was to review her firm's technology errors and omissions (Tech E&O) policy. As the chief underwriting officer for cybersecurity insurance services firm Resilience, she understood that rogue AI agents causing inadvertent compromises could result in significant losses to insurers in the future. This incident showed that the future wasn't that far off. For Hugging Face, the incident would almost certainly be covered by cyber-liability insurance as a classic security breach. However, if AI agents routinely escape containment, insurers have to consider that the volume of policy claims could grow. Even more concerning is the view from an insured company that uses agentic AI. In the July rogue-agent incident, OpenAI was the user; future incidents could involve an enterprise deploying agents from one of the major model providers. If those deployed agents go rogue, questions remain about who would be responsible for the badly behaving programs, she says. Would it be the enterprise or the model provider? Related:Stronger Security Drives Ransomware Groups to Recruit From Within "Typically with a Tech E&O policy, the intent of that policy is to cover the organization if there were to be a financial loss to a third party that is their client," Long says. "But the gap that's so interesting is, well, [an affected firm such as Hugging Face] is not a client — you may have created a financial loss to a third party." As the insurance industry attempts to determine who is liable when autonomous agents go rogue, AI has already become a major factor in cyber insurance losses. While Resilience did not have a single claim stemming from a fully automated AI attack chain, insured losses from AI-powered social engineering have surged, contributing to 85% of losses in the first half of 2026, up from 18% in the first half of 2024. More professional lures and deepfakes created using AI models are to blame, Resilience stated in its 2026 Midyear Cyber Risk report. As Incidents Grow, Liability Remains a Question While attackers' use of AI is certainly a major problem facing corporate security teams, a bigger problem is that companies' own AI agents keep going rogue. In addition to OpenAI, both Meta and Anthropic have acknowledged that AI agents have escaped research sandboxes and taken offensive cyber actions against third parties. At the end of July, for example, the United Kingdom's AI research policy center, the AI Security Institute, discovered that during a cybersecurity challenge run 122 times, two advanced models — Anthropic's Mythos 5 and OpenAI's GPT-5.6-Sol with cyber classifiers— took 19 unsanctioned actions on the live Internet. Overall, 8% of cases resulted in rogue behavior. Related:The Guardrails Debate: Security Researcher Changes His Mind "These attempts were unsuccessful, and our investigations have not evidenced any resulting real-world harm," the institute stated in an analysis. "But this is the first time we have seen risks around autonomy and deception manifest this clearly, without specific prompting, in the real-world." Overall, incidents of AI system failures and safety issues have taken off in 2026. The four preceding years saw a few dozen incidents (34 to 36) reported per year, but so far in 2026, there have already been 43, according to the MIT AI Risk Initiative. As companies accelerate their adoption of AI and increasingly automate some tasks with AI agents, cybersecurity has become a major concern, but one that often takes a back seat to efforts to gain productivity and business advantage from the new technology. The problem with AI agents, however, is their persistence in pursuing their goals, and a single bad decision by an AI agent could trigger a worm-like outbreak of attacks, says Jack Nelson, CISO and deputy general counsel at Ivanti, an endpoint-security management provider. Related:CISOs Break Their Silence in 'Declassified' Docuseries "I suspect your insurance carriers are having a hard time underwriting things like this because they just don't know how to [gauge liability] because of how fast these incidents could balloon," he says. The issue could extend to criminal liability as well. The Trump administration's Executive Order 14409, published in June, prioritizes the investigation and prosecution of AI-enabled attacks in which anyone "utilizes AI to illegally access or damage a computer without authorization." Considering that attacks by rogue AI agents are not easily discernible from malicious AI attacks — Hugging Face initially just knew it was being attacked — rogue AI agents could result in prosecutions, a problem, considering that AI agents' goal-oriented behavior makes them hard to control. Moving Beyond Breaches and Downtime Currently, much of cyber insurance focuses on breaches and downtime, and that remains the focus of most insurers, says Resilience's Long. As companies rely more heavily on AI services, and an AI service goes down due to an error or malicious action, this could lead to claims for losses. "If you're now six months, one year, two years deep into your AI build-out, and really making this a routine part of your day-to-day [operations], what happens if that service is down and you can't use it?" she asks. "Does that cause an interruption to the business? Does that result in a monetary loss to the organization?" Yet, the companies that are building out their AI frameworks and creating new services need to take care in having adequate controls for AI agents that attempt to exceed their remit, Long says. These incidents are "a really good example of 'we're just trying to test something, we're running an experiment, but maybe we're not necessarily thinking about the ramifications and maybe whether this was really planned out the way that it should have been,'" she says. Overall, as with much of the innovation around AI systems, everything is up in the air at the moment and could change in six months, says Ivanti's Nelson. Given the deep pockets of the foundational AI model firms, however, and the past history of the 'shared responsibility' model for cloud services, much of the responsibility will likely land on the organization that deploys agents, he says. "Liability has yet to be determined — whether it's totally going to sit with the person that unleashed the agent, or is it going to sit with the actual model creators that created a model that could do that," he says. "I suspect the former is more likely, because [the operator has] so much input in terms of harnesses, skills, how you're training the agent." About the Author Robert Lemos Contributing Writer Rob is an award-winning, veteran technology journalist of more than 30 years, reporting on global cybersecurity issues, the latest offensive and defensive technologies, malware incidents, cyber conflict, and AI's impact on software and cybersecurity. A former research engineer, Rob has written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. He has received five awards for journalism, including Best Deadline Journalism (Online) in 2003 for his coverage of the Blaster worm. Rob also analyzes data on various trends using Python and R for both his reporting and his clients. Recent reports include analyses of the shortage in cybersecurity workers, annual vulnerability trends, and annual threat reports. Rob holds degrees from Cornell University in Electrical Engineering and Computer Science (double major). Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Building an Effective Red Team: Beyond Penetration Testing How to Leverage Threat Intelligence Without Drowning: The Zero Noise Approach Cloud Incident Response: Forensics in Distributed Environments Beyond the Login: Key Considerations for Evaluating Identity Security SASE Pivot and Trends 2026: A Gartner Keynote More Webinars You May Also Like CYBER RISK How Can CISOs Respond to Ransomware Getting More Violent? by James Doggett JAN 28, 2026 CYBER RISK US Cyber Pros Plead Guilty Over BlackCat Ransomware Activity by Alexander Culafi JAN 05, 2026 CYBER RISK Switching to Offense: US Makes Cyber Strategy Changes by Robert Lemos NOV 21, 2025 CYBER RISK Microsoft Exchange 'Under Imminent Threat,' Act Now by Arielle Waldman NOV 12, 2025 Edge Picks APPLICATION SECURITY AI Agents in Browsers Light on Cybersecurity, Bypass Controls CYBER RISK Browser Extensions Pose Heightened, but Manageable, Security Risks CYBERSECURITY OPERATIONS Video Convos: Agentic AI, Apple, EV Chargers; Cybersecurity Peril Abounds ENDPOINT SECURITY Extension Poisoning Campaign Highlights Gaps in Browser Security Latest Articles in The Edge CYBER RISK Stronger Security Drives Ransomware Groups to Recruit From Within SEP 1, 2026 CYBER RISK The Guardr

Share this article