By Mauro Marongiu
Artificial intelligence is now part of the fabric of society – powering the systems we use to make decisions, and helping us develop the next innovations more quickly, accurately and efficiently.
As the world embraces the transformative power of AI, the topic of the risks associated with this leap forward are never far from discussions – from boardroom debates to brow-furrowing headlines.
One fast-developing angle to explore this debate from is the accompanying cyber security risks associated with AI, and how risk managers and insurers are horizon-scanning for this threat, and working on resilience-boosting solutions.
The recent Bletchley AI Safety Summit in the UK underscored the dual nature of AI, emphasising its promise while cautioning against its misuse. Indeed, AI is something of a split personality in that it plays a dual role in both exacerbating and mitigating threats.
Harnessing AI for cyber protection
On the one hand of course, the rapid integration of AI into our technological fabric offers clear and unparalleled opportunities for cyber defenders. AI-powered risk analysis can streamline incident response, accelerating alert investigations and triage. Moreover, AI holds the promise of enhancing threat detection, identifying vulnerabilities, and fortifying defences against cybercriminals.
However, the same AI capabilities that empower defenders also pose challenges. Attackers can leverage AI to develop sophisticated malware at an unprecedented pace, exploiting vulnerabilities and evading traditional security measures. From autonomously replicating malware to leveraging AI to bypass antivirus and firewall systems, adversaries are continually innovating their tactics, presenting a formidable ‘cat and mouse’ challenge to cyber security professionals.
The European cyber insurance landscape
For Europe’s cyber insurers, meanwhile, the landscape is characterised by fierce competition and evolving risk dynamics. While AI has garnered considerable attention within the insurance industry, its practical applications and implications remain a subject of exploration. There is a pressing need to evaluate AI’s potential impact on cyber risk assessment, policy underwriting, and claims management.
As cyber threats evolve, insurance policies must adapt to address emerging risks effectively. While the focus may currently be on malware and ransomware, the rise of AI-enabled attacks necessitates a proactive approach to policy wording and coverage. From marine cyber risk to autonomous systems, insurers must anticipate and mitigate the diverse threats posed by AI-driven vulnerabilities.
A key question is that of liability: who / which entity would be liable in the event of an AI-powered cyber breach? Add to this the rise of autonomous vehicles, and the potential impact and liability contagion increases. Liability might fall on AI system developers for flaws, original equipment manufacturers for cyber security oversights, or operators for negligence. Insurers would need to evaluate each party’s responsibility and coverage under relevant insurance policies, encompassing product liability, cyber security, and autonomous vehicle insurance.
Ransomware and the ethical Imperative
Ransomware, a persistent menace in the cyber security landscape, underscores the ethical dilemmas faced by insurers. Indeed, there is ongoing significant debate around this subject. While some jurisdictions permit insurers to pay claims that cover ransoms to retrieve data and restore systems in the worst scenario case where the company wasn’t able to protect itself, others, like Italian companies, adopt a principled stance against what is essentially seen by lawmakers as incentivising extortion. The debate surrounding ransomware payouts highlights the broader ethical considerations within the insurance sector and the need for cohesive regulatory frameworks.
Not if, but when
It is imperative to recognise that AI-powered cyber breaches are not a matter of if, but when, for any organization across industries. As such, organizations must prioritise resilience, adopting proactive measures to fortify their cyber defences and mitigate the impact of inevitable breaches. From robust incident response plans to AI-driven threat detection, resilience is the cornerstone of effective cyber security strategies in an AI-driven world.
By harnessing the transformative potential of AI while prioritising resilience and ethical considerations, it will be possible to safeguard our digital future against emerging threats. However, the insurance sector must keep pace with the challenges and opportunities that AI presents, in order to support individuals, businesses, governments and other key stakeholders in the effort to build cyber resilience.
The author
Mauro Marongiu is Technical Head of Cyber Underwriting, Alta Signa






