Estimated reading time: 8 minutes
No Attacker. No Breach. Still A Loss.
The most useful page in CyberCube’s new AI risk report is a blank grid.
Exhibit 5 sets six AI event families against eleven policy types: cyber, crime, media, technology errors and omissions, professional indemnity, directors and officers, general liability, property, products liability, auto liability, and standalone AI. Three states are available for each square. Covered. Silent or unclear. Excluded.
CyberCube fills in none of them. The instruction reads: mark each square based on how your organization’s policies would respond today.
That refusal is the argument. The analytics firm has mapped where AI losses will land and says the answer belongs to each carrier, because it will differ by appetite, technical capability and policy wording. The report is called “Machine State of Mind: A Framework for Quantifying AI-Driven Insurance Risk.”

The Six Families Of AI Insurance Risk
None of the six appeared in the press release. They divide across four dimensions CyberCube calls I2T2: information, intelligence, tactics, and technology stack.
Media, Regulatory and Protected Information
This covers harm the AI causes by existing. Training data disputes, copyright and patent claims, transparency violations, privacy breaches, shadow AI leaks. The model performs no erroneous action at runtime. Its design creates the liability. CyberCube cites Bartz v. Anthropic, where authors sued over pirated books used to train Claude and a $1.5bn settlement was approved this year, alongside Thomson Reuters v. Ross Intelligence, the first US decision rejecting a fair use defense for AI training. Ross ceased operations after the suit.
Output Generation Failure
That is bad information handed to a human who then acts on it. Hallucinations, biased output, defamatory output, confidential data surfaced. Deloitte Australia sits here, having partially refunded roughly A$440,000 to the Australian government after a report contained fabricated citations, experts, and a legal quotation.
Automated Decision Failure
Thisis the agentic version, where the AI decides rather than advises. Moffatt v. Air Canada, where a chatbot invented a bereavement refund, and the airline was held to it. Estate of Lokken v. UnitedHealth, alleging an algorithm drove wrongful denials of post-acute care. Mobley v. Workday on algorithmic age discrimination in hiring.
AI Physical Perils
This extends that into bodily injury and property damage. Sensing failures, autonomous action failures, critical infrastructure misdirection, product spoilage. The examples are expensive. A Florida jury found Tesla 33% liable in the first US autopilot death verdict, awarding $243m. Cruise paid between $8m and $12m after a robotaxi struck and dragged a pedestrian in San Francisco.
Adversarial Exploitation
This is AI as a weapon. The Arup deepfake belongs here, where a finance employee joined a video call populated entirely by synthetic colleagues and authorized fifteen transfers totaling around $25.6m.
Supply Chain and Dependency Failure
That is the systemic family. Foundation model compromise, connector flaws, model deprecation, inference infrastructure failure. Impacts here can hit every user of a given model simultaneously.
Why AI Risk Is Not Just Cyber Risk
CyberCube’s central claim is that treating AI as an extension of cyber will fail.
John Anderson, its director of product management, frames the error by analogy. Carriers that dismiss the shift, he argues, are attempting the modern equivalent of “those who shrug off this transformation and try the 21st century equivalent of treating all transportation risk as homogeneous will be in for a rude surprise.” Nobody prices a cargo ship and a delivery van off the same schedule.
The mechanism is precise. Cyber coverage definitions turn on malicious versus accidental acts. AI erases that line. The report argues that whether an agent breaches a system because it was instructed to or because its guardrails were insufficient does not change the fact of the breach. An AI can cause harm through hallucination or flawed output while functioning exactly as designed, with no attacker anywhere in the chain.
That has a claims consequence. Where a company deploys AI in a way that harms customers or third parties, casualty coverages may respond. Where the same deployment harms only the company itself, it may find no first-party cover to fund its recovery.
The distinction is not theoretical. Gambit Security documented an AI knocking a firewall offline at an Australian energy utility in June while assisting an intrusion. The operator wanted access. Nobody instructed the outage. That incident sits squarely inside CyberCube’s third and fourth families, and it happened before the taxonomy existed to name it.
The Data Problem Underwriters Cannot Solve With A Questionnaire
The report’s sharpest passage runs three paragraphs on page seven, and it should worry anyone selling external scanning as an underwriting input.
An outside-in telemetry scan can establish that a company uses Claude. It cannot establish what the company uses Claude for. CyberCube then lists what actually matters: how widely AI is deployed inside the organization, which connectors are permitted, whether a third party built the workflows, what governance exists, whether observed behavior matches that governance, and whether AI complements labor or replaces it.
Questionnaires capture some of this. CyberCube’s judgment is that point-in-time responses will not reflect the pace of change, and that even well-intentioned answers are likely to be wrong or incomplete. Its conclusion is that assessing AI exposure will require frequent inside-out observation, with the insured’s participation and consent.
That lands on a market currently moving the other way. Marsh and Resilience launched a program across Asia yesterday built on continuous external scanning that requires no software installation and no internal access. The frictionless design is the selling point. CyberCube has just published, independently, why outside-in visibility will not answer the AI questions underwriters need answered.
It also matches what Jessica Newman argued on this publication’s podcast in March: that the market must move from asking whether a control exists to demanding evidence of how it performs.
The Silent Cyber Playbook, Running Again
CyberCube expects the industry to handle AI the way it handled non-affirmative cyber between 2018 and 2020, and sets out three moves.
Carriers will exclude AI risk where they do not believe it belongs or cannot price it, typically in standard property and casualty lines. They will affirm it where they think it belongs, possibly subject to sublimits, typically in cyber and specialty. And they will weigh standalone AI policies for exposures that are genuinely new.
All three are happening at once, which is what made silent cyber expensive the first time.
One observation from CyberCube’s client conversations deserves attention. Cyber teams are currently fielding AI questions for their organizations across every line of business. The report calls that an understandable starting point and not a viable long-term solution. AI represents too large a transformation, it argues, for all the coverage to sit in one place. Munich Re reached a similar conclusion on where agentic exposure surfaces across lines.
Get The Cyber Insurance News Podcast
Agentic AI Cyber Insurance Risks.
What The Report Does Not Do
The title promises quantification. The report does not quantify.
There are no frequencies, no severities, no modeled losses and no probable maximum loss figures. What exists is a taxonomy, a coverage grid and a supply chain diagram. Jon Laux, CyberCube’s VP of product and analytics, describes it as the beginning of a journey and a foundation others can build on, which is an honest framing. Readers expecting numbers should know there are none yet.
The commercial context is also worth stating. CyberCube sells cyber risk analytics. A framework establishing AI as a multi-line problem enlarges the territory its models can address. That does not make the analysis wrong. It does explain why an analytics firm published a taxonomy rather than a model, and why the firm that forecast a year of AI disillusionment in January is now building the scaffolding for AI catastrophe modeling.
The blank grid remains the thing to take away. Six families, eleven policy types, sixty-six squares. Most carriers do not currently know what belongs in them. The last time the market sat here, Lloyd’s mandated clarity. The rewording still took years.
FAQ – AI Insurance Risk
What are CyberCube’s six AI event families?
Media, Regulatory and Protected Information; Output Generation Failure; Automated Decision Failure; AI Physical Perils; Adversarial Exploitation; and Supply Chain and Dependency Failure. The first four are novel to AI. The last three overlap with existing cyber and crime exposures.
What is the I2T2 framework?
Four dimensions through which AI affects insurance risk: Information, Intelligence, Tactics and Technology Stack. CyberCube built its six event families across these four dimensions to show where AI-driven losses are likely to land across policy types.
Why does CyberCube say AI risk is not just cyber risk?
Because AI can cause harm while working exactly as designed, with no malicious actor involved. Cyber coverage definitions distinguish malicious from accidental acts. An agent that breaches a system through poor guardrails rather than instruction blurs that line.
What is silent AI?
Unpriced AI exposure sitting inside policies that never contemplated it. CyberCube expects carriers to repeat the non-affirmative cyber process of 2018 to 2020, excluding AI where they cannot price it, affirming it where they believe it belongs, and considering standalone AI cover.
Does the report quantify AI losses?
No. Despite the title, it contains no frequencies, severities or modelled loss figures. It provides a taxonomy, a coverage mapping grid and a supply chain overview. CyberCube describes it as a foundation others can build on.
Related Cyber Insurance News Posts
- Marsh And Resilience Bundle Threat Hunting Into Asia Cyber Insurance. China Is Excluded.
- CyberCube Touts Cyber Insurance Tool for Brokers(Opens in a new browser tab)
- Silent Push 6.0 Gives Cyber Underwriters Sharper Threat Intelligence(Opens in a new browser tab)
- Urgent Wake-Up Call: 6 Shocking Stats About Family Office Cybersecurity in 2024(Opens in a new browser tab)
- Family Office Cybersecurity: Deloitte Finds Most Family Firms Hit By Cyberattacks(Opens in a new browser tab)