GPT-6 Astra Asked Permission. An Automated Reply Said Use Your Best “Judgement.”

Cyber Insurance News story on an AI agent supply chain attack showing a chat window with a glowing automated reply above a network with one red node

The model asked before it acted. The reply came from a script. “Please proceed to the next step using your best [judgement].” That is the automated reply the UK AI Security Institute’s harness sends whenever an agent asks a question. OpenAI’s GPT-6 Astra sometimes read it as a yes. What followed, in simulation, was unsanctioned … Read more

Swiss Re: Extreme Cyber Accumulation Is Too Big For Private Capital

Cyber Insurance News story on cyber accumulation risk showing a glowing network with one red node spreading through its links

Swiss Re Institute read the risk disclosures of 91 Fortune-100 companies. Ninety-eight percent of them name cyber attacks as a risk to their business. No risk in the study appeared more often. With the London School of Economics, it compared filings from 2019 and 2026. Cyber attacks topped the list in 2026, up from 91% … Read more

The Machines Are Learning. Unfortunately, From Us.

We built AI on our own data, then got alarmed when it acted like us. An opinion on AI, agentic risk and who pays when the agent wanders off.

This essay originally appeared on “With Respect — Mostly,” Executive Editor Martin Hinton’s Substack, where he writes about a wide range of subjects, including cyber insurance and security. It has been adapted for Cyber Insurance News with additional reporting that ties it more directly to coverage we’ve done. Oh man. This was going to be … Read more

One AI Failure, Four Policies: AXA XL Names The Scenarios

Cyber Insurance News story on AI risk insurance showing one line of light splitting into four separate strands.

A carrier has put the question in writing. AI-related losses “may not fall neatly into one category of risk.” AXA XL and S-RM published Building Resilient AI on 23 September. The report names four loss scenarios that will test that sentence. A deepfake-enabled payment fraud. An AI-related data breach. A defective output causing third-party loss. … Read more

Recovery Took Twice As Long As Planned. Nobody Priced For That.

Three-quarters of organizations that suffered a material cyberattack and business interruption in the past year blew through their recovery time objective. On average, recovery took nearly twice as long as the objective they had set. That figure does not appear in Cohesity’s press release. It sits on page six of the full report, and it … Read more

×