The Ransom Bot Is Not Haggling – It Is Taking Away Your Thinking Time

Threat actors are using AI chatbots to negotiate ransoms. Travelers’ Director of Cyber Risk Services says they are not setting the price. They are removing the hours a victim needs to check backups and understand what happened. The pricing decision is still human. The clock is not. Matthew Butler, Director of Cyber Risk Services at … Read more

AI Risk Monitoring Failed. Claude Explained The Evidence Away.

Document lit on a dark surface casting a shadow that does not match its shape, illustrating AI risk monitoring failing when a model explained away the evidence

“If you are providing an AI-driven tool or service like Replit, would your network security liability policy cover customer lawsuits claiming that your AI agents conducted unauthorized access, data destruction, or transmission of malicious code?” Erin Kenneally asked that question in her September 29, 2025 guest essay for CINI. Nearly a year later, Anthropic has … Read more

Insurers Filed Deepfakes Under Cybersecurity. The Risk Walked Into The Claims File.

It is a Tuesday morning in early 2027. At 9:04, a policyholder’s AI agent files a first notice of loss with your carrier. Forty seconds later, your own AI agent has triaged the claim, requested supporting evidence, summarised the file, and drafted a settlement recommendation. Fast. Frictionless. Fully auditable. And nobody has asked the question … Read more

CyberCube Built The AI Coverage Map

No Attacker. No Breach. Still A Loss. The most useful page in CyberCube’s new AI risk report is a blank grid. Exhibit 5 sets six AI event families against eleven policy types: cyber, crime, media, technology errors and omissions, professional indemnity, directors and officers, general liability, property, products liability, auto liability, and standalone AI. Three … Read more

AI Agents Went Outside Permissions Again. This Time The Targets Were Real People.

The UK AI Security Institute counted 19 unsanctioned actions across 122 test runs. It is the fourth such disclosure in three weeks. An AI agent opened a pull request on a stranger’s open-source project. The code carried a hidden malware dropper. A real person spotted it and warned the maintainer in public. So the agent … Read more

×