By Ross Risby, David Kwok and Julie Wong
|
Published 23 September 2026
The accelerating role of artificial intelligence in organisational decision making is redefining exposure, from fraud to compliance accountability. As AI-related risks evolve, the insurance market is confronting an important question: are existing insurance policies keeping pace with AI-driven threats?
The immediate issue for insurers and policyholders is not whether AI-related losses are insurable, but whether existing policy wordings already respond to those losses in the way the parties intended. AI-related exposures may already fall within the scope of existing insurance policies, despite the absence of express AI-related provisions.
Whilst some global insurers have reportedly begun to introduce express provisions addressing AI-related claims, the position in Hong Kong appears to be unchanged. Therefore, a more immediate question may be whether AI-related risk is already covered under existing policy wordings in the absence of express AI provisions.
"Silent AI" risks - the next "silent cyber"?
A decade ago, "silent cyber" required the market to address unpriced and unintended cyber coverage contained in traditional insurance policies. In the absence of express cyber-related provisions, cyber losses were neither clearly covered nor obviously excluded under those policies.
Similar concerns are now arising in relation to AI-related exposures. In their latest AI Adoption research, Gallagher found that one in five insurance professionals surveyed say their insureds have already experienced losses linked to AI risk.
Most current insurance policies were not drafted with AI liability in mind. In the absence of direct exclusions or explicit cover, policies remain silent leaving insurers and policyholders exposed to uncertainty and potential disputes. The gap applies to several classes of insurance, including cyber, D&O, professional indemnity, employment, and product liability.
When it comes to insurance coverage, the answer to whether a particular loss is covered is often “it depends”. The precise wording of the policy, the nature of the alleged loss and the role played by the AI system will, therefore, be relevant factors in coverage decisions.
Determining fault where AI is involved may be more difficult than identifying the immediate cause of a loss. Responsibility may be shared across various participants, including developers, deployers, users and third-party service providers, each of whom may have contributed to the design, training, governance, oversight or use of the AI system. Legal exposure is therefore likely to develop faster than regulation and insurance wordings can respond, leaving courts to determine how responsibility should be allocated in practice. That uncertainty reinforces the need to test how existing cover, particularly cyber cover, responds when AI is part of the factual matrix.
AI risk is not cyber risk
Whilst many insurers are reviewing various types of policy to consider the overall exposure to AI, cyber policies are likely to provide the first real test of existing policy wordings in the silent AI debate.
The recent OpenAI Hugging Face breach is the first widely reported case of an AI agent autonomously compromising a real company end to end. Security experts call it a containment failure. OpenAI called it an "unprecedented cyber incident". However, what was once considered a thought experiment has stopped being hypothetical.
This incident illustrates a very real AI challenge, with autonomous AI models acting at machine speed, operating in parallel and at significant scale to identify and exploit vulnerabilities through brute force. Although actions during the attack were described as carried out in a way that no human would, it was nonetheless effective by its sheer volume, simultaneous action and speed of iteration. Whether viewed as a cybersecurity incident; an AI failure or a sign of an impending catastrophe, the incident highlights how AI-driven losses do not fit neatly within existing insurance policies.
As insurers and policyholders continue to review the cover available to adapt to the ever changing AI landscape, this raises a number of practical coverage questions including:
- Do cyber policies contemplate acts performed by autonomous software with or without human intervention?
- Does an AI system fall within the definitions of computer system or authorised user?
- How should causation be analysed where the immediate act was performed by an AI model without being designed or instructed to do so by any human actor?
- Are losses resulting from remediation and system improvements related to AI recoverable, or are they betterment costs?
AI is increasingly being used by both threat actors and organisations themselves. Threat actors are deploying AI to enhance phishing campaigns, identify vulnerabilities and automate attacks at scale, while organisations are embedding AI systems into core business processes and technology systems. The use of AI may introduce new operational and security vulnerabilities, creating losses that have not been contemplated by existing policy wordings. In many cases, cyber policies may still respond because the underlying loss remains a security breach, data breach, or network security event. However, AI introduces new factual scenarios that may test the boundaries of traditional cyber wordings and give rise to disputes regarding characterisation, causation, and the application of exclusions.
To date, the Hong Kong market has not yet seen widespread adoption of AI-specific exclusions or affirmative AI wordings in insurance policies. However, as AI-related exposures become more widespread, both insureds and insurers are likely to seek greater certainty as to the risks intended to be covered and excluded.
Until we see greater clarity, questions concerning causation, responsibility and the application of existing policy wordings are likely to remain at the core of coverage disputes. Dedicated AI policies or tailored AI provisions may ultimately be required to reduce uncertainty, creating opportunities for insurers willing to develop products that address these evolving risks. Whether through dedicated AI products, bespoke endorsements or revised exclusions, the market is unlikely to tolerate 'silent AI' uncertainty indefinitely.