Your clients’ policies haven’t caught up with AI attacks
When more than 100 technology companies sign the same document, including direct competitors who agree on almost nothing else, something has shifted in how that industry reads its own risk. On Aug. 27, OpenAI published an open letter titled a call for collective action on cyber defense. CNBC counted 116 signatories. Anthropic, Microsoft, Google, Amazon, CrowdStrike, Palo Alto Networks, Mastercard and Visa were among them.

Most of the coverage treated it as a technology story. For anyone who places cyber, professional liability or property coverage, it is something closer to a memo from the field. The best-informed companies in the world just told the market, in writing and with signatures attached, that the loss environment is about to change.
The operative sentence: In the coming months, AI-enabled cyberattacks will become far more widespread and sophisticated as models around the world become increasingly capable. Read that again with a renewal calendar in front of you.
What did the open letter actually say?
The letter warns that AI is making sophisticated attack capability cheaper and more available, that current security practices are not sufficient, and that hospitals, water utilities and power systems are exposed. It asks organizations to treat cyber defense as a leadership priority, asks governments to fund under-resourced essential services, and asks AI developers to put defensive tools in the hands of critical infrastructure operators.
What makes it unusual is the concession. Vendors do not typically co-sign a public statement that the security their customers already bought is insufficient for what's coming. This one does, and it does not soften the point with the usual language about an evolving threat landscape.
For an advisor, the useful part is not the recommendations. It's the admission underneath them.
Why does an AI warning matter to an insurance conversation?
It matters because underwriting depends on loss history, and AI is changing attack economics faster than loss history can accumulate. Actuaries price what they can model. When frequency and severity both start moving in a direction the data has never recorded, the rational carrier response is to narrow the language, not to raise the price.
We have already watched this play out once. Reporting from Wolfe Research and The Information documented carriers winning approval to strip artificial intelligence exposures out of standard liability forms, and the standardized commercial forms produced by the Insurance Services Office gave them a clean way to do it. That happened quietly, one endorsement and one renewal at a time.
There's no reason to assume cyber lines will behave differently. When a category of loss outruns the data, the coverage moves before the premium does. Your clients will discover this at renewal, in form changes they were not expecting, unless somebody walks them through it first.
How fast are AI-driven attacks actually moving?
Fast enough that human response time has stopped being a meaningful control. On Nov. 14, 2025, Anthropic disclosed what it described as the first reported AI-orchestrated cyber espionage campaign. A Chinese state-linked group it tracks as GTG-1002 targeted roughly 30 organizations and used Claude Code to execute 80% to 90% of the operation on its own. Human operators contributed a maximum of about 20 minutes of work at the key decision points.
Twenty minutes of human effort. Thirty targets. That is the number to carry into a client conversation, because it reframes what a security program is buying.
Most of what your commercial clients spend on cybersecurity funds is about noticing and responding: monitoring tools, alerting, a security operations team, an incident retainer. All of that is built on the assumption that a person will have time to make a decision. Against an adversary that runs itself, the assumption doesn't hold, and the loss that follows lands on a policy somebody underwrote.
What should advisors ask clients before the next renewal?
Ask what stops an attack, not what sees one. The distinction sounds academic until a claim is filed, and it is the single most useful question an advisor can put to a commercial client this year.
First, ask them to separate their security stack into two columns: controls that detect and alert, and controls that block execution outright. Most clients have never sorted it that way, and the exercise itself is revealing.
Second, ask what happens overnight. If an attack lands at 2 a.m. on a holiday weekend and nobody is watching the console for nine hours, what stands between the payload and the file server? For many mid-market clients, the honest answer is nothing.
Third, ask about AI on the inside of the business, not just outside it. Employees adopt tools without approval, software ships with AI features switched on by default, and code is increasingly machine-generated. Each of those widens the surface a carrier is asked to cover.
Fourth, read the endorsements. Exclusions arrive quietly at renewal, buried in form changes rather than announced. Clients deserve to hear in plain language what their policy no longer pays for.
How can a client improve its position with underwriters?
By proving it reduced the odds of a loss, not just the time to notice one. Insurability has always rewarded demonstrable risk reduction, and this is the year that standard gets applied to cyber with real teeth.
The organizations that come out of this cycle with coverage and a survivable premium will be the ones that can show an underwriter something concrete. Controls that stop malicious code at the moment of execution, without waiting for a human or a signature update. Documented evidence of what was blocked rather than what was investigated. A written answer to the overnight question.
That posture does two things at once. It genuinely lowers the probability of the claim, and it gives an underwriter something to price favorably at a moment when very little else in the file is priceable. Detection alone is no longer a differentiated story. Every applicant has it, and the letter's signatories just explained why it isn't enough.
The warning is the underwriting memo
There will not be a single announcement that AI has repriced cyber risk. Structural change in insurance never arrives that way. It shows up one endorsement at a time, and the clients who prepared look nothing like the clients who didn't.
The signatories were clear that the window for getting ahead of this is measured in months. Renewal cycles are measured in months too. That is not a coincidence worth ignoring.
The risk didn't wait for the policy language to catch up. It moved first. It always does.
© Entire contents copyright 2026 by InsuranceNewsNet.com Inc. All rights reserved. No part of this article may be reprinted without the expressed written consent from InsuranceNewsNet.com.
Brad LaPorte is chief marketing officer at Morphisec. Contact him at [email protected].


Gen X faces ‘pension envy’ as they head into retirement
A-Cap strikes back with lawsuit accusing SC regulators of sloppy process, leaking secrets
Advisor News
- House panel advances CLEAR Forms Act backed by IRI
- Modifying life insurance based on evolving needs
- Gen X faces ‘pension envy’ as they head into retirement
- Your client wants to cash out an annuity. Here’s what to consider
- How student loan debt impacts 401(k) balances
More Advisor NewsAnnuity News
- A-Cap strikes back with lawsuit accusing SC regulators of sloppy process, leaking secrets
- AM Best to Discuss Its Views on Private Credit Surge and Risks at 2026 NAIC/NIPR Insurance Summit
- OID recovers $260M in life insurance benefits
- NUNN BILLS TO COMBAT PAYMENT SCAMS, CUT FINANCIAL RED TAPE PASS FINANCIAL SERVICES COMMITTEE
- SS&C Black Diamond Expands Annuities & Insurance Marketplace with New Insurance Capabilities and Carriers
More Annuity NewsHealth/Employee Benefits News
Life Insurance News