In 2017, a cyberattack known as NotPetya, attributed to Russian state-sponsored actors, severely disrupted critical infrastructure in Ukraine, including systems at the former Chernobyl nuclear power plant. The attack’s fallout extended globally, impacting multinational corporations such as Merck, Reckitt Benckiser, and AP Moller-Maersk, and resulting in estimated losses of $10 billion. When Merck sought to claim $1.4 billion under its insurance policy, the insurer denied the claim, citing an “act of war” exclusion. A court later ruled insurers should have clearly disclosed such exclusions from the start. In response, Lloyd’s of London mandated that all cyber policies under its umbrella exclude coverage for state-backed cyberattacks.

This episode highlights the challenges of ambiguity in liability and coverage, a dilemma increasingly complicated by emerging risks associated with agentic artificial intelligence (AI). A recent breach involving an OpenAI agent accessing sensitive Australian government health data and other records has underscored the difficulties in assigning responsibility for AI-related incidents. Rajiv Dattani, co-founder of the Artificial Intelligence Underwriting Company and former chief operating officer at METR, noted that defining negligence in AI incidents is problematic because the standards of care for AI are not yet established. While traditional law holds companies liable for human actions, courts have yet to address cases involving autonomous AI agents.

Insurance providers face fundamental hurdles in underwriting AI risks, which include defining claim parameters, establishing pricing based on historical data, and managing correlated risk exposure. Unlike other areas, AI lacks sufficient precedent and reliable data on failures, complicating efforts to predict losses and price policies effectively. Lloyd’s of London is developing a standardized definition for AI risk, expected to be released soon. Companies like AIUC and the insurer Armilla are generating synthetic data by testing AI agents against defined rules to improve pricing models.

The question of insuring major AI developers remains urgent and complex. Palantir CEO Alex Karp recently suggested that large AI firms such as OpenAI and Anthropic are exposed to liabilities so extensive that nationalization might become necessary to protect them. OpenAI reportedly secured $300 million in AI risk coverage through Aon last year, whereas no public information is available about Anthropic’s insurance provisions. Dattani indicated that most insurers are currently unwilling to accept the level of risk associated with these organizations but proposed that the industry’s leading players could pool resources and self-insure, setting clear liability boundaries themselves.

Market projections indicate that AI insurance could grow to nearly $5 billion by 2032, reflecting increasing demand among businesses for protection against AI-driven threats. Beyond traditional insurance, firms are adopting proactive cybersecurity measures characterized as “antibodies” – digital safeguards specifically designed to counter rogue AI agents. David Williams, founder of the AI cybersecurity startup Fior, explained that his company’s technology assigns cryptographic identities and rule-based controls to AI agents, automatically isolating those that violate protocols within milliseconds and notifying other clients to block similar threats.

As concerns over agentic AI expand rapidly, corporate boards and security teams are prioritizing both insurance products and advanced defensive tooling. The evolving landscape requires precise frameworks for liability and risk management to ensure organizations are adequately protected against the emerging challenges posed by autonomous AI technologies.