The rapid adoption of artificial intelligence (AI) by investment managers and financial services firms is prompting insurers to rethink how cyber risks are assessed, priced and covered, as autonomous systems and AI-generated errors create potential gaps in traditional insurance policies.
According to a recent analysis by ACA Group, AI is increasingly being used across the investment management industry to automate workflows, summarise research, monitor threats and strengthen cybersecurity. However, the growing deployment of the technology is also introducing new risks for businesses and insurers.
The report said cyber insurers were responding to the changing risk landscape in different ways, with some tightening policy language and introducing AI-related exclusions, while others were offering incentives to organisations that use AI to strengthen their cybersecurity defences.
It said the key question for companies seeking cyber insurance was no longer simply whether AI was covered, but which AI applications were covered, under which policy and subject to what conditions.
ACA Group noted that traditional cyber policies were generally designed around events such as unauthorised access, data compromise, system intrusion and business interruption.
This creates uncertainty when an AI system operated by an insured company causes a loss without a conventional cyberattack.
For instance, an autonomous AI system could modify a database, delete records or trigger an unauthorised transaction without an external attacker gaining access to the system.
According to the report, such incidents may not fit neatly within traditional cyber insurance policies because the loss does not necessarily result from hacking, data theft or another conventional cyber event.
The challenge is particularly relevant to the growing use of agentic AI, which refers to systems capable of making decisions and executing tasks with limited or no human intervention.
Unlike AI tools that simply generate recommendations or content, agentic systems can perform actions within business processes, potentially increasing both their usefulness and the scale of losses when they operate outside their intended boundaries.
ACA Group said insurers were therefore increasingly assessing how organisations govern and control their AI systems when underwriting cyber policies.
The report identified AI inventories, documented risk assessments, adversarial testing or red-teaming, and human oversight as factors that could influence an organisation’s position during insurance underwriting and renewal.
It noted that firms able to demonstrate effective AI governance could be better positioned when negotiating cyber insurance coverage, avoiding unnecessary exclusions or seeking additional policy endorsements.
The development is also creating a distinction between AI used as a source of risk and AI deployed as a defensive tool.
According to the report, insurers are increasingly recognising the value of AI-powered cybersecurity tools that can detect threats, identify suspicious activity and strengthen an organisation’s overall cyber defences.
ACA Group cited industry research showing that some organisations have received premium discounts or credits for deploying AI-based security technologies, particularly when combined with other security measures such as phishing-resistant multi-factor authentication and endpoint detection and response systems.
The report therefore argues that insurers are increasingly viewing AI through two different lenses. Uncontrolled or poorly governed AI can increase an organisation’s exposure to losses, while well-managed AI used for cybersecurity can strengthen its risk profile.
The changing landscape could have implications for financial institutions and other businesses in markets such as Nigeria as the adoption of AI expands across banking, investment management, insurance and other financial services.
For insurers, the challenge is how to price risks associated with technologies whose behaviour can be difficult to predict and whose actions may not always be easily traced to a specific human decision.
ACA Group said this uncertainty was already affecting conversations between insurers and policyholders, particularly during cyber insurance renewals.
It advised organisations to maintain an up-to-date inventory of AI tools and models, conduct risk assessments before deploying new systems, test AI applications that can modify or act on production data and establish clear points of human oversight.
The report stressed that strong AI governance would not automatically guarantee coverage for every AI-related loss, particularly where an autonomous system causes damage without a conventional cyber incident.
However, it said documented controls could improve an organisation’s position with insurers, support requests for additional coverage and make the handling of claims easier if an incident occurs.





