CyberCube - Cyber Insurance Analytics

When the Model Goes Dark: AI Dependency and Cyber Resilience

Written by Jon Choi | Sep 21, 2026, 4:48:41 PM

For the past two years, many organizations have treated large language models as productivity tools. They have been used to write emails, summarize documents, draft code, analyze data, and accelerate knowledge work. In that framing, the central risk question has often been: Is the model accurate?

That question is no longer sufficient.

As agentic AI becomes embedded in enterprise workflows, AI systems will increasingly become part of the operational fabric of the business. Agents will write and deploy code, triage security alerts, handle customer service requests, prepare financial analyses, monitor supply chains, support underwriting, coordinate procurement, and manage increasingly complex chains of action across software systems and knowledge work. In this world, AI will not simply advise humans. It will participate in the execution of business processes.

That creates a new risk that (re)insurers will need to contemplate: AI dependency risk.

The issue is not only whether an AI model hallucinates, leaks sensitive information, or produces biased outputs. Those are important risks, and organizations should continue to manage them. But as AI systems become more autonomous and more deeply integrated into core operations, businesses will also need to ask a more fundamental resilience question: What happens if the primary AI provider fails, restricts access, compromises the service, raises prices prohibitively, or withdraws it?

For businesses, this is an enterprise resilience question. For cyber insurers, it is also becoming an important aspect of an insured's risk posture. If AI agents become embedded in revenue generation, software development, security operations, customer support, finance, or other critical functions, then the resilience of those AI-enabled processes will become part of the organization's broader cyber and technology risk profile.

Mythos and Fable 5 Suspended: A Glimpse of Future AI Dependency Risk

The recent launch and subsequent suspension of Anthropic's "Mythos-class" models offers an early illustration of this issue. Anthropic announced Claude Mythos 5 to select participants of its Project Glasswing and Claude Fable 5 to the general public on June 9, 2026. The company described Fable 5 as its most capable generally available model, with particular strength in long-running agentic tasks, software engineering, knowledge work, vision, and scientific research.

Just three days later, Anthropic posted an update suspending access to both models as a result of the U.S. government issuing an export-control directive. The practical effect was that Anthropic had to disable the models for all customers to ensure compliance. Anthropic later restored access to Claude Fable 5 nearly three weeks later on July 1, 2026, following the lifting of export controls.

By the time access was suspended, it is unlikely these Mythos-class models had already been integrated into any organizations' business-critical processes within the three days they were available. But this illustrates an important point: access to frontier AI capabilities can be interrupted by causes outside a customer's control. Those causes may include cyberattacks, technical failures, emergency safety actions, contractual disputes, regulatory intervention, geopolitical restrictions, or government orders.

For companies experimenting with AI, that may be inconvenient. A temporary loss of access to an AI writing assistant may reduce productivity. But a temporary loss of access to an AI agent that triages security alerts, supports customer onboarding, coordinates logistics, or generates production code could affect service levels, revenue, security posture, and contractual obligations.

AI Resilience Is Cyber Resilience

Cyber risk management has matured substantially over the past two decades. Most sophisticated organizations no longer assume that every cyber incident can be prevented. Instead, they invest in resilience: the ability to withstand, respond to, and recover from disruption. That is why cyber risk management today emphasizes controls such as backups, recovery time objectives, recovery point objectives, patch management, identity and access management, zero trust architecture, network segmentation, incident response planning, endpoint detection and response, and third-party risk management.

The question has shifted: not can we stop every adverse event? but rather can the organization continue to operate or recover quickly when something goes wrong?

AI risk management will need to undergo a similar transition.

Today, many AI governance programs focus on model selection, acceptable use, privacy, bias, explainability, and human review. Those are necessary foundations. But as AI agents become operational dependencies, organizations will need to extend AI governance into AI operational resilience. In simple terms, this means business continuity planning for the AI era.

In practical terms, businesses will need to ask:

  • What are the backups for AI-enabled workflows?
  • What is the recovery time objective if the primary model provider becomes unavailable?
  • What is the fallback if an AI agent can no longer access a critical tool, data source, or API?
  • Which AI agents have privileged access to systems, data, or decision rights?
  • How would the company detect, contain, and recover from an AI-specific incident?

In other words, organizations should not ask only whether their AI systems are powerful, accurate, or safe. They should ask whether their AI-enabled operations are recoverable.

AI Dependency Risk Is Broader Than Model Risk

AI dependency risk has several dimensions. Here, we describe some of these dimensions though this is not meant to be an exhaustive list.

The first is provider concentration risk. Many organizations may standardize on one frontier AI provider, creating a single point of dependency. If that provider suffers an outage, withdraws a model, changes its access policy, is subject to government restriction, or materially changes pricing, the customer's AI-enabled workflows may be affected.

The second is model concentration risk. Even when a company uses multiple applications, those applications may rely on the same underlying model family. A business might believe it has diversified because AI is embedded across several vendors, only to discover that those vendors are all dependent on the same frontier model providers.

The third is visibility risk. AI may become embedded in processes that were previously distributed across teams, tools, and human judgment, without management knowing which business functions would degrade if the AI layer became unavailable.

The fourth is execution dependency risk. AI systems depend and act on cloud platforms, identity providers, API gateways, vector databases, orchestration frameworks, code repositories, data pipelines, and monitoring tools. A failure in any one of these layers can interrupt the AI-enabled business process.

The fifth is agentic autonomy risk. The more authority an AI agent has, the larger the potential impact when something goes wrong. A chatbot that drafts a response for human review creates one level of exposure. An agent that can access customer records, write code, open tickets, trigger payments, change configurations, or interact with production systems creates a different exposure.

The sixth is policy and sovereignty risk. AI access may be shaped by export controls, data localization requirements, national security concerns, privacy law, intellectual property disputes, or sector-specific regulation. A model that is available today may not be available tomorrow in the same way.

For underwriters, the common theme is not simply "AI use." It is operational dependence. Two companies may both use AI extensively, but one may use it for non-critical productivity tasks while the other may rely on it to execute business-critical workflows. Those are very different risk profiles. Understanding the level of dependence which business-critical workflows have on AI becomes the pertinent question.

A Practical AI Resiliency Framework

As AI becomes more critical to the enterprise operating model, AI resiliency will need to form part of enterprise risk management. This will help organizations avoid building brittle, opaque, and highly concentrated dependencies around systems that may become business-critical. Such a framework could include several components.

1. Map AI dependencies across the enterprise. Organizations should maintain an inventory of where AI is used, which models and vendors support each use case, what data those systems access, and which business processes depend on them. This inventory should distinguish between low-criticality and high-criticality use cases. The key questions are: which AI-enabled workflows matter most, and what would happen if they failed?

For instance, an AI tool used to summarize meeting notes is less critical than AI agents used to triage production incidents, support cyber defense, generate code, support customer onboarding, or produce regulated communications.

2. Define AI recovery time objectives. The recovery objective should reflect business impact, not technical convenience. For each critical AI-enabled workflow, organizations should define how long they can operate without the primary model, vendor, agent framework, or AI platform. Some workflows may tolerate multi-day degradation. Others may require near-real-time continuity. A security operations team relying on AI-assisted alert triage may have a very different tolerance from a marketing team using AI for content ideation.

3. Build model and provider redundancy. Organizations should consider where redundancy is appropriate — maintaining relationships with more than one frontier AI provider, testing fallback models including closed and open weight models, or designing workflows so they can be moved from one model to another with minimal reengineering. These model fallbacks should be tested as part of a robust resilience strategy.

4. Design human fallback procedures. For critical workflows, organizations should define what reduced-service manual operation looks like. Which procedures need to be documented before the AI system fails? Which teams or staff have the expertise to take over and how effective are those manual processes? What processes can be paused and which decisions deferred? Which must continue?

5. Develop AI incident response playbooks. Playbooks should address model outage, provider suspension, prompt injection, data leakage, unsafe agent actions, erroneous automated decisions, and loss of access due to legal or regulatory action. The playbooks should be tested well before an incident ever occurs.

6. Run AI tabletop exercises. Organizations should test AI resilience before they need it.

A useful exercise might test what happens when the company's primary AI model or agent is unavailable for five business days, which workflows stop? Which degrade? Which contractual obligations are affected? These exercises will help organizations identify gaps in their AI incident response playbooks or critical AI implementations that were previously overlooked.

What This Means for Cyber Underwriting

For cyber insurers, the rise of agentic AI creates a new underwriting challenge. The question should not be limited to whether a company "uses AI." Instead, underwriters may need to understand how AI changes the insured's operational dependency profile, security posture, and business interruption exposure.

At the single-account level, underwriting questions could include:

  • Business Criticality: Which specific business processes depend on AI, and are these processes revenue-critical, security-critical, safety-critical, or customer-facing?
  • Provider Concentration: Is the insured dependent on a single primary AI provider, and have they formally tested fallback providers or manual procedures to ensure continuity?
  • Agentic Authority: What level of authority do AI agents possess, and do they have access to highly sensitive systems, such as production environments, payment processing, or customer records?
  • Resilience Planning: Does the company maintain AI-specific incident response playbooks and business continuity plans that include clear decision rights for events like model outages or agentic failures?
  • Governance and Vendor Management: Do contracts with AI vendors adequately address availability, liability, data usage, and termination rights to protect the organization from supply-chain disruptions?

These questions matter because AI can affect both frequency and severity. Poorly governed AI may increase the likelihood of operational errors and data leakage. Highly concentrated AI dependency may increase the severity of a provider outage, model suspension, or agentic failure.

Underwriters will want to be proportionate with breadth and depth of questions asked of insureds based on their size, complexity, and AI sophistication. But over time, answers to such questions may change how underwriters differentiate accounts. A company that has mapped its AI dependencies, tested fallback providers, limited agent privileges, and run AI resilience exercises should present a different risk profile from a peer that has embedded AI deeply into operations without understanding its dependencies or recovery options.

What This Means for Accumulation Risk

The same AI dependencies that matter at the individual account level may eventually matter at the portfolio level. Cyber insurers already monitor correlated exposure to cloud providers, widely used software, and managed service providers. AI may add another layer to that analysis. Many insureds could rely on the same small group of frontier AI providers, agentic platforms, or cloud-hosted AI services. Even a diversified book of business may contain hidden AI concentration risk.

For risk managers, the near-term priority is likely not to model every AI accumulation scenario in detail. It is to start collecting the right signals at the account level: which insureds depend on AI for critical operations, which providers and platforms they rely on, and whether they have credible resilience measures in place.

From Adoption to Resilience

The first phase of enterprise AI has been defined by adoption. The next phase will be defined by resilience.

As AI agents become embedded in critical operations, businesses will need to understand not only what AI can do, but what happens when it fails. They will need to map AI dependencies, test fallback options, govern agent permissions, develop AI incident response playbooks, and evaluate provider concentration with the same seriousness they apply to other critical technology dependencies.

For insurers, AI will create new questions at both the underwriting and portfolio levels. At the individual account level, AI adoption may alter business interruption exposure, security posture, third-party dependency, and governance maturity. At the portfolio level, common AI providers and agentic platforms may create new forms of accumulation risk.