Skip to content

Machine State of Mind: What AI Actually Means for Insurance Risk

Explore how AI risk diverges from traditional cyber risk, uncovering new exposures and the need for a tailored insurance framework in CyberCube's latest report.

  • 4 Minute Read

AI has moved past the pilot stage. It's drafting code, handling customer service, and increasingly making decisions that used to require a person. That shift changes the risk conversation for every business that uses it, and for every insurer that covers them.

Some organizations are still testing AI cautiously, using it for internal drafts or simple customer queries. Others have already handed it real operational authority, letting it act, decide, and interact directly with customers and systems. That gap in maturity means the exposure looks different from one business to the next, which is part of what makes this risk hard to underwrite with a single, uniform approach.

CyberCube's new report, Machine State of Mind: Creating a Framework for Quantifying AI-Driven Insurance Risk, sets out that framework. Here's the short version.

AI risk isn't just cyber risk with a new label

It's tempting to treat AI as an extension of cyber risk. The two share real similarities: single points of failure, human error, and threats that get faster and cheaper as AI improves.

But AI introduces something cyber risk doesn't usually have to account for. It can cause real harm through hallucination or flawed output even when the system is working exactly as designed. No malicious actor required.

That distinction matters. It's why the report argues AI risk deserves its own framework, not a footnote in the cyber one.

A framework for where AI risk actually lands: I2T2

To make sense of where AI-driven loss shows up, CyberCube built a framework called I2T2. It organizes AI risk across four dimensions:

  • Information — where the AI's design itself creates legal exposure, such as copyright and IP disputes
  • Intelligence — where AI produces a bad output or makes a bad decision
  • Tactics — where AI becomes a tool for exploiting people or systems
  • Technology Stack — where the AI infrastructure itself becomes a single point of failure

From these four dimensions, the report identifies six event families that span nearly every line of property-casualty insurance: Cyber, Tech E&O, professional liability, general liability, product liability, D&O, crime, media, and property.

The point isn't that every business needs to worry about all six. It's that AI risk doesn't sit neatly inside one policy, and treating it that way creates blind spots. This structure is also the starting point for quantifying AI risk: before insurers can size potential losses, they need a shared way of categorizing where those losses come from.

Why this matters beyond the cyber team

Cyber teams are usually the first to field AI-related questions inside an organization. That makes sense given AI's technical nature, but it's not where the full exposure lives. A single policy, whether standalone cyber or standalone AI, isn't built to capture how AI is reshaping professional indemnity, product liability, or media exposure all at once.

Consider a few real examples the report walks through:

  • A generative AI product reproduces copyrighted content, creating IP and media liability exposure that has nothing to do with a network breach
  • An AI chatbot promises a customer a refund the company never intended to offer, and the company gets held liable for honoring it
  • Professionals rely on AI-generated output that turns out to be fabricated, and the resulting error becomes a professional liability claim
  • Scammers use AI-generated deepfakes to impersonate a company's own executives on a video call, convincing an employee to authorize millions in fraudulent transfers

None of these require a hacker. They require an organization using AI, and a risk landscape that hasn't caught up yet.

What insurers should expect

The report draws a direct comparison to how the industry handled "silent cyber" between 2018 and 2020. AI risk is likely to follow a similar path:

  1. Insurers exclude AI risk where it doesn't clearly belong and can't be underwritten
  2. Insurers affirm AI coverage where it does belong, often with sublimits
  3. Insurers evaluate standalone AI products for the exposures that don't fit anywhere else

Different carriers will land in different places, depending on their risk appetite, technical capabilities, and existing policy wordings. That's expected. What matters is that each one makes a deliberate decision instead of discovering the answer after a claim comes in.

The report also points to a related, forward-looking question: what happens when a business can no longer access the AI it has come to depend on. As AI takes on more operational responsibility, a provider outage, a suspended model, or a sudden change in access can disrupt a business the same way a cyber incident can. That dependency risk is closely related to the exposures covered here, and it's worth understanding as its own category.

The bigger picture

Every major wave of technology has forced insurance to catch up: the automobile, the airplane, the internet. Each looked, at first glance, like a variation on something familiar. Each turned out to carry its own distinct risks that demanded their own thinking.

AI is no different. It shares real characteristics with the risks the industry already understands. But treating it as simply an extension of those risks means missing what makes it genuinely new, and where the losses are actually going to land.


This is a brief overview of CyberCube's full report, which goes into detail on all six AI event families, real-world case examples, and a practical coverage-mapping tool for insurers navigating this shift. [Read the full report → Machine State of Mind: Creating a Framework for Quantifying AI-Driven Insurance Risk]

Join CyberCube's experts in our Beyond Cyber: Understanding AI Exposures Across Insurance Lines Webinar on Thursday, September 17, 2026, 4:00 PM BST | 11:00 AM EDT where they will cover the types of AI-driven incidents (re)insurers should be preparing for, the coverage triggers involved, and what it means for underwriting and risk management.