AI has moved past the pilot stage. It's drafting code, handling customer service, and increasingly making decisions that used to require a person. That shift changes the risk conversation for every business that uses it, and for every insurer that covers them.
Some organizations are still testing AI cautiously, using it for internal drafts or simple customer queries. Others have already handed it real operational authority, letting it act, decide, and interact directly with customers and systems. That gap in maturity means the exposure looks different from one business to the next, which is part of what makes this risk hard to underwrite with a single, uniform approach.
CyberCube's new report, Machine State of Mind: Creating a Framework for Quantifying AI-Driven Insurance Risk, sets out that framework. Here's the short version.
It's tempting to treat AI as an extension of cyber risk. The two share real similarities: single points of failure, human error, and threats that get faster and cheaper as AI improves.
But AI introduces something cyber risk doesn't usually have to account for. It can cause real harm through hallucination or flawed output even when the system is working exactly as designed. No malicious actor required.
That distinction matters. It's why the report argues AI risk deserves its own framework, not a footnote in the cyber one.
To make sense of where AI-driven loss shows up, CyberCube built a framework called I2T2. It organizes AI risk across four dimensions:
From these four dimensions, the report identifies six event families that span nearly every line of property-casualty insurance: Cyber, Tech E&O, professional liability, general liability, product liability, D&O, crime, media, and property.
The point isn't that every business needs to worry about all six. It's that AI risk doesn't sit neatly inside one policy, and treating it that way creates blind spots. This structure is also the starting point for quantifying AI risk: before insurers can size potential losses, they need a shared way of categorizing where those losses come from.
Cyber teams are usually the first to field AI-related questions inside an organization. That makes sense given AI's technical nature, but it's not where the full exposure lives. A single policy, whether standalone cyber or standalone AI, isn't built to capture how AI is reshaping professional indemnity, product liability, or media exposure all at once.
Consider a few real examples the report walks through:
None of these require a hacker. They require an organization using AI, and a risk landscape that hasn't caught up yet.
The report draws a direct comparison to how the industry handled "silent cyber" between 2018 and 2020. AI risk is likely to follow a similar path:
Different carriers will land in different places, depending on their risk appetite, technical capabilities, and existing policy wordings. That's expected. What matters is that each one makes a deliberate decision instead of discovering the answer after a claim comes in.
The report also points to a related, forward-looking question: what happens when a business can no longer access the AI it has come to depend on. As AI takes on more operational responsibility, a provider outage, a suspended model, or a sudden change in access can disrupt a business the same way a cyber incident can. That dependency risk is closely related to the exposures covered here, and it's worth understanding as its own category.
Every major wave of technology has forced insurance to catch up: the automobile, the airplane, the internet. Each looked, at first glance, like a variation on something familiar. Each turned out to carry its own distinct risks that demanded their own thinking.
AI is no different. It shares real characteristics with the risks the industry already understands. But treating it as simply an extension of those risks means missing what makes it genuinely new, and where the losses are actually going to land.
This is a brief overview of CyberCube's full report, which goes into detail on all six AI event families, real-world case examples, and a practical coverage-mapping tool for insurers navigating this shift. [Read the full report → Machine State of Mind: Creating a Framework for Quantifying AI-Driven Insurance Risk]
Join CyberCube's experts in our Beyond Cyber: Understanding AI Exposures Across Insurance Lines Webinar on Thursday, September 17, 2026, 4:00 PM BST | 11:00 AM EDT where they will cover the types of AI-driven incidents (re)insurers should be preparing for, the coverage triggers involved, and what it means for underwriting and risk management.