The skill floor collapsed. The coverage didn’t follow.
Agentic attacks broke the link between skill and damage. That breaks one part of how we insure, and hands insurtech, cybersecurity, and the carriers themselves a problem worth solving.
Duncan Platt
Group CTO and Co-Founder
Audio edition
Listen to this article
In February 2026, someone in Addis Ababa broke into at least fourteen companies (opens in new tab). He was not a skilled hacker. Researchers at OALABS recovered his entire working directory, more than a thousand agent sessions, because he ran his tools on a server he didn’t own and never turned off the logging. The logs are the story.
He gave vague instructions. “Recon this.” The agents, Anthropic’s Claude Code and OpenAI’s Codex, filled in the rest: mapped exposed services, found the vulnerabilities, wrote the exploit code, validated access, harvested the data. For each company he got into, the agent wrote him a clean pentest report with the stolen data catalogued and a dollar estimate of what it was worth. Across all thousand-plus sessions, the models raised ten policy violations total. He got past them with one phrase, repeated: “authorized redteam exercise.”
The researchers’ own conclusion is the part to sit with. The attacker did not need to be an expert. He needed the right framing for his prompts.
A pattern, not a headline
This is not a one-off, and the most credible evidence comes from the model makers themselves. In August 2025, Anthropic published a threat report (opens in new tab) on an actor it tracked as GTG-2002, who used Claude Code to extort at least seventeen organisations (hospitals, emergency services, government agencies, religious groups) with ransom demands from $75,000 to over half a million dollars in Bitcoin. The same operator had the model draft the ransom notes, tuned for pressure. The same report documents someone with only basic coding skills selling AI-generated ransomware kits as a service.
Put those next to the Ethiopian case and the shape is clear. The expertise an attack used to require has moved into the tool. A person who could not have written a working exploit two years ago now directs an agent that writes it, tests it, and files a report. The link between how skilled an attacker is and how much damage they can do — the assumption every security model and every underwriter has quietly relied on — is gone.
The market is pricing this backwards
Here is where it gets strange. As the attacks get cheaper to run, cyber insurance is getting cheaper to buy.
The numbers are not subtle. AM Best reported that the first quarter of 2026 was the eighth straight quarter of price cuts (opens in new tab) in US cyber insurance, with the sharpest drops in the two most recent quarters. Cyber reinsurance rates fell about 32% at the January 2026 renewals; Gallagher Re called it historic softening (opens in new tab). And the softening ran into rising losses: third-party cyber claims climbed roughly 30% in 2025, and the industry loss ratio crossed 50% (opens in new tab) for the first time since the pandemic ransomware surge. Cyber still makes up well under 1% of global property and casualty premium, and the exposure it covers is growing faster than the market that covers it.
So exposure is climbing and price is falling. That gap is not a rounding error. It is the tension the rest of this piece is about.
One component of risk quietly stopped fitting
I want to be precise here, because the easy version of this argument is wrong. Traditional insurance is not going away. Most risk is still insurable the way it always was: fire, theft, most liability, most cyber. The pool-and-price model works, and it will keep working for the vast majority of what a business needs to cover.
What changed is narrower. A new component of risk has appeared inside businesses, the autonomous agent, and it does not behave like the risks insurance was built to absorb.
Insurance works by pooling risks that don’t move together. Your building and mine don’t burn down on the same night, so the pool holds. Agentic attacks break that assumption. One framing, one working technique, runs against thousands of targets at once, at machine speed, and the losses arrive together. Gallagher Re named this in its 2026 report Smart Systems, Blind Spots: because the whole AI ecosystem leans on a handful of foundation-model providers, a single flaw in one widely used model could trigger claims across thousands of unrelated policyholders at the same time. That is the accumulation problem reinsurers lose sleep over, and no amount of added capital fixes it. You cannot reinsure your way out of a tail that fires everywhere at once.
When ISO carved generative AI out of the standard commercial general liability form (opens in new tab) in January 2026 (endorsements CG 40 47 and CG 40 48, with a products-liability variant in CG 35 08), that was not the industry losing its nerve. ISO forms are the standard-language foundation for US commercial liability, so the change spreads fast. By April, Chubb, Travelers, Berkshire Hathaway, and W.R. Berkley (opens in new tab) had filed AI exclusions or their own proprietary versions, and state regulators approved more than 80% of the requests. Pricing actuaries recognised the move on sight: it repeats the silent-cyber problem the industry spent five years unwinding after 2018, when coverage nobody had priced turned up in claims nobody expected. Read the exclusions as a signal, not a retreat. A new component has been named, and the old instrument doesn’t fit it.
What the new instrument looks like
The interesting question is not who is excluding this risk. It is who is building the thing that fits it. The answer includes the biggest names in the industry, working the same direction as the startups.
The shape they are converging on inverts the old order. Legacy insurance is pure risk transfer: pool it, price it once off a questionnaire, pay when it breaks. That model dies against a correlated tail. The model that survives reduces the risk first and transfers only what’s left. Verify the system, monitor it continuously, enforce the controls that prevent the loss, then insure the residual.
Coalition (opens in new tab) is the proof this works at scale. The US carrier, one of the largest cyber insurers in the country and approaching a billion dollars in premium, calls its approach Active Insurance. Rather than underwrite a business once off a form, it continuously scans each policyholder’s internet-facing attack surface and warns them before an attacker gets in. Coalition reports its policyholders file roughly 70% fewer claims than the broader market. This week it went further, expanding its enterprise programme with Allianz (opens in new tab). The insurer stopped being a payer and became a loss-prevention engine that happens to carry a policy.
At the frontier, the same pattern. Armilla (opens in new tab), a Lloyd’s coverholder out of Toronto, tests an AI system for vulnerabilities before it will write a policy — model evaluation, stress testing, red teaming, drawing on more than 500 AI evaluations — then underwrites the liability up to $25 million. Munich Re has run performance-guarantee cover for AI since 2018 and now offers up to $15 million through Mosaic (opens in new tab). Testudo, the newest entrant out of the Lloyd’s Lab, writes AI-specific liability for the enterprises deploying the technology. As of early 2026, that was close to the entire supply of standalone AI liability insurance. Three firms. Against a risk this size, that is not a mature market. It is a starting line.
Notice what every one of them shares. They do not price the risk from the outside. They look inside the system, confirm how it actually behaves, and make the coverage conditional on hygiene that holds. That is the whole move. The agentic tail becomes insurable only when the insurer can see and shape the thing it’s insuring, which means the winners in this category won’t be the ones with the biggest balance sheet. They’ll be the ones with the best verification and the best telemetry.
How we think about it at Openfin
I sit on the building side of this. At Openfin we back and build insurtech, and the hinge between what a business runs and what a business can insure is exactly what I spend my time on. Our Meteoric Cyber venture quantifies cyber risk for the boardroom, putting a number on exposure that a CFO and an underwriter can both act on. That quantification is the pricing engine the new instrument needs. And the compliance posture we hold ourselves to internally (individual identities, scoped access, attributable logs, continuous rather than one-time) is the same hygiene the new model underwrites against. We didn’t design it for insurance. We designed it because it’s how you run a serious operation. It turns out to be the substrate the risk-reduction model runs on.
What this means if you’re building
If you take one thing from this, make it operational.
For founders: the whitespace is open and thin. Three firms at the frontier of AI liability. A verify-then-insure model that has barely been built for agents specifically. Agent telemetry that most companies don’t collect and couldn’t reconstruct after an incident. (OALABS had to release an open-source forensics tool precisely because the volume of agent logs defeats manual review.) Risk quantification a carrier can actually underwrite against. Each of those is a company waiting to be started, and the demand curve is already bending towards it.
For everyone else, and this is the part I’d hand to any operator whether they ever touch Openfin or not: go find the components of your business where an agent can act, or be turned against you — the credentials it can reach, the systems it can touch on your behalf. Then check two things. Check whether your current coverage still responds to a loss that runs through AI, because your last renewal may have quietly excluded it. And check whether you could reconstruct what an agent did on your systems if you had to. Most companies can answer neither. That is the work.
The hopeful part
Here is what I keep coming back to. The same technology that collapsed the skill floor for attackers is the technology that makes the new insurance model possible. The agent that writes an exploit is the agent that can be verified, monitored, and instrumented. The capability cuts both ways, and the side that wins is the side that builds the discipline around it first.
This is an opening. For the carriers already reinventing how they underwrite; for the security teams who get to matter more than they ever have; for the founders who look at three firms holding a frontier and see a category instead of a footnote. After the exclusions, the pricing paradox, and the first full logs of an AI doing the breaking, the conclusion writes itself: a new component of risk has arrived, and the instruments that fit it are still being built. If you are building anything right now, that is about the best news you could ask for!
About the Author
Duncan Platt
Group CTO and Co-Founder
Duncan is the Group CTO at Openfin. He has over two decades of technical leadership across US and South African ventures.
Stay updated on insurtech insights
Get our latest research and analysis delivered to your inbox.