BLOG POST

Tech & Sourcing @ Morgan Lewis

TECHNOLOGY TRANSACTIONS, OUTSOURCING, AND COMMERCIAL CONTRACTS NEWS FOR LAWYERS AND SOURCING PROFESSIONALS

When a Cyber Loss Has No Conventional Hacker

Cyber insurance traditionally assumes a familiar sequence: an attacker gains access to a system, data is stolen or operations are disrupted, and a claim follows. Autonomous systems may complicate every step, including whether the event qualifies as a cyber incident at all.

Recent reporting has highlighted how insurers are reassessing coverage as autonomous systems become capable of identifying vulnerabilities, choosing intermediate steps, and acting without direct human instruction. The issue is broader than any single technology or incident: policyholders and insurers must determine whether losses caused by software operating with some independence fit policy language written for more conventional attacks.

When the Attacker Is Not a Person

Autonomous systems can create familiar cyber consequences through unfamiliar conduct. The OWASP Top 10 for Agentic Applications identifies risks including goal hijacking, tool misuse, identity and privilege abuse, and unexpected behavior. Those risks can arise even when a system begins with valid access and is pursuing an authorized objective.

After receiving an initial instruction, an autonomous system may decide how to complete a task and take intermediate steps without further human approval. If those steps cause a loss, it may be unclear whether the system qualifies as an attacker, whether its actions were authorized, and which party should bear responsibility.

These characteristics are prompting insurers, brokers, and policyholders to examine whether existing definitions and exclusions account for losses produced by systems that can plan and act with limited supervision. The Geneva Association similarly notes that agentic systems can make causation and liability harder to trace and that insurability may depend on the maturity of an organization’s governance framework.

Coverage Without Unauthorized Access

Cyber policies commonly address ransomware payments, business interruption, system restoration, forensic investigations, notification, and legal costs. Those coverages often depend on defined terms such as “security failure,” “privacy event,” “unauthorized access,” or “network interruption,” and the wording can vary materially among policies.

Those policies frequently contemplate an identifiable security event, such as an outside attack or an employee obtaining unauthorized access and stealing data. An autonomous agent can present a different fact pattern because it may begin with valid credentials and permission to enter the relevant environment.

Consider a company that grants an autonomous system network access to identify and repair security vulnerabilities. The system might independently exploit a vulnerability, move through connected systems, and expose sensitive data. The company has experienced a loss, but there may be no conventional hacker and no unauthorized access at the beginning of the incident.

That distinction could determine whether the event falls within the policy’s definitions of security failure, unauthorized access, malicious activity, or cyber incident.

Adapting Existing Policies

The Geneva Association’s analysis observes that agentic systems may increase demand for insurance that expressly addresses autonomous risks. Coverage is unlikely to turn on a simple question of whether autonomous technology was involved. Existing cyber coverage may still respond if the system produces a recognized event, such as a data breach or network interruption. Other losses may fit more naturally under technology errors-and-omissions, professional liability, crime, or another line—if the relevant requirements are satisfied.

Policy wording may therefore need to separate the technology from the resulting harm. An autonomous system may remain within cyber coverage when it produces a conventional incident, while a policy may respond differently when the system simply makes a poor decision within the authority it was granted.

The harder cases arise when the system operates as designed but makes an expensive autonomous decision. That may look more like an operational or professional-liability loss than a cyber event. Insurers also must consider aggregation risk: one shared platform or common vulnerability could contribute to claims across many insured organizations.

A Growing Market with Limited Claims Data

Munich Re estimates that the global cyber insurance market totaled nearly $15 billion in 2025 and could reach around $28 billion by 2030. Its separate 2026 cyber risk and trends analysis notes that nonmalicious claims—including losses attributed to human error or flawed software—are gaining significance.

Historical claims of data specific to autonomous-system losses nevertheless remains limited. As adoption expands, policy language and underwriting practices may evolve through revised definitions, endorsements, pricing, or targeted exclusions, while policyholders’ governance and controls may become increasingly important to insurability.

Reading the Policy for an Autonomous World

Policyholders should review whether coverage depends on an external threat actor, malicious intent, or unauthorized credentials. They also should consider how the policy addresses business interruption, data exposure, regulatory investigations, third-party systems, and technology operating within the permissions it was granted. Because coverage analysis after an incident will depend on the facts, organizations should preserve logs showing the system’s instructions, permissions, decisions, and human approvals. NIST’s AI Risk Management Framework offers a useful governance starting point for identifying and managing system risks before a loss.

Coordination among cyber policies, technology errors-and-omissions coverage, crime coverage, and contractual indemnities also may become increasingly important. A loss that falls outside one policy because no traditional security event occurred may implicate another form of coverage—or reveal a gap between them. Contracting teams should compare insurance requirements and indemnity obligations against the parties’ actual control over credentials, system configuration, monitoring, and incident response.

Autonomous systems may not create a wholly new category of loss, but they can make conventional categories harder to apply. As the Geneva Association emphasizes, cyber insurance can support resilience before, during, and after an incident; that value depends on coverage language and governance practices keeping pace with how systems actually operate. When software acts on its own, the first coverage question may be not only what it did, but whether the policy recognizes what happened.