Your Cyber Insurance Renewal Is About to Ask You a Question You Cannot Currently Answer

Somewhere in the next renewal cycle, a cyber insurer is going to send a questionnaire that looks different from the one your organisation filled out last year. It will ask about your AI agents. Not in general terms about your AI strategy, but specifically, about what those agents are authorised to do, who granted that authority, and how you would prove it if asked.

This is not a prediction. It is already happening. MSIG, QBE, and Beazley are actively rewriting the language of their cyber policies, and the reason is straightforward once you say it plainly. An AI agent can now cause a genuine financial loss without anything that resembles a traditional security incident. No breach. No stolen credentials. No malware. Just a system doing exactly what it was technically permitted to do, in a sequence nobody quite intended.

Munich Re has put a number on the scale of what is now at stake, valuing the affected market at close to fifteen billion dollars. That figure is not really about the agents themselves. It is about how much money is currently moving through systems that most organisations cannot fully explain if something goes wrong.

Why this is harder than it sounds

The instinct, when a questionnaire like this arrives, is to pull together whatever documentation already exists and hope it is enough. The trouble is that most of what organisations have on hand describes intention rather than evidence. A policy says agents should only act within certain limits. It does not prove that the technical configuration actually enforces those limits, or that the gap between the two has ever been measured.

Insurers are not asking whether you have a policy. Ninety eight percent of organisations already have one, according to a recent EY survey, and nearly half admit to bypassing it when a deployment felt urgent enough. Insurers are asking whether you can independently demonstrate that the policy and the reality match. Those are very different questions, and only one of them is answerable with a document you already have sitting in a shared drive.

What a real answer looks like

A genuine answer to this question is not a longer policy. It is a reconciled account of four things at once. What your organisation formally declared. What was actually delegated. What the technical systems genuinely permit. And what your agents have actually done. Where those four layers disagree is where your real exposure sits, and it needs to be expressed as something concrete, ideally in dollars, not as a general assurance that everything is under control.

That kind of evidence, produced independently of the platforms your agents run on, is what an insurer, a regulator, and increasingly an enterprise counterparty are all starting to expect to see in the same document.

If your next renewal questionnaire is going to ask this question, the better time to find your answer is now, not in the middle of filling it out.

See where your own agents stand before the questionnaire arrives.