This is not a prediction. It is already happening. MSIG, QBE, and Beazley are actively rewriting the language of their cyber policies, and the reason is straightforward once you say it plainly. An AI agent can now cause a genuine financial loss without anything that resembles a traditional security incident. No breach. No stolen credentials. No malware. Just a system doing exactly what it was technically permitted to do, in a sequence nobody quite intended.
Munich Re has put a number on the scale of what is now at stake, valuing the affected market at close to fifteen billion dollars. That figure is not really about the agents themselves. It is about how much money is currently moving through systems that most organisations cannot fully explain if something goes wrong.