Artificial intelligence is changing how cyberattacks are carried out. Advanced models can identify vulnerabilities, generate malicious code, obtain credentials, and coordinate multiple stages of an attack. AI agents can also interact directly with computer systems and external applications.
The National Institute of Standards and Technology identifies offensive cyber capabilities, information security, and data privacy as key generative AI risks and recommends human oversight, testing, and monitoring.1
If a criminal uses an AI agent to obtain banking credentials and transfer funds, the claims team must reconstruct how the loss occurred, what authority the agent had, and which controls failed. The investigation may extend to the AI developer, deploying business, financial institution, and technology vendors. Its findings will shape coverage, allocation, and recovery.
Key Takeaways
- AI agents can use credentials, enter systems, and initiate transactions with limited human involvement.
- Claims teams must separate model, human, and vendor activity before allocating the loss across parties and policies.
- New AI exclusions and overlapping coverage make early policy analysis and recovery planning increasingly important.
When AI Moves From Tool to Active Participant
An AI model that provides general security information presents different claims issues from an agent that uses credentials, enters a protected system, and initiates a transaction. Claims teams must determine what instructions the agent received and which actions it performed without additional human direction.2
The investigation should use prompts, model versions, permissions, authentication records, system logs, internal warnings, security testing, bank records, and vendor communications to reconstruct the event and separate the actions of each party. A single loss may implicate multiple types of policies.3 The following graphic maps those potential responsibilities, coverages, and recovery paths.
PASTE IMAGE 1 (image1.png)
AI Losses Extend Beyond Financial Theft
AI-related losses may also involve network breaches, property damage, medical errors, or harmful chatbot guidance. The examples below are illustrative.
Product Liability Remains Unsettled
In Garcia v. Character Technologies, a federal court's May 2025 motion-to-dismiss ruling allowed claims based on alleged design defects to proceed while distinguishing those claims from the chatbot's ideas or expressions. The preliminary ruling did not establish that every AI model is a product.4
Silent AI Coverage Is Narrowing
New ISO endorsements allow insurers to exclude generative AI losses from CGL coverage. CG 40 47 applies to bodily injury, property damage, and personal and advertising injury; CG 40 48 applies only to personal and advertising injury; and CG 35 08 addresses products and completed operations. The endorsements are optional, but they are beginning to appear at renewal.5
Claims teams should therefore map coverage early. AI-enabled theft may implicate cyber, commercial crime, financial institution bond, or technology E&O policies, while related third-party claims may encounter AI exclusions. Early review of policy terms, limits, notice requirements, and recovery rights can prevent gaps and preserve options.
First 72 Hours: Preserve the Record
AI systems, logs, permissions, and model versions can change quickly. Claims leadership should coordinate immediately with coverage counsel, SIU, forensic specialists, and relevant vendors to preserve:
- Prompts, instructions, outputs, and time stamps
- Model name, version, configuration, and connected tools
- User, system, and vendor permissions
- Credentials, access tokens, and authentication records
- Security testing and vulnerability reports
- Internal warnings, alerts, complaints, and escalations
- System, application, cloud, and network logs
- Transaction, payment, and bank records
- Vendor contracts, service agreements, and incident communications
Records should be preserved in their original format with available metadata. Routine deletion and log-rotation processes should be suspended where appropriate.6
How Alan Gray Can Help
For claims leadership, coverage counsel, SIU and forensic teams, and runoff managers, the work should follow five steps:
1. Reconstruct the event. Trace prompts, model versions, permissions, system activity, and the transaction path.
2. Quantify the loss. Measure transferred funds, business interruption, extra expense, and related costs.
3. Map the coverage. Identify potentially responsive cyber, crime, product liability, E&O, D&O, and property policies.
4. Evaluate recovery. Assess potential recovery from vendors, financial institutions, and other parties.
5. Review performance. Independently evaluate claim handling, documentation, and vendor performance.
The Claims Imperative
AI-enabled losses may cross systems, organizations, and insurance policies. Early reconstruction of the event, coordinated coverage analysis, and recovery planning can determine how effectively the loss is resolved.
Citations
- National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile. NIST AI 600-1, July 2024, NIST.
- OpenAI. "The Hugging Face Incident and the Road Ahead." 26 Aug. 2026, OpenAI.
- Arthur J. Gallagher & Co. "Not So Silent: Tackling the Complexities of AI Liability." May 2026, Gallagher.
- Garcia v. Character Technologies, Inc., No. 6:24-cv-1903-ACC-UAM, U.S. District Court for the Middle District of Florida, 21 May 2025, FindLaw.
- Jergler, Don. "Insurer Interest in AI Coverage Exclusions Growing as Risk Becomes Omnipresent." Insurance Journal, 17 Aug. 2026, Insurance Journal; Arthur J. Gallagher & Co. "ISO Introduces Generative AI Exclusion in Commercial General Liability Policies." 2026, Gallagher.
- Nelson, Alexander, et al. Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile. NIST SP 800-61 Rev. 3, Apr. 2025, NIST.

%20(1).png)
-2.png)
-2.png)
