A Reuters report dated August 27, 2026, based on eight executives and analysts, found that cyber insurers are reviewing policy language because helpers that can take a series of steps after a single instruction do not fit cleanly inside the definitions most policies were written around. MSIG, QBE, and Beazley are among the carriers now reviewing traditional cyber policies and adapting language, according to that reporting.

Most cyber policies were designed around a specific security event: unauthorized access, a server attack, ransomware delivered by a stranger. Helpers can cause losses using access they were deliberately given. There may be no conventional attacker. There may be no unauthorized credential use at the outset. The claim form still tends to ask about a stranger.

The hard case

Karthik Ramakrishnan, CEO and founder of Armilla AI, told Reuters: "Some losses caused by AI agents will absolutely fall within cyber policies." He added: "The harder cases are where there is no conventional attacker and potentially no unauthorized credential use."

That is the household version of the same problem. A family gives a helper access to email and files. A small shop connects one to its website and customer records. Neither owner thinks of that as a break-in, because they handed over the keys on purpose. If the helper then deletes files, sends mail to the wrong people, or exposes data, the path to a paid claim runs through whatever definition of a cyber event is sitting in that policy.

QBE's global head of cyber, Serene Davis, gave Reuters a statement: "AI is treated as a risk amplifier, not a fundamentally new cyber risk." She added that if an AI-related event leads to a conventional cyber incident, the losses stay in cyber. That is carrier positioning, not a coverage promise, and it does not settle what happens when the loss never becomes a conventional cyber incident at all.

For the most part, Reuters found, insurers are clarifying existing policy language rather than issuing a wave of exclusions. Targeted exclusions are being discussed in some areas: events where a single model or platform contributes to losses across many organizations, and cases where a helper acting as designed makes a costly decision that some carriers might classify outside cyber entirely.

What state regulators heard in August

On August 13, 2026, the National Association of Insurance Commissioners' Big Data and Artificial Intelligence (H) Working Group met in Columbus, Ohio. Edin Imsirovic of AM Best presented on AI governance and said at the outset that his presentation was for discussion and does not change AM Best's criteria, methodology, or rating guidance.

His working distinction between system types is useful for the insurance question. Predictive systems score, rank, or flag. Generative systems create content and can sound confident when wrong. A third type can work through a series of steps toward a goal, use tools, look up information, update a system, route work, or move a workflow forward. That third type is the one that raises the access and accountability questions carriers are now reviewing.

For those action-taking systems, Imsirovic said, evidence has to be more concrete. Are permissions tested? Are actions logged in a way that lets the company reconstruct what happened? Is there a kill switch that can roll the process back to a safe state? Does a person have the authority to override the system's actions? He also noted that looking up information is not the same as changing coverage or issuing a payment.

Nevada member Gennady Stolyarov II offered an illustration of why logging and reversibility matter. A chatbot that gives wrong information can mislead, but a person can intercede and the error is correctable. A helper that, trying to be useful, proactively and irreversibly deletes the company's claims files to free up storage is a different class of failure. He cited the July 2024 CrowdStrike incident as the kind of catastrophic failure those controls are meant to prevent. The deletion example is a hypothetical raised in discussion, not a documented paid claim.

Working Group Chair Nathan Houdek reported that a 12-state AI Risk Evaluation Supplement pilot has run since March 2026. Some states used it inside a planned exam; others used it as a standalone questionnaire. The pilot continues through September, a revised version goes out for public comment in early September, and the goal is adoption at the Fall National Meeting.

The NAIC's December 2023 Model Bulletin on the Use of Artificial Intelligence by Insurance Companies set expectations for how insurers govern the AI they use on customers, in underwriting, pricing, and claims. That is a separate question from how a policyholder's own helper might create a loss. The bulletin is not a rewrite of consumer cyber policies.

Three kinds of loss, and which one the form knows

It helps to sort losses into three rough groups. The first is what claim forms already understand: a stranger breaks in, uses unauthorized access, and causes damage. That is ransomware. That is the server attack.

The second is an ordinary human mistake. An employee sends the wrong file. An owner deletes the wrong folder. This tends to get handled as an operations issue or an error, when it gets handled at all.

The third is the one both the Reuters reporting and the NAIC discussion are circling: a helper using access it was deliberately given, causing a loss with no conventional attacker. This is an interpretation of the two sources, not a legal category. It still describes the practical situation many homes and small businesses are already in. They connected a helper to something real, and the existing policy definitions were written before that was a common thing to do.

What the evidence cannot establish

No named household or small business has a documented paid or denied claim of this type in the public record used here. Lab incidents disclosed by OpenAI, Anthropic, and Meta involved unexpected behavior in controlled test environments, and Reuters reported those events did not cause damage. That is not the same as widespread real-world insured losses. Market-size figures from Munich Re and forecasts from Aon are estimates. Carrier statements are positioning, not payment commitments. The 12-state pilot is not adopted law. None of this establishes how any specific policy will respond to a specific event.

Before something happens

The practical move is to send two questions in writing to whoever sold the policy. First: if a helper I authorized deletes files, sends mail, or exposes data, does this policy treat that as a cyber event? Second: what record would you need from me that day to support a claim?

Keep the written reply with the policy. That is an observation task, not a coverage promise. A written answer before a loss is more useful than a phone call after one.

Public sources