Dinsmore & Shohl LLP
  December 9, 2024 - Louisville, Kentucky

Insurance Strategies to Mitigate AI and Cyber Risks
  by Richik Sarkar

In an era of increasing data breaches and cyberattacks, businesses face mounting risks that can lead to financial, reputational, and operational damage. The cost of a data breach reached an average of $4.88 million in 2024, a 10 percent increase from the previous year. And with companies increasingly relying on artificial intelligence (AI) for decision-making and operations, they must navigate additional risks and legal challenges as AI’s transformative power introduces opportunities and significant exposures.

In this context, cyber insurance is a comforting safety net, helping businesses manage and mitigate the impact of cybersecurity incidents, including those driven by AI technology. AI’s evolving landscape also creates new challenges, such as algorithmic biases, unpredictable outputs, and the potential for “black box errors”—AI errors with unclear causes—that may result in uninsured exposure if not properly accounted for in insurance policies. Knowing that such a safety net exists can provide a sense of reassurance in the face of these evolving risks.

Even with strong cybersecurity, systems can be breached. Cyber insurance can help cover costs from data breaches, ransomware, and AI risks, though AI-specific coverage is still developing. Many policies offer some AI protection, but specialized coverage for algorithmic bias, large language model (LLM) hallucinations, and regulatory issues is emerging, often with broader protection than traditional policies.

However, expect high premiums and low limits, much like early cyber insurance. Insurers may also exclude losses from intentional AI misuse, standard software failures, and breaches not covered in existing policies. Exclusions for noncompliance with data privacy laws may also appear as regulations evolve.

Given the increasingly sophisticated nature of cyber and AI-related threats, the importance of cyber insurance cannot be overstated. AI creates unique vulnerabilities, from algorithmic decision-making errors to data privacy violations. Without adequate cyber insurance, businesses risk financial devastation and legal exposure in the event of AI system malfunctions or cybersecurity breaches.

Types of Cyber Insurance Coverage

Insurance policies generally provide two categories of coverage: first-party and third-party. With AI becoming integral to business processes, understanding these coverage types and how they apply to AI-specific risks is essential for selecting the right policies.

First-Party Coverage

First-party coverage addresses direct financial losses from a cyberattack or AI-related incident. An AI-related incident includes malfunctions, errors, or unforeseen consequences from AI systems, such as algorithmic biases, black box errors, security breaches, or data mishandling. As AI becomes integral to operations, these risks increase, potentially falling outside traditional insurance policies. Critical areas of coverage, often focusing on intangible losses like data breaches and cyber extortion and offering specialized services such as breach response and reputation management, include:

Third-Party Coverage

Third-party coverage focuses on liabilities your business might face from external parties due to a cyber or AI-related incident. Areas it covers include:

The Cyber Insurance Procurement Process

Due to AI developments, securing the right cyber insurance policy has become more complex. Businesses must adopt a comprehensive approach that ensures their insurance policies cover both traditional cybersecurity threats and emerging AI-related liabilities.

Step 1: Assess Cybersecurity and AI Risks

Before pursuing a cyber insurance policy, it’s not just important to conduct a thorough risk assessment, particularly concerning AI usage; it’s essential. This assessment helps identify vulnerabilities in your information and AI systems and data protection strategies, ensuring your business is prepared for AI-related and traditional cyber threats. Being prepared with a thorough risk assessment can provide a sense of readiness in the face of these risks.

Step 2: Gather Information

Underwriters require detailed information about your business’s cybersecurity and AI protocols. Be prepared to provide details on the following:

Step 3: Compare Policies

When comparing policies, consider both traditional and AI-related risks. Key factors include:

Step 4: Negotiate Terms

Negotiating AI-specific terms is crucial to ensure your policy provides the necessary protection. Areas to negotiate include:

Step 5: Understand Policy Exclusions and Limitations

With the rapid adoption of AI, businesses should pay particular attention to policy exclusions related to AI use. Standard exclusions might include:

Step 6: Regularly Review and Update Your Policy

Regularly reviewing and updating your business insurance policies as cyber risks and AI technology evolve ensures that your coverage remains adequate to address new AI-related dangers and vulnerabilities. AI systems are continuously improving; your insurance must keep pace with these changes.

Best Practices for Managing AI-Related Cybersecurity Risks

AI introduces significant new risks, from algorithmic biases to unforeseen system failures. However, strong governance and cybersecurity measures can minimize the likelihood of AI-related incidents. Here are several best practices to mitigate AI risks and improve cybersecurity posture:

Cyber insurance is crucial for managing cyberattack fallout, but with AI’s rise, all businesses must understand their insurance coverage and how they mitigate cyber and AI-specific risks. Businesses should consider AI-specific coverage, regularly review regulatory and risk management guidelines for their industry, especially those issued by regulators, and prepare for policy renewals by outlining their AI strategies, uses, and compliance measures. Understanding AI technology and articulating risk management is crucial in insurance negotiations. Thorough risk assessments, strong AI governance, and regular policy updates will mitigate cyber and AI risks in our complex digital world.




Read full article at: https://www.dinsmore.com/publications/insurance-strategies-to-mitigate-ai-and-cyber-risks/