Following an article on Cyber Insurance in the Financial Times today ‘Growing threats prompt rethink over cyber insurance’ I felt a moment of déjà vu, as I reflected on a piece I wrote just over 10 years ago to the day Cyber Insurance – Let the dance begin. In which I predicted the disruption to the Cyber Insurance industry that is perhaps now taking place.
For decades, cyber insurance has operated on a relatively simple premise, understand an organisation’s security controls, estimate the likelihood of loss, price the risk and review it again next year. Artificial intelligence has quietly dismantled that model and in here lies the foresight I shared in 2016.
The problem is not simply that AI has created new threats such as deepfakes, autonomous malware or prompt injection. It is that AI has fundamentally changed the nature of cyber risk itself. Risk is no longer static enough to be measured annually, nor confined to servers, laptops and data centres. It now extends to digital identities, autonomous agents, foundation models, supply chains and machine-driven decision making.
An organisation can materially change its exposure in a single afternoon simply by deploying a new AI service or granting an autonomous agent authority to act on its behalf. Against that backdrop, the traditional cyber insurance questionnaire begins to look like a relic from another era. It asks whether security controls existed at the moment the form was completed. It says almost nothing about whether they remain effective today.
The cyber industry has spent years encouraging organisations to move from periodic audits to continuous security monitoring. It seems inevitable that insurers will now need to make exactly the same transition. The most likely destination is continuous, evidence-based underwriting.
Rather than relying on lengthy questionnaires, insurers will increasingly consume trusted assurance data from a new generation of independent ‘Digital Trust’ assurance platforms. These platforms will aggregate technical telemetry, governance evidence, AI oversight, resilience testing and independent validation into a continuously updated view of organisational trustworthiness. The implications extend far beyond operational efficiency.
Premiums could become dynamic, reflecting an organisation’s live risk rather than last year’s declarations. Organisations that continuously demonstrate strong governance and effective controls could benefit from lower premiums, while deteriorating security posture or unmanaged AI deployments would be reflected before losses occur rather than after claims are submitted.
Claims investigations would also become more objective. Instead of reconstructing events months later from incomplete evidence, insurers could reference independently maintained assurance records that demonstrate precisely how an organisation’s control environment changed over time.
In many respects, cyber insurance may begin to resemble telematics in motor insurance. Safe drivers increasingly pay less because insurers observe behaviour continuously rather than relying solely on historical assumptions. AI is pushing cyber insurance towards the same destination.
Yes there already exist some cyber ratings providers that solved an important problem, they gave insurers, investors and customers an independent view of an organisation’s externally observable cyber hygiene. in simple terms they scanned an organisations digital contact surface for vulnerabilities and gave a score based on findings. That was highly valuable when cyber risk was largely correlated with exposed infrastructure. The AI era changes that equation, many of the most significant AI and agentic related risks are not externally observable. The question is whether they remain cyber ratings companies or evolve beyond external ratings by integrating internal assurance evidence, or become extinct as a new generation of ‘Digital Trust Authority’ usurps them.
In an AI driven economy, organisations are not simply trying to minimise vulnerabilities, they are trying to demonstrate that they can be trusted to operate autonomous technologies safely. That is a broader proposition than cyber hygiene alone and it is where ‘Digital Trust Authorities’ could represent the next stage in the evolution of cyber assurance.
The irony is striking. For years, insurers have asked organisations whether they can be trusted. In the AI era, they may no longer need to ask. They will simply consume trusted evidence.
The winners will not necessarily be the organisations with the largest security budgets. They will be those capable of proving, continuously and independently, that they remain worthy of trust. Which may prove to be the most significant evolution in cyber insurance since the market was created.
Posted on July 20, 2026
0