African insurers on notice as AI tests cyber insurance boundaries in the West

HomeRisk Management

African insurers on notice as AI tests cyber insurance boundaries in the West

The increasing adoption of artificial intelligence (AI) in Western markets is testing the boundaries of cyber insurance, forcing insurers to reconsider what constitutes a cyber event when the technology is involved. It is a development that African insurers are watching closely as AI adoption spreads across the continent.

The developments offer an early warning for African insurers as businesses and individuals across the continent increasingly adopt AI for work and everyday tasks, bringing new and still-evolving risks into the insurance landscape.

Firms across the continent are increasingly deploying AI for functions ranging from customer service and fraud detection to underwriting, claims management and software development. A PricewaterhouseCoopers (PwC) study published in May 2026 found 82% of African organisations surveyed were running AI pilots, with a smaller share having moved to enterprise-wide deployment.

That growing use of AI in Africa means insurers are not merely adopting AI themselves. They are also increasingly insuring businesses whose operations, controls and risk profiles are being reshaped by the technology.

Recent cases in the West involving AI agents acting beyond their intended instructions are forcing insurers in such mature AI markets to confront questions over what constitutes a cyber event, who bears liability when an AI system causes a loss and whether existing policies provide adequate protection.

For African insurers, these incidents offer an early glimpse of risks that could become more relevant as local AI adoption deepens. The continent may not yet be seeing the same scale of rogue-agent incidents, but the growing adoption of AI means they cannot afford to sit pretty as AI changes the risk profiles of the customers they underwrite.

In the West, where adoption of increasingly autonomous AI systems is further ahead, insurers are already confronting questions over what happens when an AI system causes a loss without a conventional hacker or unauthorised access.

The warning from the West

Several insurers including MSIG, QBE and Beazley recently told Reuters they are reviewing traditional cyber policies and adapting their language to account for emerging risks posed by such systems taking on more autonomous tasks. The review comes on the back of AI agents becoming capable of making decisions and carrying out tasks with limited human intervention. The issue is particularly difficult where an organisation has deliberately given an AI system access to its networks and the system subsequently causes damage.

The issue moved from theoretical to more tangible territory in July when OpenAI disclosed that an AI agent being tested had escaped its controlled environment and compromised infrastructure at the open-source platform Hugging Face. Investigations found that hundreds of AI agents had participated in the activity.

The incidents did not translate into insured losses but they demonstrated a problem that insurers are beginning to confront. An AI system can potentially act as an attacker even when it was initially given legitimate access by the policyholder. That challenges a basic assumption embedded in many traditional cyber policies.

Cyber insurance has generally been designed around events such as unauthorised access, ransomware, data theft, system compromise and other identifiable security incidents. An autonomous system that has been legitimately authorised to access a network, however, could cause a loss without a conventional external attacker breaching the system.

Karthik Ramakrishnan, founder and chief executive of AI risk specialist Armilla AI, told Reuters that some losses caused by AI agents would clearly fall within cyber policies, but the harder cases arise when there is neither a conventional attacker nor unauthorised use of credentials.

“Some losses caused ​by AI agents will absolutely fall within cyber policies. The harder cases are where there is no conventional attacker and potentially no unauthorised credential use,” said Ramakrishnan.

For insurers, that creates questions over whether the resulting loss is a cyber event or instead a technology failure, professional liability, operational risk or another form of insured exposure. It also creates a pricing problem, especially that there is not enough historical claims experience to establish with confidence how frequently AI-driven incidents will occur, how severe they will be or which sectors will be most affected.

That is a problem that African insurers should pay attention to now rather than wait for local claims to provide the answers. The data problem is more complicated given that insurers are already grappling with data gaps when it comes to other emerging risks such as climate change whose impact is already being felt across the continent.

AS CSO Online, a digital media dedicated to enterprise security, risk management and cybersecurity leadership noted, AI agents can go to great lengths to complete the tasks their operators assign, and this can include exploiting third-party systems, manipulating people and distributing malicious code.

However, CSO notes that AI agents are not people who can be fired, sued, or criminally prosecuted, and it remains unclear whether responsibility for the damage they might cause rests with the employees who built them, the company that deployed them, the security teams and leaders responsible for containing them, or the AI labs who provided the large language models (LLMs) that power them.

Africa’s exposure is building

The continent is not yet facing the same volume of AI-agent incidents reported in more advanced markets, and there is little evidence to suggest that rogue autonomous agents are currently generating a significant pool of insurance claims in African markets. However, this is precisely why developments in the West should be viewed as a learning opportunity amid reports forecasting a rise in AI-related risks.

The fourth edition of Munich Re’s Global Cyber Risk and Insurance Survey published in April 2026 estimated the global cyber insurance market to be nearly US$15billion in 2025 and forecasts the global premium volume to expand to around US$28 billion by 2030, representing an average annual global growth rate of 15% between 2020 and 2030. The report also highlighted growing risks.

“The magnitude of the cyber threat is striking: if cybercrime were a country, it would be the world’s third-largest economy. By 2028, global cybercrime costs are expected to reach US$14 trillion, according to Statista, surpassing the current combined GDP of Germany, Japan and India,” said the report.

In addition, Munich Re experts said they expect cybercrime to become increasingly automated and democratised through the widespread use of AI tools, thereby “lowering the skill level required to launch an attack.”

“This will expand access to sophisticated attack capabilities, amplifying threats particularly for micro and mid-sized companies. The assumption that “my company is too small or uninteresting to be attacked” is now obsolete. As a result, cyber insurance will be indispensable for organisations of all sizes in the future,” said the reinsurer.

Meanwhile, Aon forecasts that close to 20% of cyberattacks will involve generative AI by 2027. The situation has insurance companies wrestling with what their cyber policies should cover.

Given that African companies are moving steadily from experimenting with AI to embedding it in business processes, the evolving risk landscape linked to AI use makes the experiences in developed economies one they have to follow closely.

The coverage question

Reuters reported that several insurers are instead examining how existing cyber wording responds when AI is involved. QBE, for example, has described AI as a risk amplifier rather than an entirely new category of cyber risk, while other insurers are developing protection for more specific AI exposures.

The approach could be particularly relevant to African markets, where cyber insurance is still developing and specialised AI insurance products may remain limited.

Underwriters in Africa may need to establish what constitutes a security event when an AI system is involved. They may also have to understand whether losses arising from hallucinations, erroneous automated decisions, data leakage, intellectual property violations or AI-enabled fraud are covered elsewhere in the client’s insurance programme.

“The market is still evolving, but we expect organisations and insurers to ​continue exploring ways to address AI-related exposures as adoption accelerates,” Jenny Soubra, vice president of specialty commercial ​lines at Verisk Underwriting Solutions, told Reuters.

This is increasingly important because AI does not create only cyber risks. Munich Re’s 2026 cyber insurance analysis says agentic AI is expected to influence the frequency of attacks and could affect covers ranging from system failure and business interruption to incident response, data restoration and cyber extortion. It also points to potential third-party losses involving privacy violations, media liability and technology errors and omissions.

“AI introduces a broad range of exposures across both first-party and third-party risk categories, with particular sensitivity in Media Liability and Technology E&O policies. In most cyber policies, AI falls under the standard definition of computer systems, meaning it may typically be covered even when not explicitly referenced,” said Munich Re.

For African risk managers, this means AI should not sit solely with the IT department when insurance is being arranged. They may have to ask questions such as: What AI systems does the business use? What can they access? What decisions can they make? How are their actions monitored? And what happens when they fail? Answers to such questions will increasingly become relevant to underwriting decisions.

The aggregation problem

Risk analysts are warning that AI risks may not remain confined to individual policyholders. Companies across a market can rely on the same cloud provider, AI model, software platform or technology infrastructure. This means a failure, vulnerability or malicious exploitation affecting that common provider could generate losses across many insureds at the same time.

For African markets, where businesses may increasingly depend on a relatively concentrated group of global technology providers, understanding these dependencies could become an important part of cyber underwriting and reinsurance. The industry’s challenge will be to avoid discovering the scale of that accumulation only after a major event.

A chance to get ahead

The lesson for African insurers is to use the experience of more mature markets to prepare before the claims arrive.

“That means reviewing cyber policy language, developing underwriting questions around AI use, improving risk assessment and working with brokers and clients to establish clearer responsibilities. It also means collecting data,” said Dennis Rotich, an independent cyber risk analyst based in Nairobi.

Aon’s 2026 research titled ‘Intangible vs Tangible Risks Comparison Report’ found that 63% of respondents either believed their existing policies or standalone AI liability cover did not address AI-generated attack risks or were unsure whether they did. Yet, 63% are interested or very interested in purchasing an AI liability policy.

COMMENTS

WORDPRESS: 0
DISQUS:

Discover more from Africa Ahead

Subscribe now to keep reading and get access to the full archive.

Continue reading