This document is provided for general informational purposes only and does not constitute legal, tax, accounting, insurance, brokerage, risk management, or other professional advice. You should consult your own legal counsel or other qualified professional advisors regarding your specific circumstances, and receipt of this document does not create any client, advisory, fiduciary, brokerage, or other professional relationship with Alliant Insurance Services, Inc. This document is provided “as is” without warranty of any kind, and Alliant Insurance Services, Inc. disclaims any liability for any loss or damage arising out of or relating to reliance on this document.
AI Risk Beyond Cyber: Emerging Exclusions and the Future of Insurance Coverage
By Alliant Cyber
AI is creating unprecedented challenges for organizations and their insurance programs. In this episode, Brendan Hall and Jennifer Page, Alliant Cyber, welcome Brad LaPorte, CMO, Morphisec, to discuss emerging AI exclusions, shadow AI, AI agents and the evolving cyber insurance landscape. They also share practical considerations for strengthening AI governance, cyber resilience and operational readiness.
Welcome (00:01):
Welcome to the Alliant Specialty Podcast, your source for insights on emerging risks, market trends, and specialty insurance solutions.
Brendan Hall (00:09):
All right. Welcome back to yet another Alliant Specialty Podcast. I am your host with the most, Brendan Hall, Senior Vice President, Cyber Insurance here at Alliant. I'm joined by our colleague, Jennifer Page. And then, as far as I know, first ever return guest, Brad LaPorte, Chief Marketing Officer at Morphisec Security. Brad, welcome back to the pod.
Brad LaPorte (00:34):
Thank you. Wow. So much has changed since the last time we did part one. It definitely warranted a revisit. I mean, I went back and looked, listened to the original. I mean, all relevant, but it's amazing how much just a few months in the space, will rock you to your core, especially with everything happening recently.
Brendan Hall (00:57):
Look, that tees us up nicely. I was, you know, going to say, I would love to hear, you know, an update on what's happening at Morphisec and for those who didn't join the first podcast, Morphisec is, you know, phenomenal technology that prevents ransomware from taking place in a client's environment or in a corporate environment. But I know you guys have made some additions to the product as things have evolved.
Brad LaPorte (01:17):
Yeah, it's quite amazing. I mean, we're cranking out new modules every quarter now. We're really steaming along, and it's based on the same core concept of anti-ransomware. So stopping ransomware now and for good. And we have a multi-layered approach, which allows us to stop 100% of all ransomware. We actually back that with an assurance guarantee. And very few, if any companies actually allow, you know, do that. And that works well with your general liability policy as well as the cyber insurance policy if you're able to get one nowadays. What we do on the back end to stop this is we do have visibility from the earliest stages all the way through to an execution attempt or a potential impacts event, which very rarely even gets to that stage. And this multi-layered approach, basically allows us to mitigate it.
Brad LaPorte (02:11):
It's a true defense in depth. And we're basically morphing everything on the back end. So if someone actually breaks into your house, they get through the front door, you know, we're there as, like a fun house of mirrors to morph the, you know, and confuse those individuals that they're not even able to get into the house and do any kind of damage. But the whole intent is that they don't even get to the front door. So we try our best.
Brendan Hall (02:35):
Right, yeah. When you had approaches about kind of doing this part two with the idea, you know, we started talking initially about the exclusions that we're now seeing pop up in insurance policies. And surprisingly, it's not Cyber policies where we're seeing the exclusions. We're seeing, you know, Berkshire Hathaway and Chubb have gotten legislative approval to exclude AI from general liability, D&O, E&O you know, in other insurance lines where you'd think the first one would be Cyber.
Brad LaPorte (03:01):
I'll start off with, like the situation first. So basically, over 80% of providers are now entertaining these exclusions. So Berkshire, Hathaway, Chubb, Travelers, like you said, that they're starting to have these AI exclusions. So basically, if you have any kind of damages and you do the root cause analysis and you find that AI was the culprit or involved in any way, shape or form. You know, I live in Florida. So basically it's kind of like we have our regular home insurance, and then you have, wind insurance. So, you know, if there's a named hurricane, or named storm, like, you're kind of SOL if on your regular policy, unless you have a wind policy, and all mortgages, if you have a mortgage, you're required to have a wind policy. And if you're on the water, it's even complicated with flood.
Brad LaPorte (03:47):
This is kind of like what's happening with AI. It was the easiest, you know, without over-complicating it with jargon and everything else, because they have a whole vast of different, you know, listeners, that know everything and everything else. And so it's starting on the general liability side, and it makes sense because we've already gone through a lot of scrutiny on the Cyber insurance side of the house. You know, now it, you have to go through, you know, the seven layers of the candy cane forest to effectively get Cyber insurance policy these days, and it can be, quite costly, and it requires that you have all the, dials and knobs. You have multifactor authentication. You have to have endpoint detection response. You have to have, you know, all these strategies and policies in place, and you have to check all these boxes.
Brad LaPorte (04:30):
And, you know, so it is pretty hardened and fortified in that nature. So it actually makes a lot of sense to me that it wouldn't start here. And because of the rapid pressure that's coming down from the boards, from key stakeholders, senior leadership, that we got to go now. We got to basically get this, AI adopted, implemented. We need the return on investment. We need to show profits. And subsequently, we're seeing layoffs, so we're seeing less resources. And that is cascading into, you know, now we're seeing this. It's Risk Management 101. And then so when I'm looking at my general liability policy and other policies that are applicable to this, you know, that, from a risk manager perspective, I'm like, "Oh, oh, oh, oh boy what are we going to do about this?" You know, if someone takes down a whole factory with AI, we're in a lot of trouble.
Brendan Hall (05:25):
Yeah. And we're starting to say, you know, we talked about this earlier. There was a loss. Recently, a company called Best, that makes car rental software for car rental companies. And they had built it out with Claude. They put in all the proper safeguards, as at least as far as they understood. And Claude, for whatever reason, just decided one day to delete their entire production database. And so we're starting to see more of these types of losses mount up. You know, Jen, from your perspective, I mean, obviously right now, AI losses are still covered in Cyber, but I mean, are we starting to hear any sort of, like, whispers of changes for, you know in terms of exclusions?
Jennifer Page (06:01):
Yeah. I think there's some buzz about it. You know, there haven't been any broad exclusions that have come out in the Cyber world, but there's a heightened awareness of it. You know, carriers are starting to ask AI-related questions on their applications. You know, things like "What AI deploy tools are you deploying internally?" "Is there an AI governance policy?" Formal AI risk, you know management framework type of stuff. They're also, you know, I think an area of concern for Cyber specifically is in the social engineering world. You know, there's a lot of concern that AI is, you know, going to dramatically increase, like the sophistication and the frequency of like, some impersonation fraud attacks. We've already seen things like, you know, deepfakes and so on and so forth. So again, you know, while there hasn't been exclusions that have really come out to the market, carriers, depending on, you know, responses to the applications may have follow-up questions around social engineering.
Jennifer Page (07:02):
You may see reduced sub-limits, you know, for some insureds, perhaps higher retentions. You know, a lot of carriers are asking about those callback verifications. So yeah, I mean, there's a lot of talk about it. You know, I think everybody is discussing wanting to know how it's going to impact the, you know, their Cyber policy, and it's almost like no one really knows yet, you know? We're all just kind of waiting for something to happen, and then we'll see how the market responds. But definitely questions the carriers are asking and, you know, a little bit of focus around the, you know, impersonation fraud stuff with all the deepfake capabilities out there.
Brendan Hall (07:40):
So that, so you're saying watch this space, the things that could be all, everything's fine for now. It could be tomorrow, as you say, you know, the deepfakes, I mean, we already have seed losses associated with people being socially engineered through deepfakes. And there are you know, there is technology out there, to sort of identify that. So when does that become, like, the next thing that they require? But, you know, you bring up another good point there is that, you know, they're asking questions about the governance aspect. And one thing that we hear a lot from clients, especially in the private equity world, they're concerned about their portfolio companies and what they are or not doing as it relates to AI technology and how they're, you know, staying on the right side of justice.
Brendan Hall (08:17):
You know, Brad, you had mentioned that one of the newer modules on your tech now is going help, you know, kind of track down shadow AI, right? Which I guess for those of you who don't know, like, AI that's out there that is not authorized by, you know, by the IT. In the sort of the general, like you know, limitations of the company.
Brad LaPorte (08:35):
Yeah. Like I said, we take a multi-layered approach, and one of the best features that we've actually launched to date in kind of the most impactful and get garnered the most interest is something called Adaptive AI defense. And it's very unique because we sit on the endpoint across Windows, Linux, Mac, we are able to basically block and disrupt any AI attack at machine speed. And that includes any shadow AI. So if you're running your own custom model on your laptop, if you have a loose higher IT policy and allows you to download Claude or OpenCloud or some of these really powerful tools that can really do some serious damage, your organization, like, as an organization, as a risk manager, you need to be able to have visibility into that. And not only visibility, but actually having user control around it. So we've launched something called AI Usage Control, which basically gives that visibility, real-time inventory of all the AI agents who are running on those endpoints in your fleet.
Brad LaPorte (09:36):
Being able to prevent it by blocking different types of attacks, like prompt injection, which is actually paramount with AI and kind of rogue automation that might be working in the background, and any kind of data, exfiltration that agents might be trying to execute, either with or without the user's knowledge. So Jennifer is talking about insider threats. We are effectively getting into another realm of insider threat where, you know, an agent is now being considered an employee. You know, <laugh> I mean, we're, this is the narrative and that's being implemented. So what does it mean when your agent is accelerating data? And so we just recently saw, you know, this Fable 5 Claude, just anthropic Claude, their model. They just launched a new model called Fable 5, which is based on, off mythos. Fable 5 is the public guardrail model, and it wasn't even out for a few hours, and they rolled it back, and it was basically banned by the US government.
Brad LaPorte (10:38):
So it just goes to show you the level of, you know, your care that's needed across the shadow of IT and how, like, this. We're really moving at a extremely breakneck speed right now.
Brendan Hall (10:51):
What a fascinating concept of AI agents being insider threats. And then, like, and so, where does the, and, if a liability is shifted away from underwriters and onto, you know, the companies and the employees themselves, if you create an agent and that agent goes haywire, are you, like, culpable? Are you responsible for that? Like, how does that work?
Brad LaPorte (11:13):
Yeah well, as Jennifer stated, currently today, it would, you know, it would be covered. Like, it would be covered by the policy. But like, we've seen this movie before. We've seen the summer blockbuster. I'm not saying it's going to be a 2026 blockbuster, but it very much could be a 2027 blockbuster where if you go back in a time machine, like, 16 years ago, you know, Cyber insurance came out of nowhere. It was relatively inexpensive. You had minimal underrating questionnaires. You know, it was like getting a mortgage pre - 2009. You know a guy and you get, you get signed off, you're good. You got a mortgage. I'm good. You don't worry about my credit...
Brendan Hall (11:52):
Billion dollar mortgage with 40K in salary. Don't make sense.
Brad LaPorte (11:55):
Yeah and a 500 credit score, you're good. So, you know, and then what happened in 2017? We had this massive ransomware explosion. And so we had WannaCry, NotPetya, you know, ransomwares in service, primers and service exploded. And then, you know, basically, we have a contraction, COVID and post - COVID, which was barriers responded by dramatically increasing the premiums. In some cases, 100%-300%. We had adding sub-limits on ransomware and caps, the co-insurance requirements, all the, you know, mandates for MFA, DR, etc. the 10, you know, double-digit things that you have to do now. And then, and all the underwriting questionnaires. I mean, it's insane, you know? It just to even navigate just the questionnaires alone is a full-time job. AI exclusions in the general liability side of the house, however you want to state it, is really a canary in the coal mine, because we are at a snap of a finger, we could find ourselves watching this blockbuster.
Brad LaPorte (12:59):
That's the popcorn because, you know, if the government can take away Fable 5 in a snap of a finger, it's like, what's saying the inverse isn't there?
Brendan Hall (13:10):
Oh by the way, for those, any CISOs out there listening, you know, there is personal coverage available to you. Crum & Forster is offering a product that, definitely worth looking into. It's relatively inexpensive for up to about a million bucks in coverage. But Jen, did you have something you want to add there?
Jennifer Page (13:26):
But, you know, agreeing with Brad in the sense that it just. We're one catastrophic event away from basically the emergence of the whole, you know, slew or a whole, you know, slew of AI-related exclusions, you know, that dawn as a result of whatever happens. But until then, everyone's, like, from a Cyber standpoint, "a lot of talk", but kind of just waiting, waiting, waiting, because no one knows what to do. Everyone wants to see, how the other person reacts first. But it'll be interesting. I mean, it's obviously, it's not going away. It's, I think, it's going to change the insurance landscape on all lines, you know, Cyber included. We'll just have to see. There's a lot of talk about it as we're talking about it today. We'll just kind of have to, we'll see how it plays out.
Brendan Hall (14:13):
And it's a whole other skillset, right? 'Cause like, there's Insurance, there's Cybersecurity expertise and AI while it's related. I mean, there's something with machine learning in particular, it's like after a couple of iterations of learning, the machine starts making decisions that we can't actually explain, "Oh, I did this because of that." It's like, "well we didn't really know that it learned stuff," and then it made predictions or whatever else. Brad, any closing thoughts here before we wrap up?
Brad LaPorte (14:40):
Yeah, I mean, really, it comes down to, okay, "what can you do today?" And, you know, I have a very strong military background, and it just starts with having the conversation. Have the conversation with your peers, having the conversation, you know, inside and outside the house, and at the board level, and it really comes down to defense in depth, re-looking at your risk management profile, "what's your risk tolerance?" You know, it's just Insurance 101, and can you do everything from an insurance perspective giving this? And like, right now, some of these things are not even in place yet. And so what could happen in the next one to three months or even one to three years? And getting ahead of that power curve. And then, while preparing for the next thing. SoI mean doing, you know, Cyber ranges and just operational readiness exercises go a long way.
Brad LaPorte (15:27):
I mean, just getting your crew together around a round table and just getting the pencils out and doing just a mock-up of like, "what would happen if this were to take place?"
Brendan Hall (15:39):
Yeah. And it's having that corporate muscle memory around exercises so that you're not going, "Okay, what's my role?" Like, you need to know, okay gosh, like the thing that we practiced is happening, right? It's like a fire drill. Like, I know which staircase I'm going down. Well, Brett it was great to have you back on. I'm not futured but, you know, it's possible there's going be a part three. I don't want to get people too excited. Jen, thank you so much as my colleague for joining. I know these are, this is a new thing for you to do five stars. I'm going give you five stars right after this. Well, thank you guys. That has been great. I appreciate it.
Thanks for your message.
We’ll be in touch shortly