National Cyber Practice Leader
- Cambridge, MD
Artificial intelligence is actively transforming how organizations operate, compete and innovate as businesses embrace AI to improve efficiency, streamline workflows and enhance decision-making. But those same technologies are also giving cybercriminals more sophisticated tools to launch faster, more convincing and increasingly targeted attacks.
"AI is moving at a breakneck pace," says Steve Robinson, Area President and National Cyber Practice Leader at RPS. "The flip side is that threat actors are using the same tools to make their nefarious operations faster, more effective and ultimately more profitable."
For retail agents, that shift is creating a new challenge: helping clients understand how AI is changing their cyber exposures — and ensuring their insurance programs evolve just as quickly.
Cybercriminals have always adapted quickly to new technology. What's different today is the speed and scale at which AI allows attacks to be developed and executed.
AI tools can automate tasks that once required significant technical expertise, including:
"The line between deciding to target an organization and actually executing an attack has become much shorter because AI helps criminals identify vulnerabilities, gather information and automate much of the process," Robinson explains.
Rather than replacing traditional cyberattacks, AI is making existing attack methods more efficient and scalable. Criminals can launch more campaigns in less time while tailoring communications to appear increasingly legitimate.
The result is a surge in sophisticated attacks that are more difficult for employees — and traditional security controls — to recognize.
One of the most visible shifts tied to AI is the rapid advancement of social engineering and fraud schemes.
Deepfake audio, AI-generated messaging and voice cloning technologies are making it increasingly difficult to distinguish legitimate communications from fraudulent requests. Criminals can now replicate writing styles, eliminate language barriers, mimic executive voices and combine multiple attack techniques into a highly convincing scam.
For example, attackers who gain access to an executive's email or calendar can use AI-generated voice cloning to leave a voicemail that references actual meetings, travel plans or business transactions, making fraudulent requests appear authentic.
"These attacks aren't just more believable because of the technology," Robinson says. "They're more believable because AI allows criminals to combine multiple sources of information into a single, convincing interaction."
From a coverage perspective, these evolving tactics create additional pressure on:
While the attack methods have become more sophisticated, Robinson noted that many Cyber policies already respond to these events.
"The important question isn't whether AI was used to commit the crime," he says. "It's whether the covered cyber event occurred. Today's Cyber policies generally respond regardless of whether the threat actor employed AI."
Even as AI-driven attacks become more convincing, one of the most effective defenses remains surprisingly simple: independent verification.
"If you receive a request to change banking information or transfer funds, pick up the phone and call the known number already on file," Robinson advises. "That one step would stop the overwhelming majority of these crimes."
Many Cyber insurers now require organizations to maintain documented procedures for two-factor authentication or out-of-band verification before authorizing financial transactions. Those controls not only reduce the likelihood of loss but may also play an important role during the claims process.
As AI-driven threats continue to evolve, carriers are reassessing how they evaluate cyber risk, particularly for organizations with:
This increased scrutiny may lead to higher retentions, more restrictive terms, reduced capacity and additional underwriting questions regarding AI governance and internal controls.
For agents, that means more placements may fall outside the standard market appetite, particularly as underwriters seek greater visibility into how clients implement and manage AI technologies.
As cyber risk becomes more nuanced, specialty and E&S markets are playing an increasingly important role in helping brokers secure appropriate coverage for clients with emerging or non-standard exposures. Through RPS, agents can access:
Beyond market access, RPS specialists help brokers translate technical cyber risks, including AI governance, security controls and operational practices, into underwriting-ready submissions that carriers can confidently evaluate.
As organizations continue to adopt AI across their operations, brokers should revisit Cyber programs with a fresh perspective. Important discussion points include:
Robinson encourages agents to move beyond simply asking whether a client uses AI. Instead, conversations should focus on who within the organization is using AI, which business functions rely on it and what safeguards are in place to validate AI-generated information or financial requests.
These conversations can uncover vulnerabilities that may not have existed when a client's Cyber program was originally placed.
It's important to note that we're discussing the use of AI by adversaries when executing attacks. The potential liabilities for businesses that employ client-facing generative AI outputs are a separate topic, and the insurance marketplace is still in relative infancy with respect to coverage, exclusions, policy coordination and overall approach. RPS remains on the front lines of the liability side of the discussion and can work with agents to find the right solutions for insureds facing these new exposures.
AI isn't simply introducing new cyber risks; it's accelerating the pace at which those risks evolve. This creates both a challenge and an opportunity for agents. Clients increasingly need guidance on balancing innovation with risk management while keeping their insurance programs aligned with an evolving threat landscape.
"Cyber insurance can't prevent an attack," Robinson says. "But agents can help clients build stronger resilience by validating their controls, identifying coverage gaps and making sure their cyber program evolves alongside the technology they're using."
By leveraging specialty market access, flexible program structures and underwriting expertise, agents can help clients build Cyber programs that respond to today's threats — and adapt to tomorrow's.
The information contained herein is offered as insurance industry guidance and provided as an overview of current market risks and available coverages and is intended for discussion purposes only. This publication is not intended to offer financial, tax, legal or client-specific insurance and risk management advice. Any description of insurance coverages is not meant to interpret specific coverages that your company may already have in place or that may be generally available. General insurance descriptions contained herein do not include complete insurance policy definitions, terms and/or conditions, and should not be relied on for coverage interpretation. Actual insurance policies must always be consulted for full coverage details and analysis. Risk Placement Services, Inc. IL License No. 100294602 DBA in California as Risk Placement Services Insurance Brokers. CA License No. 0C66724.