When Maria Long heard about OpenAI’s rogue model attacking AI-model service provider Hugging Face, her first stop was to review her firm’s technology errors and omissions (tech E&O) policy.
As the chief underwriting officer for cybersecurity insurance services firm Resilience, Long understood that rogue artificial intelligence (AI) agents causing inadvertent compromises could result in significant losses to insurers in the future. This incident showed that the future wasn’t that far off. For Hugging Face, the incident would almost certainly be covered by cyber-liability insurance as a classic security breach. However, if AI agents routinely escape containment, insurers have to consider that the volume of policy claims could grow.
Even more concerning is the view from an insured company that uses agentic AI. In the July rogue-agent incident, OpenAI was the user; future incidents could involve an enterprise deploying agents from one of the major model providers. If those deployed agents go rogue, questions remain about who would be responsible for the badly behaving programs, she says. Would it be the enterprise or the model provider?
“Typically with a tech E&O policy, the intent of that policy is to cover the organization if there were to be a financial loss to a third party that is their client,” Long says. “But the gap that’s so interesting is, well, [an affected firm such as Hugging Face] is not a client — you may have created a financial loss to a third party.”
As the insurance industry attempts to determine who is liable when autonomous agents go rogue, AI has already become a major factor in cyber insurance losses. While Resilience did not have a single claim stemming from a fully automated AI attack chain, insured losses from AI-powered social engineering have surged, contributing to 85% of losses in the first half of 2026, up from 18% in the first half of 2024. More professional lures and deepfakes created using AI models are to blame, Resilience stated in its “2026 Midyear Cyber Risk Report.”
As Incidents Grow, Liability Remains a Question
While attackers’ use of AI is certainly a major problem facing corporate security teams, a bigger problem is that companies’ own AI agents keep going rogue. In addition to OpenAI, Meta and Anthropic have both acknowledged that AI agents have escaped research sandboxes and taken offensive cyber actions against third parties. At the end of July, for example, the United Kingdom’s AI research policy center, the AI Security Institute, discovered that during a cybersecurity challenge run 122 times, two advanced models — Anthropic’s Mythos 5 and OpenAI’s GPT-5.6-Sol with cyber classifiers — took 19 unsanctioned actions on the live Internet. Overall, 8% of cases resulted in rogue behavior.
“These attempts were unsuccessful, and our investigations have not evidenced any resulting real-world harm,” the institute stated in an analysis. “But this is the first time we have seen risks around autonomy and deception manifest this clearly, without specific prompting, in the real-world.”
![]()
Overall, incidents of AI system failures and safety issues have taken off in 2026. The four preceding years saw 34 to 36 incidents reported per year, but so far in 2026 there have been 43, according to the MIT AI Risk Initiative. As companies accelerate their adoption of AI and increasingly automate some tasks with AI agents, cybersecurity has become a major concern but one that often takes a back seat to efforts to gain productivity and business advantage from the new technology.
The problem with AI agents, however, is their persistence in pursuing their goals, and a single bad decision by an AI agent could trigger a worm-like outbreak of attacks, says Jack Nelson, CISO and deputy general counsel at Ivanti, an endpoint-security management provider.
“I suspect your insurance carriers are having a hard time underwriting things like this because they just don’t know how to [gauge liability] because of how fast these incidents could balloon,” he says.
The issue could extend to criminal liability as well. The Trump administration’s Executive Order 14409, published in June, prioritizes the investigation and prosecution of AI-enabled attacks in which anyone “utilizes AI to illegally access or damage a computer without authorization.” Considering that attacks by rogue AI agents are not easily discernible from malicious AI attacks — Hugging Face initially just knew it was being attacked — rogue AI agents could result in prosecutions, a problem considering that AI agents’ goal-oriented behavior makes them hard to control.
Moving Beyond Breaches and Downtime
Currently, much of cyber insurance focuses on breaches and downtime, and that remains the focus of most insurers, says Resilience’s Long. As companies rely more heavily on AI services, claims for losses could increase if an AI service goes down due to an error or malicious action.
“If you’re now six months, one year, two years deep into your AI buildout and really making this a routine part of your day-to-day [operations], what happens if that service is down and you can’t use it?” she asks. “Does that cause an interruption to the business? Does that result in a monetary loss to the organization?”
Yet companies building out their AI frameworks and creating new services need to take care in having adequate controls for AI agents that attempt to exceed their remit, Long says.
These incidents are “a really good example of ‘we’re just trying to test something, we’re running an experiment, but maybe we’re not necessarily thinking about the ramifications and maybe whether this was really planned out the way that it should have been,'” she says.
Overall, as with much of the innovation around AI systems, everything is up in the air at the moment and could change in six months, says Ivanti’s Nelson. Given the deep pockets of the foundational AI model firms, however, and the past history of the “shared responsibility” model for cloud services, much of the responsibility will likely land on the organization that deploys agents, he says.
“Liability has yet to be determined — whether it’s totally going to sit with the person that unleashed the agent or is it going to sit with the actual model creators that created a model that could do that,” he says. “I suspect the former is more likely because [the operator has] so much input in terms of harnesses, skills, and how you’re training the agent.”

Comments are closed