Prompt Injection Attacks as an Insured Cyber Event

Insurers haven't caught up to how AI systems actually get attacked.

Policy & Ethics Editor · · 10 min read
Cover illustration for “Prompt Injection Attacks as an Insured Cyber Event”
AI Model Liability · October 7, 2026 · 10 min read · 2,276 words

Prompt injection causes real financial losses, but standard cyber insurance was never built to pay out on them, and the mismatch is widest when the system is autonomous or agentic. The gap between what a policy covers and what a prompt injection actually does sits in the mechanics of the attack itself, not in some ambiguous fine print that a lawyer can argue around after the fact.

Why prompt injection is not the same threat category as the attacks standard cyber policies were built to cover

Cyber insurance forms in wide use today were drafted against a specific picture of what an attack looks like: an outsider steals a credential, plants malware, or breaks through a network perimeter to get somewhere they're not supposed to be. That picture assumes a boundary, and it assumes the attacker crosses it. Every major clause in a standard policy, from the insuring agreement to the definition of a security failure, was built to recognize that crossing.

Prompt injection doesn't cross a boundary in that sense. Large language models process the instructions an operator gives them and the external content they encounter, a document, a webpage, a README file, as one continuous stream of tokens. There is no architectural wall separating "things the system was told to do" from "things the system happened to read." When an attacker hides an instruction inside a piece of content the model later ingests, the model has no built-in way to tell that instruction apart from a legitimate one. It just acts on it.

That means the system in question isn't breached the way a firewall or a password gets breached. It's manipulated into carrying out an instruction it had no authorization to follow, and that is a very different event from the one most policy language was written to catch. Two documented cases make the mechanism concrete. CurXecute, a vulnerability in the Cursor IDE tracked as CVE-2025-54135 with a CVSS score of 8.6, let attackers bury malicious prompts inside a repository's README file; when a developer simply opened the project, the AI assistant executed arbitrary commands, with no traditional exploit involved. EchoLeak, disclosed by researchers at Aim Security in June 2025 and tracked as CVE-2025-32711 with a CVSS score of 9.3, hit Microsoft 365 Copilot as a zero-click prompt injection: it required no user interaction whatsoever to succeed.

Agentic and physical AI systems raise the stakes further. Traditional industrial machines execute fixed commands: the same input produces the same output, every time. Physical AI systems use sensors, software, and models to decide how to act as conditions change, so the system's behavior can be genuinely unpredictable in a way traditional liability frameworks never had to account for. That flexibility is precisely the feature that insurance underwriting has not yet caught up to, and it's the thread that runs through every coverage gap discussed below.

How the covered-event definition in a standard cyber policy reads against a prompt injection loss

Diagram: The Coverage Gap: How Prompt Injection Falls Outside Standard Policy Triggers. Visualizes: Visualize a side-by-side comparison of two event types: a conventional cyberattack (credential theft / malware / perimeter breach) versus a prompt…

Almost every standard cyber policy conditions coverage on language like "security failure," "unauthorized access," or "computer attack." Each of those terms presumes a boundary the system defended and the attacker overcame. That presumption is the whole problem when the loss in question is a prompt injection.

When an LLM-based system is prompt injected, no credentials are stolen, no perimeter is breached, and no malware gets installed. The system receives what it interprets as a valid instruction, processes it as it would any other instruction, and produces an output. From the system's point of view, nothing went wrong technically. An insurer reviewing a claim on a standard form has a ready argument available: no covered security event occurred, because the AI simply did what it was asked to do, however deceptive the ask behind that instruction happened to be.

Some 2026-era endorsements close this gap directly. One carrier endorsement defines an "AI security event" as the failure of security of computer systems caused by any artificial intelligence technology, including through the use of machine learning or prompt injection exploits. Language like that names prompt injection as a covered peril rather than leaving a court or a claims adjuster to decide whether it fits inside "unauthorized access." But that endorsement has to be attached to the policy for the coverage to exist. The base form, without it, is built around a boundary-crossing requirement that a prompt injection loss typically doesn't satisfy, and most companies currently carry the base form, not the endorsement.

The objection that cyber insurance already handles this because it covers data breaches doesn't hold up cleanly either. If the policy's breach definition requires unauthorized system access as a precondition, a data exfiltration caused by prompt injection might not trigger privacy liability coverage after all. Many breach definitions carry that requirement, so the same boundary-crossing problem reappears in a different clause of the same policy.

The Second, Independent Coverage Problem for Agentic and Autonomous Systems

Even where a policy's trigger language is broad enough to fire, agentic and autonomous systems run into a second obstacle that has nothing to do with wording. Losses from these systems can occur independently of any conventional cyber compromise: hallucinations, flawed reasoning, unsafe delegation between AI agents, model drift, or an autonomous action taken without authorization can all produce significant financial harm with no network breach and no intrusion anywhere in the chain.

That independence matters because it undercuts the entire premise a cyber policy rests on. If there's no breach, no intrusion, and no security failure to point to, just a system that was manipulated or that reasoned its way into a bad outcome, a cyber policy has nothing in its structure for a claim to attach to. The policy isn't ambiguous in that scenario so much as inapplicable.

The problem compounds further for physical autonomous systems like warehouse or manufacturing robots. If a standard property or casualty policy does respond to a robot incident, it typically covers physical damage only, not the production losses that follow when a line shuts down because a robot malfunctioned. A prompt-injected robot that misbehaves without breaking anything, say, one that halts, misroutes, or acts erratically without causing physical destruction, generates exactly the type of loss most policies exclude by design.

The Mexican government breach, running from December 2025 through February 2026, shows how this plays out at scale. A single attacker used commercial AI platforms, Anthropic's Claude Code and OpenAI's GPT-4.1, to breach nine government agencies and exfiltrate hundreds of millions of records. The AI tools were the weapon in that attack, not the target, and no traditional intrusion technique was required to carry it out. Research tracking these incidents found that lateral movement appeared in eight of 21 documented multi-stage agentic AI incidents across 2025 and 2026, up from none in 2023, and a January 2026 paper on the promptware kill chain identified 21 multi-stage attacks that traversed four or more kill chain stages, including persistence and lateral movement. An event built this way can look, after the fact, like a sophisticated conventional intrusion. The initial vector was a prompt, not a stolen credential or a software exploit, and a forensic investigation has to establish that distinction before anyone can say which policy, if any, responds.

The 2026 Wave of AI Exclusions

Diagram: The 2026 AI Exclusion Wave: Who Moved and When. Visualizes: Show a compact timeline of the 2026 exclusion wave, placing these events in sequence: Fall 2025 — Berkshire Hathaway and Travelers begin filing AI exclusion language; January 2026…

Insurers have not waited for a court to resolve whether any of this ambiguous language covers a prompt injection loss. Carriers are rewriting their forms to remove AI exposure outright, and the 2026 renewal cycle is when most policyholders are encountering that change for the first time.

For several years, many companies carried what the market calls "silent AI" coverage: AI-related risk was implicitly covered under existing cyber and Tech E&O policies simply because those policies never mentioned AI at all, one way or the other. That silence is ending. Insurers are introducing AI-specific exclusions and revised policy forms ahead of the 2026 renewal season, and the shift is deliberate.

ISO form CG 40 47 01 26, released in January 2026, is the clearest example of how fast this can spread across the market. It applies to Coverage A and Coverage B of the standard commercial general liability policy, and it excludes bodily injury, property damage, and personal or advertising injury that arises out of generative artificial intelligence. Because it's a standardized ISO form, any carrier that adopts it pushes the same exclusion language into its book of business at once, before negotiating the change policy by policy.

Three of the largest commercial insurers in the United States moved the same way in early 2026. Berkshire Hathaway and Travelers began filing exclusion language as early as fall 2025, with Chubb joining them, and the exclusions took effect across carriers starting in early 2026 after state regulators approved the majority of those filings. D&O policies have seen some of the broadest language of all: several insurers introduced "absolute" AI exclusions in management liability coverage, purporting to exclude any claim arising out of the use, development, or deployment of artificial intelligence in any form. If a governance failure gets triggered by a prompt injection event, language that broad could leave a company's leadership personally exposed with no D&O backstop.

The practical consequence lands hardest on companies that haven't looked at their policy forms recently. If a company renewed in 2024 under silent-AI assumptions and hasn't reviewed its forms since, it is very likely uncovered today for a prompt injection event it could have filed a legitimate claim for two years ago. The market is moving toward more restriction: as companies push insurers to pay for more AI-related losses, insurers are responding with tighter exclusions and new sublimits.

Affirmative AI Coverage in the 2026 Market

Coverage built specifically for AI risk, including prompt injection, does exist in the 2026 market. You can't assume it comes attached to a standard renewal. It has to be sought out, carrier by carrier, line by line.

The carrier endorsement mentioned earlier, which defines an "AI security event" to include failures caused by prompt injection exploits, is affirmative coverage language in the fullest sense: it names the peril directly rather than leaving a claims team to argue over what "unauthorized access" was meant to cover. CFC updated its policy suite in June 2026 to introduce explicit AI-related language across seven of its policy lines, and it now names model hallucination, AI-generated content, and model drift as exposures the policies address head-on. Beazley added its own affirmative AI endorsement inside its cyber and Tech E&O policies on September 17, 2026.

Coverage built for physical autonomous systems looks different again. AXIS Insurance built a program just for autonomous robots, and it covers bodily injury and property damage caused by AI navigation or perception failures, physical damage that results when a cyberattack takes over a robot's controls, and production losses that follow a software update or sensor failure that takes a robot offline, even when no physical damage occurred. That last piece matters, because it's precisely the gap identified earlier: standard property forms pay for broken equipment, not for the production line that sat idle because a robot stopped working correctly.

None of this adds up to a single policy a company can buy and consider the matter closed. A single AI-driven event can implicate cyber coverage for a data breach, Tech E&O coverage for a product failure, and D&O coverage for a governance failure, all from the same incident, and affirmative coverage secured in one of those lines doesn't extend automatically to the others. Handling this well means coordinating placement across all three lines at once, not treating any one policy as sufficient on its own.

Underwriting Submissions for AI and Autonomous Systems

What a company gets covered for, and whether a claim actually gets paid after an incident, now depends heavily on the quality of its underwriting submission and how well it maintains the documentation behind it over time.

Underwriters writing cyber and Tech E&O coverage for AI-driven products have moved well past simple checkbox questionnaires. Where a product involves AI or machine learning, underwriters increasingly ask for documentation covering training data sources and quality controls, model validation and testing processes, bias testing and audit trails, explainability capabilities for any high-stakes output the system produces, and how AI-related liability is addressed in the company's own client contracts. When a company can produce structured governance documentation, it gets meaningfully better terms than one that can't. The submission sets the price and the scope of what gets covered, and a thin or vague answer on any one of those fronts changes the terms offered.

The stakes around accuracy in that submission are higher than they might appear. An insurance application is a representation the insurer relies on to price and issue a policy. If a renewal application asks whether a company uses AI and in what way, an answer that's inaccurate or incomplete about deployed autonomous systems gives the insurer grounds to rescind the entire policy the moment a claim comes in, regardless of whether the misstatement had anything to do with the loss itself.

Insurers are also beginning to ask directly about AI governance practices in renewal questionnaires, and some will exclude AI-related incidents from coverage where a company can't produce a documented risk assessment to back up its answers. Questionnaire answers from last year's renewal can go stale fast if a company has deployed new agentic capabilities since then and hasn't updated what it told its carrier. A company evaluating its exposure to prompt injection losses needs to treat its underwriting file as a living document, not a form filled out once a year, because that documentation decides whether a claim gets paid or rescinded after the fact.

Sources

  1. The Promptware Kill Chain: How Prompt Injections Gradually Evolved Into a Multistep Malware Delivery Mechanism