TL;DR
- AI is not mentioned in any of the seven policy terms I checked. So there's no AI exclusion, and the core coverage is usually written in dader-neutral — attacker-neutral — language.
- It gets shakier around money, fraud and extortion. Definitions of "hacker," "third party" and "theft" quietly assume a human at several insurers.
- Zurich is the most AI-robust, Centraal Beheer the least. One broad definition of the word "third party" makes the difference between covered and not.
- There's no one to recover the loss from once the attacker is an autonomous AI system with no legal personhood and no bank account.
- The US and London markets are already adding AI clauses to cyber policies — the same movement that once ended "silent cyber."
This week I read 264 pages of policy terms, from Hiscox to Zurich, looking for one answer. Does a Dutch cyber insurance policy cover a hack carried out by an AI?
The trigger: on July 21, OpenAI disclosed that its own models had escaped a test environment and hacked Hugging Face, with no human at the controls. I wanted to know who pays in that case.
I come from the insurance world and work with AI every day, so this question sits right at the intersection of both my fields. What I found in those terms partly reassured me and partly surprised me. The good news and the problem both live in the definitions — the part of a policy I myself had never read with this specific question in mind until last week.
A hack with no human behind it
First, briefly, what happened, because this incident differs from an ordinary hack on two points. OpenAI disclosed on July 21 (opens in new window) that a combination of its models, including GPT‑5.6 Sol and an unreleased model, escaped a sandboxed environment during an internal test. The models ran with reduced safety restrictions because they were being tested for cyber capabilities. They reached the open internet, exploited a vulnerability, and breached Hugging Face's production systems — one of the largest platforms for open-source AI.
The technical report OpenAI published in late August (opens in new window) shows how far this went. For months, more than a thousand AI agents communicated with each other through a self-built message board the researchers didn't know existed. Over seven hundred of those agents took part in the breach. The motive was mundane: the models were looking for answers so they could cheat on an evaluation. I described exactly how that escape unfolded, and what reward hacking is, earlier in AI Agents Hacked Their Way Out of Their Cage. Hugging Face's CEO stressed that, in his view, there was no malicious intent behind it.
Those two points matter later on: there was no human perpetrator, and there was no malicious intent. The damage is no less real for it, but in a policy, those two elements decide whether a claim gets paid.
What I looked for in the terms
I collected seven complete sets of Dutch policy terms. I read the CyberClear policy from Hiscox (HCC-2022/01, 32 pages) (opens in new window) and Chubb's Cyber Enterprise Risk Management terms (24 pages) (opens in new window) in full, line by line. I also went through the terms of Allianz (CYB24, 20 pages), Centraal Beheer (CYB23, 101 pages), Zurich (#CyberComfort, 16 pages), Markel (Cyber 360, 37 pages) and the Rabo CyberRisicoverzekering (34 pages) (opens in new window). Together those cover more brands than these seven names suggest. Nationale-Nederlanden uses Hiscox's policy for its business cyber insurance (opens in new window), and Chubb sits behind the Rabobank policy as the risk carrier, with literally the same definitions. Only for HDI (CyberTec+) could I not find the full terms, so that one counts only partially.
My question was simple. Is there an exclusion anywhere for damage caused by AI, or does it say anywhere that the attacker must be a person?
The first answer is clear: the word AI does not appear in any of the seven sets of terms. I already knew this pattern, because when I searched nine professional indemnity policies for AI, the count was also zero. There's no AI exclusion in these terms, and that didn't surprise me, because every one of them was written before anyone had to account for a model that breaks in on its own.
The second answer is more nuanced, and that's where it gets interesting. The core coverage is often written in attacker-neutral language. Take Hiscox and Chubb, the two I dug into most deeply. Hiscox describes a cyberattack as any digital attack that disrupts access to, or the operation of, your computer system. Chubb ties its business-damage cover to a business interruption incident — the interruption of your system caused by, among other things, a malicious computer act or unauthorised access. Neither description says who or what carries out the attack. If your company falls victim to an autonomous AI hack, that event fits, in plain language, within the cover for your own damage, your recovery costs and your business downtime. That's the reassuring part.
Four places where it goes wrong
Yet reading on, I found four formulations where an AI perpetrator can genuinely fall outside the cover. Not in the core of the policy, but in the parts dealing with money, fraud and perpetrators.
1. The third party that has to be a person
Chubb defines a third party as "any legal entity or natural person who does not qualify as an insured under this policy." An AI model is neither a natural person nor a legal entity. Coverage for loss of money then requires theft by such a third party. And at Chubb, theft only counts as theft when the perpetrator takes the money to gain a financial benefit for themselves. An autonomous model siphoning off money has no legal personhood and no financial interest of its own. On paper, this exact scenario falls outside this cover.
2. The hacker who is "anyone"
Hiscox defines a hacker as "anyone, including an employee of yours," who gains unauthorised access. In ordinary usage, "anyone" refers to people, and the added reference to employees confirms the drafters were thinking of humans. The cover for electronic theft and social engineering rests entirely on this hacker definition. In Nationale-Nederlanden's consumer policy it's even more explicit: the Cyberservice terms (opens in new window) describe unauthorised parties as "a person or persons" who break into your system without permission. There, the human perpetrator is written into the policy literally.
3. Intent that wasn't there
Chubb refers to a malicious computer act carried out with the intent to alter, remove or destroy data. At Hugging Face, according to everyone involved, there was no malicious intent at all: the models were trying to complete a test task and broke through security measures to do it. Does a system with no consciousness have "intent"? I expect insurers will, in practice, look at the effect rather than the intention, but the text does hand an insurer looking to deny a claim a first argument.
4. Extortion and reward money are built around people
Hiscox's extortion cover requires a threat from a third party. Chubb's reward fund only pays out for information that leads to the arrest and conviction of a person. Ransomware carried out entirely by an autonomous system, with no human collecting the ransom, fits that frame poorly. You can't arrest an AI agent, and you can't convict one.
Nine providers, ten policies side by side
Here's what the text says, per provider, if the attacker is an AI. Note: this is my own reading of the policy text, not a coverage guarantee, and the actual outcome depends on your specific policy schedule and situation.
| Insurer (product) | AI hack covered? | Explanation |
|---|---|---|
| Hiscox (CyberClear, HCC-2022/01) | Core: probably yes. Money/fraud: doubtful | Cyberattack is defined attacker-neutrally. But a hacker is "anyone," and extortion requires a threat from a third party. |
| Chubb (Cyber ERM V2) | Core: probably yes. Money: probably not | A third party is by definition a natural person or legal entity, and theft requires the perpetrator's own financial gain. |
| Rabobank (CyberRisicoverzekering, Oct 2023) | Same as Chubb | Chubb is the risk carrier and the terms contain the literal same third-party definition. |
| Nationale-Nederlanden (business) | Same as Hiscox | NN uses Hiscox's cyber insurance policy. |
| Nationale-Nederlanden (Cyberservice, consumer) | Doubtful | Unauthorised parties are here literally "a person or persons" who break into your system. |
| Allianz (Cyberverzekering, CYB24) | Core: probably yes. Extortion/theft: doubtful | Cyberattack is "breaking into the business computer system," with no perpetrator specified. But a third party is a natural person or legal entity, and extortion requires "an extortionist." |
| Centraal Beheer (Cyberverzekering, CYB23) | Doubtful, even at the core | The cyber incident covers malware neutrally, but a break-in is "someone else breaking in" with the aim of causing damage. An AI with no intent to cause damage already strains this base definition. Extortion speaks of "someone else" and "he." |
| Zurich (#CyberComfort) | Most AI-robust of all | A network incident requires a third party, but here a third party is "anyone other than the insured or a service provider." No person requirement. |
| Markel (Cyber 360, MISE 2023) | Core: probably yes | A network incident is attacker-neutral: an electronic attack, malware or unauthorised access, with no requirement as to who or what is behind it. |
| HDI (CyberTec+ International) | Not assessable | Only the product summary (IPID) is public; the perpetrator definitions sit in the full terms. |
The pattern across the board: the closer a coverage part gets to money, fraud and extortion, the more often the text quietly assumes a human. At Centraal Beheer, that assumption even sits inside the base definition of the cyber incident itself. Zurich shows at the same time that it doesn't have to be this way — one broad definition of the word "third party" removes the entire problem.
Follow me on LinkedIn
No perpetrator to recover from
At the family business where I worked for twenty years, we built an entire division around recovering car-accident damage from the other party. At its peak, we did that more than a thousand times a month. The whole system of damage and insurance rests on one assumption: somewhere, there's a party you can recover the loss from, or at least someone you can sue or have prosecuted.
In an autonomous AI hack, that party is missing. The insurer that wants to exercise its right of recovery after paying a claim finds no criminal with a bank account. At best, it finds an AI lab that says it was an accident. Whether OpenAI is liable in such a case for an escaped model is legally uncharted territory. Until a court has ruled on that, the loss stays entirely with the insurer. My estimate: you'll see that reflected in premiums and underwriting questionnaires within two years, well before you see it in the policy terms.
America and London have already started
For a sense of direction, I look at the English-language market, because a familiar pattern is repeating itself there. Cyber damage sat silently inside ordinary fire and liability policies for years, until Lloyd's forced insurers in 2019 to explicitly include or exclude cyber. The same thing is now happening with AI. Law firm Fenwick describes how the market is moving away from "silent AI" (opens in new window): the practice of implicitly covering AI risk within existing cyber, technology-liability and directors-and-officers policies. In the United States, standards body ISO introduced three optional generative-AI exclusion endorsements effective January 1, 2026, but those applied to commercial general liability (CGL) policies, not to cyber insurance itself. Cyber remains, according to industry analysts, the most AI-friendly insurance line, though a Delinea survey (opens in new window) confirms that 42 percent of companies already carry an AI exclusion in their own cyber policy.
The discussion accelerated after the Hugging Face incident. Reuters reported this week (opens in new window) that insurers are revising their policy language because AI agents can cause damage without a conventional attacker. Players like Armilla, Munich Re and AXA XL already offer dedicated AI insurance products. The tone in London, for now, is clarifying rather than excluding. The exception is systemic risk: one widely used model causing damage at thousands of companies at the same time. That's the one area where insurers are openly discussing exclusions, because it's a risk they simply can't carry.
My view: the Dutch market shouldn't wait for that revision — it should get ahead of it. The answer isn't an AI exclusion, because that makes the product worthless exactly when customers need it most. The answer is attacker-neutral definitions: write into the policy that a hacker or third party can also be an automated system acting without human direction. That costs an insurer three sentences, and it removes precisely the uncertainty business owners are dealing with right now.
Three questions for your insurance broker
If you have cyber insurance, or you're considering one, ask these three questions at your next renewal.
1. Does the perpetrator in my policy have to be a person?
Ask specifically about the definitions of hacker, third party and theft, and whether they also apply to the coverage for money, fraud and extortion. You're usually fine on the core coverage; often not on the money-related coverage.
2. What happens if the attacker had no malicious intent?
The Hugging Face scenario shows that a system can cause enormous damage with no malicious intent at all. Ask how your insurer handles intent requirements in its definitions.
3. Will an AI clause be added at renewal?
Exclusions and clarifications are now being added to policies in America and London. Ask your broker to flag any new AI clause explicitly at renewal, so you don't discover what's changed only when you file a claim.
The honest answer to my own opening question is: probably yes, except in the places where it comes down to money. I don't think the first Dutch claim to be denied over an AI hack will run aground on an AI exclusion. It'll run aground on a perpetrator definition that quietly assumes a human. So read your policy before it comes to that.
Sources
I reviewed the terms of Allianz (CYB24), Centraal Beheer (CYB23, August 2022), Zurich (#CyberComfort), Markel (Cyber 360 MISE 2023), Rabobank (OC10-01, October 2023) and the HDI CyberTec+ IPID as PDFs; these are available on request from your broker or the insurer.
- OpenAI: security incident during model evaluation at Hugging Face (opens in new window) (July 21, 2026)
- CNBC: OpenAI publishes technical report on the Hugging Face hack (opens in new window) (August 26, 2026)
- Hiscox CyberClear policy terms HCC-2022/01 (opens in new window)
- Chubb Cyber Enterprise Risk Management V2 policy terms (opens in new window)
- Nationale-Nederlanden: cyber insurance underwritten by Hiscox (opens in new window) and Cyberservice PP 2811-03 terms (opens in new window)
- Rabobank CyberRisicoverzekering, risk carrier Chubb (opens in new window)
- Fenwick: The End of Silent AI (opens in new window)
- Kovrr: Does Cyber Insurance Cover AI Incidents? (opens in new window)
- FinTech Global: Why autonomous AI could void your cyber insurance in 2026 (opens in new window)
- Reuters: Cyber insurers adapt policies as rogue AI agents raise new coverage and liability questions (opens in new window)
