Get a Demo
Contact Sales

AI, Cyber, and the opportunity in P&C to not repeat history

Blog

We won’t begrudge you with another tale about “how rapidly AI is changing the landscape in P&C”. It’s evident in every conversation happening in every boardroom, at every carrier, in every corner of the world.

How do we use it, how do we integrate it, how will it make our operations better, how do we measure the ROI, how do we track it, how do we know the risk, how do we regulate it, how do we control it.

AI drift, unvalidated data, hallucinations, and misrepresentations are the new frequent flyers of litigation. It’s made carriers weary. Agentic has chops. But it also comes with new levels of risk and exposure, and new categories of considerations for how carriers assess it internally and how it affects them externally.

Which… yeah. We’ve seen this show before, folks. Despite the word "unprecedented" threatening to bury us alive.

In the early 90s (yeah those days, kids), the first versions of Cyber Liability worked their way into the market. Quiet at first—’digital media and data-processing errors’ became minor add-ons to existing GL and E&O policies. There were exclusions, of course, for things like regulatory infractions and rogue employees, but little by little this new exposure took shape.

Then the dot.com boom pulled a Kool-Aid Man mid-decade, and there was no hiding in the fine print anymore. In April of ‘97, roughly 20 people showed up to a convention event in Honolulu aptly named “Breach on the Beach”, where broker Steve Haase unveiled the first standalone cyber policy with a (wait for it) splash. Coined ‘Internet Security Liability’, it was solely backed by AIG after Haase spent over two years finding a carrier to write it.

Later, he’d admit there were exactly *zero* actuarial studies of internet commerce to scope it against. It was all his educated guess, and a lone carrier willing to bet on it.

Not that it mattered. The gates had opened.

Companies navigating an unknown liability, with a low appetite for risk, knew they could buy some level of insulation from it. And market demand doesn’t go quietly.

So, the industry gave it to them… sort of. Even with Haase’s leap into uncharted waters, “Silent Cyber”—or non-affirmative cyber exposure if you like industry jargon—remained the name of the game for years. Implied coverage for cyber exposures still sat, unassuming, within traditional liability policies without ever explicitly outlining what was and wasn’t applicable. 

The industry lived in that gray area (industries LOVE gray areas), until it couldn’t.

Hello, 2017 👋

The ever-infamous $1.4B NotPetya ransomware attack (and subsequent litigation over the invocation of “act of war” exclusions) gave “Silent Cyber” a name. Major underwriting syndicates like Lloyd's of London reacted with mandates for explicit exclusions and standardized practices. This forced businesses to carefully scrutinize the exact wording of their own cyber coverage. It also forced carriers who’d been perfectly content to straddle the line between “we offer it” and “we offer it 😉” to finally make a choice.

Black and white: in or out. 

As of this year, Cyber Insurance is a $33B market that’s expected to reach a dizzying $240B by 2034 (We wonder why!?). An entire market was created because a new thing existed, which introduced a new category of risk. And despite a desperate clinging to indecisiveness, both carrier and company were forced to pick a side.

It all took 20 years.

AI didn’t even give us 20 months.

There is an inevitable catalyst on the horizon that will force the same questions around AI liability, how it affects underwriting and premiums, and what coverage looks like when it's AI that causes a loss. (One could argue the AI exclusions rolled out by Verisk in January of this year are the first indicators). 

That’s the show we’ve seen before.

But there is a unique opportunity here that didn’t exist that day in Honolulu. AI is multi-faceted. It’s not just a new liability line item, but an entirely new collection of technologies that has applications for every facet of how society lives, works, and operates. Which means carriers have the ability to develop frameworks for integrating, operating, assessing, quantifying, and mitigating the risks of AI internally before it ever affects them externally. Because every P&C carrier in the market is exposed on multiple fronts regardless of where they sit on the adoption spectrum.

We’ve all heard the “junk in, junk out” tropes and how AI is “only as good as the data you feed it.”

We’d argue the reality sits a layer deeper. AI is only as good as its integration is holistic.

Developing AI as a core tenant of technical infrastructure is where the world is going (we are readily available for a healthy debate with anyone who would argue the contrary), so “let’s try AI in just [insert department or function here] and see how it goes” is, for all its good intentions, a hefty step backwards. And an attempt to live in a gray area that’s rapidly dissipating.

There is no method that exists now, or will ever, to quantify the full impact of AI if it’s cordoned off from core architecture.

And yet, the piecemeal approach is the trap a lot of P&C is walking into right now. "Does this tool work?" will never return the same impact as "does this solution know what the rest of my stack is doing, and does my stack know what this solution is doing?". The black box approach can’t cut it, because you can’t understand the impact of AI if you don’t have visibility into what it touches.

The considerations for a commercial carrier looking at how AI liability affects underwriting and the ones for an auto carrier assessing the use of AI internally might seem worlds apart. They’re not. Because if the auto carrier can’t efficiently and quantifiably speak to the total impact of AI across their entire organization, they are looking at some very uncomfortable renewal conversations with their own reinsurers. 

Back to the beach, for a moment.

Steve Haase admitted he had no actuarial data. What he had was a way to treat a brand-new risk as a singular thing instead of a dozen disconnected ones. One investment made in full instead of twenty small hedges nobody could add up. 30 years of hindsight shows it was the right side to be on. 

AI isn’t giving the industry the luxury of time, but speed isn’t the lesson to be learned here. When the dust settles, no one will remember “who moved the fastest.” The orgs that thrive in hindsight will be the ones that saw the opportunity AI presents for what it was: the chance to skip 20 years of trial and error and make the inevitable part of the infrastructure.

Seems like the side worth picking. 

Customer story

When we were evaluating whether to build or buy, Snapsheet stood out as the clear choice. It offered the capabilities we needed out of the box, but also the flexibility to create anything beyond that to best fit how we work.

Sam Rea
Chief Technology Officer, Aspire