Marsh Re’s Anthony Cordonnier and Erica Davis on how advances in AI could impact the cyber (re)insurance market
Artificial intelligence is changing cyber risk, but not in the way most headlines suggest. It is not creating entirely new classes of attack. The more immediate shift is simpler, and more consequential for carriers: AI is compressing timetables. It is scaling familiar tactics, and helping attackers find and exploit known vulnerabilities faster, which means cyber exposures are moving closer to machine speed.
That has real implications for how losses emerge. If time-to-exploit keeps shrinking, the window for detection and patching narrows with it. Some events may become more front-loaded, with faster propagation and quicker loss crystallisation, particularly where security hygiene is weak. That said, cyber will remain long-tailed in important respects. Litigation, regulatory action, complex forensics and coverage disputes do not move at machine speed. The profile is mixed: faster loss emergence in some scenarios but claims development and resolution that can still take years.
The bigger question is what impact this has on catastrophe potential. AI-enabled vulnerability discovery increases the probability of fast-moving events touching widely deployed software, critical shared services or concentrated dependencies. These are the scenarios that turn ordinary cyber losses into event-like behaviour, with clustering across policyholders in a compressed window. The issue is not simply severity. It is correlation, and whether program mechanics reflect how modern cyber events actually unfold.
For cedants, that creates a clear reinsurance agenda. Catastrophe and portfolio models should be interrogated for where accumulation sits, including technology dependencies and common single points of failure. Program structures should be tested against the possibility that some buyers will conclude they need materially more protection as loss clustering becomes more plausible. Event definitions, where used, should align with realistic outbreak and service disruption narratives. Additionally, coverage intent should be kept clear, so that AI-related loss drivers do not become a source of unintended ambiguity inside cyber wordings.
Reinsurance structures are also more flexible than they have been for years, and cedants should be deliberate about the trade-offs they are making. The balance between proportional and non-proportional cover, where attachments and limits sit, how reinstatements and aggregation mechanics behave in fast-moving scenarios: these are key decisions. In our experience, reinsurers are listening carefully and showing genuine flexibility where the structure is transparent and aligned to the underlying exposure.
At Marsh Re, we support this with portfolio diagnostics, scenario analysis and accumulation mapping, underpinned by bespoke analytics and modelling. The aim is to help clients form a clear view of what they are protecting and why, then translate that into market-leading structures.
Cyber reinsurance needs to remain fit for purpose as the risk moves to a higher tempo. That means clear decisions on where limits sit, how losses aggregate and how the program supports the underwriting strategy it was built to optimise.