Skip to main content
Share via Share via Share via Copy link

AI-enabled attacks are scaling: what the UK warnings mean for insurers (and their lawyers)

30 September 2026
Jeanette Flowers

UK cyber authorities are increasingly explicit that AI is not creating an entirely new category of cyber risk so much as industrialising the old one: faster reconnaissance, more convincing social engineering, quicker vulnerability exploitation, and more efficient use of stolen data. The UK National Cyber Security Centre (NCSC) assesses that AI will almost certainly increase the volume and impact of cyberattacks in the near term, in particular a likely increase in reconnaissance and social engineering, and that lowering the barrier for less-skilled actors is likely to feed into the ransomware ecosystem. 

The NCSC’s forward-looking assessment to 2027 ('Impact of AI on cyber threat from now to 2027') frames the growing gap between AI-enabled attackers and under-prepared defenders as a "digital divide" between organisations that keep pace with AI-enabled threats versus those that do not. It also highlights that the disclosure-to-exploitation window, which is already "days" for known vulnerabilities, will almost certainly compress further as AI-assisted vulnerability research and exploit development improves. In underwriting terms this is a frequency-and-speed problem because controls that rely on slow patch cycles, weak asset inventory, or thin monitoring become materially more loss-generative.

The NCSC also warns of “unsanctioned actions” and “human-like deceptive behaviour” by frontier AI models on the open internet, and stresses that “detection alone after the fact… will not be enough” calling for safeguards, real-time oversight, and response plans ('NCSC statement in response to recent incidents resulting from frontier AI evaluations'). This matters because insureds are increasingly embedding agentic tooling into finance, IT and customer workflows. This can create new pathways for fraud, data leakage and outage that may sit awkwardly across cyber, crime and liability towers. The legal position on how such losses are allocated across these towers remains unsettled and in any event will depend on the language used in specific policy wordings, most of which were drafted before the AI boom. insurers should not assume that existing wordings will produce clear answers.

Coverage implications for social engineering and fraud

A recent episode of Today in Tech describes attackers using AI, social engineering, and legitimate business tools to make malicious activity look like normal work by impersonating vendors, manipulating invoice/payment conversations, exploiting shared inboxes, and targeting business processes rather than perimeter defences. For insurers, this pushes claims and coverage disputes towards questions of authorisation, and whether a loss is best characterised as a cyber breach, social engineering fraud, or funds transfer fraud (and how exclusions and conditions interact).

AI-assisted target selection and planning are now being reported in physical-world crime. The Observer reports expert concerns that thieves are using chatbots to identify vulnerable targets, value items, and even forge provenance documentation. AI can reduce planning friction and improve target selection. This should be on the radar for fine art, specie, jewellers’ block, cargo and high-net-worth lines, especially where policy pricing assumes “bespoke, high-skill” offender behaviour rather than commoditised planning. Our insurance sector team can help assess how these emerging risks interact with existing policy wordings. 

Disclaimer: This article is provided for general information purposes only and does not constitute legal advice. It should not be relied upon as a substitute for specific legal counsel. The law and regulatory landscape in this area are evolving, and the application of the principles discussed will depend on the particular facts and circumstances of each case. No liability is accepted for any reliance placed on the content of this article.

Contact

Contact

Jeanette Flowers

Claims Handler

Jeanette.Flowers@brownejacobson.com

+44 (0)330 045 2178

View profile
Can we help you? Contact Jeanette

Tim Johnson

Partner

tim.johnson@brownejacobson.com

+44 (0)115 976 6557

View Profile Connect on Linkedin
Can we help you? Contact Tim

You may be interested in