AI-enabled attacks are scaling: what the UK warnings mean for insurers (and their lawyers)
UK cyber authorities are increasingly explicit that AI is not creating an entirely new category of cyber risk so much as industrialising the old one: faster reconnaissance, more convincing social engineering, quicker vulnerability exploitation, and more efficient use of stolen data. The UK National Cyber Security Centre (NCSC) assesses that AI will almost certainly increase the volume and impact of cyberattacks in the near term, in particular a likely increase in reconnaissance and social engineering, and that lowering the barrier for less-skilled actors is likely to feed into the ransomware ecosystem.
The NCSC’s forward-looking assessment to 2027 ('Impact of AI on cyber threat from now to 2027') frames the growing gap between AI-enabled attackers and under-prepared defenders as a "digital divide" between organisations that keep pace with AI-enabled threats versus those that do not. It also highlights that the disclosure-to-exploitation window, which is already "days" for known vulnerabilities, will almost certainly compress further as AI-assisted vulnerability research and exploit development improves. In underwriting terms this is a frequency-and-speed problem because controls that rely on slow patch cycles, weak asset inventory, or thin monitoring become materially more loss-generative.
The NCSC also warns of “unsanctioned actions” and “human-like deceptive behaviour” by frontier AI models on the open internet, and stresses that “detection alone after the fact… will not be enough” calling for safeguards, real-time oversight, and response plans ('NCSC statement in response to recent incidents resulting from frontier AI evaluations'). This matters because insureds are increasingly embedding agentic tooling into finance, IT and customer workflows. This can create new pathways for fraud, data leakage and outage that may sit awkwardly across cyber, crime and liability towers. The legal position on how such losses are allocated across these towers remains unsettled and in any event will depend on the language used in specific policy wordings, most of which were drafted before the AI boom. insurers should not assume that existing wordings will produce clear answers.
Coverage implications for social engineering and fraud
A recent episode of Today in Tech describes attackers using AI, social engineering, and legitimate business tools to make malicious activity look like normal work by impersonating vendors, manipulating invoice/payment conversations, exploiting shared inboxes, and targeting business processes rather than perimeter defences. For insurers, this pushes claims and coverage disputes towards questions of authorisation, and whether a loss is best characterised as a cyber breach, social engineering fraud, or funds transfer fraud (and how exclusions and conditions interact).
AI-assisted target selection and planning are now being reported in physical-world crime. The Observer reports expert concerns that thieves are using chatbots to identify vulnerable targets, value items, and even forge provenance documentation. AI can reduce planning friction and improve target selection. This should be on the radar for fine art, specie, jewellers’ block, cargo and high-net-worth lines, especially where policy pricing assumes “bespoke, high-skill” offender behaviour rather than commoditised planning. Our insurance sector team can help assess how these emerging risks interact with existing policy wordings.
Disclaimer: This article is provided for general information purposes only and does not constitute legal advice. It should not be relied upon as a substitute for specific legal counsel. The law and regulatory landscape in this area are evolving, and the application of the principles discussed will depend on the particular facts and circumstances of each case. No liability is accepted for any reliance placed on the content of this article.
Contents: The Word, September 2026
- Insurance insights: The Word, September 2026
- Britain's e-scooter crisis: What insurers need to know
- War risk insurance: why ancient clauses are failing modern conflict
- ChatGPT and the FCA: regulation comes knocking?
- Claims definitions: Why the FCA's latest focus matters
- A 'tidal wave' of PFAS for AI
Contact
Jeanette Flowers
Claims Handler
Jeanette.Flowers@brownejacobson.com
+44 (0)330 045 2178
Tim Johnson
Partner
tim.johnson@brownejacobson.com
+44 (0)115 976 6557