Artificial intelligence is creating an insurance problem that cannot be neatly contained inside a cyber policy. CyberCube has introduced six new AI Event Families and an I2T2 framework—Information, Intelligence, Tactics and Technology—to help insurers, brokers and risk managers evaluate how AI could generate losses across multiple lines of coverage.
AI is rapidly moving from an assistive technology into systems capable of making decisions, generating content and executing operational tasks. For insurers, that creates an uncomfortable question: when an AI system causes a loss, which policy responds?
Cyber risk analytics provider CyberCube is attempting to provide a more structured answer.
The company has unveiled six new AI Event Families alongside an I2T2 framework designed to help carriers, brokers and risk managers assess and quantify AI-driven insurance risk. The framework is detailed in CyberCube’s new report, Machine State of Mind: A Framework for Quantifying AI-Driven Insurance Risk.
Its central argument is that AI should not simply be treated as the next chapter of cyber risk.
The I2T2 framework divides AI’s potential impact on insurance into four dimensions: Information, Intelligence, Tactics and Technology. The model is intended to give insurers a common way to analyze how AI systems can create or amplify losses, including situations where no cyberattack or malicious actor is involved.
That distinction could become increasingly important as enterprises deploy generative AI, autonomous agents and machine-learning systems across business operations.
A conventional cyber event might involve stolen credentials, ransomware or data exfiltration. AI introduces another category of failure: a system can operate according to its technical design and still produce harmful results.
A generative AI model could, for example, produce inaccurate information that contributes to a financial loss. An automated system could make an inappropriate decision at scale. An AI-enabled workflow could amplify a small error across thousands of transactions or customer interactions.
In such cases, the underlying event may have little resemblance to a traditional cyber incident.
CyberCube argues that AI-related losses could therefore extend across Errors & Omissions (E&O), Technology E&O, Cyber, General Liability and Directors & Officers (D&O) insurance. The challenge is not merely identifying the risk; it is determining how responsibility and coverage could be allocated when a single AI-driven event touches multiple policies.
That makes AI a potentially significant challenge for underwriting.
The insurance industry has already encountered a similar problem with silent or non-affirmative cyber risk, where cyber-related exposures existed inside policies that were not explicitly designed to cover cyber events. Insurers spent years working through how cyber exposures should be identified, priced, excluded or affirmatively covered.
AI could create a broader version of the same problem.
Unlike cyber risk, however, AI is not inherently adversarial. An attacker does not need to compromise an AI system for it to generate a loss. Hallucinations, flawed outputs, inappropriate automation and other forms of model failure can occur within normal system operation.
That changes the risk equation.
It also means that traditional cybersecurity controls alone are unlikely to provide a complete solution. Organizations adopting AI will need to consider model governance, data quality, human oversight, system permissions, testing, auditability and the boundaries placed around autonomous decision-making.
For insurers, these factors could eventually become underwriting considerations.
CyberCube’s new approach arrives as businesses are rapidly experimenting with AI agents and generative AI systems. Microsoft, Google, Amazon and Salesforce, among other major technology vendors, are embedding AI capabilities into enterprise software, while companies across financial services, healthcare, manufacturing and professional services are incorporating AI into operational workflows.
As adoption expands, the potential number of AI-related failure points increases.
The six new AI Event Families are intended to provide a more granular way of categorizing those events. CyberCube says the framework can help the industry distinguish where AI overlaps with cyber risk and where AI creates fundamentally different exposures.
That distinction could influence how insurers develop products and pricing models.
For brokers and risk managers, the implications are equally practical. A company may have a robust cyber insurance program while still carrying significant AI-related exposures through professional liability, product liability, management liability or other policies. Understanding those boundaries could become essential as AI moves deeper into core business processes.
The bigger issue is that AI risk is evolving faster than many insurance frameworks were designed to handle.
CyberCube’s I2T2 model does not claim to settle how every AI-related loss should be insured. Instead, the company presents it as a starting point for a more systematic approach to evaluating emerging exposures.
That may be its most important contribution.
Insurance depends on turning uncertainty into measurable risk. As AI changes how information is produced, decisions are made and business processes operate, insurers will increasingly need models that capture failures beyond conventional cyberattack scenarios.
The companies that develop those models early could have an advantage in a market where AI-related claims are still difficult to categorize—and where the boundaries between technology, professional liability, cyber and operational risk are becoming increasingly blurred.
Market Landscape
The emergence of AI risk is creating a new challenge for the property-and-casualty insurance industry: determining whether AI should be treated as a standalone risk category or as an exposure embedded across existing lines.
Cyber insurance provides a useful precedent. The industry spent years addressing non-affirmative cyber exposure as organizations adopted connected technologies faster than policy language evolved.
AI may prove more complicated because its effects can be both malicious and non-malicious.
A cyberattack generally involves an adversary. An AI incident may arise because a model produces incorrect information, an automated system makes a poor decision, or an AI workflow scales an otherwise manageable error.
That creates potential exposure across cyber, E&O, technology E&O, general liability and D&O.
For enterprise risk teams, the practical takeaway is that AI governance should extend beyond security. Organizations should map where AI is being used, identify which decisions are automated, establish human oversight for consequential processes and understand which insurance policies could respond to resulting losses.
For carriers, the opportunity is to develop more precise underwriting models and coverage products before AI-related loss patterns become widespread enough to force reactive changes.
CyberCube’s I2T2 framework is positioned within that emerging effort to turn a rapidly changing technology risk into something insurers can categorize and ultimately quantify.
Top Insights
- CyberCube’s I2T2 framework categorizes AI risk across Information, Intelligence, Tactics and Technology, giving insurers a structured approach to emerging exposures.
- Six new AI Event Families expand CyberCube’s risk modeling as autonomous systems create potential losses beyond conventional cyberattacks and security incidents.
- AI failures can trigger E&O, Technology E&O, Cyber, General Liability and D&O exposures, complicating claims allocation across traditional insurance policies.
- Unlike many cyber incidents, AI can cause losses without malicious actors, including hallucinations, flawed outputs and unintended automated decisions.
- Enterprise risk teams may need AI governance and insurance reviews together as generative AI and autonomous systems become embedded in business operations.
Power Tomorrow’s Intelligence — Build It with TechEdgeAI











