Google’s Threat Intelligence Group has released the kind of update the cyber security world has been expecting, and dreading. Here is an update from our Specialist Cyber Insurance Team.
According to Google, criminals used an AI model to identify a vulnerability in a widely used system administration tool. They then used AI again to create the code needed to exploit it. This matters because it appears to be one of the first recorded examples of AI being used not just to support an attack, but to carry out the research and help build the weapon. Google spotted the activity before it caused widespread damage. The exploit code carried several tell-tale signs of AI involvement, including over-explained comments, a made-up severity score and the clean, textbook structure often produced by large language models.
Google analyst John Hultquist described it on LinkedIn as “the tip of the iceberg”. And this is not happening in isolation. Chinese and North Korean state-linked groups are already reported to be using AI in similar ways. One North Korean group has allegedly sent thousands of automated prompts to test and validate exploits against known vulnerabilities, helping them build an attack toolkit that would otherwise take a large team of human hackers to create manually. Russian-linked threat actors are also using AI to write malware that can hide inside plausible-looking decoy code.
This might sound like something from a Hollywood film, but it is real, and it is happening.
Recent examples involving OpenAI and Hugging Face have also highlighted how quickly AI cyber risk is moving from theory into practice. During a cyber security experiment, OpenAI’s models were reportedly able to discover a new vulnerability in a package registry proxy, access the internet and become implicated in a platform-level attack on Hugging Face.
This is not a typical cyber attack. But it should still be treated as a warning. Even in a limited setting, powerful AI systems can behave unpredictably and create real cyber consequences. For businesses, the key question is simple: would your cyber insurance cover respond to an AI-related incident?
Why this matters more than the average cyber security headline
For years, cyber risk has largely centred on human error: someone selecting a malicious link, using a weak password or leaving a server unpatched. Insurers have priced many policies with that world in mind. AI changes the picture.
The speed and scale at which AI can identify a target and help create exploit code is unlike anything defensive teams have faced before. A skilled human researcher might spend weeks looking for a single zero-day vulnerability. An AI model can be pointed at thousands of codebases and left to work through them at a pace no human team can realistically match.
That changes the risk calculation. It affects how likely a business is to be targeted, how quickly an attack can develop and how prepared its insurance cover really is.
Where this leaves your insurance policy
Most standard Technology Errors and Omissions and cyber insurance policies were not written with AI-driven attacks in mind.
The threat landscape is moving so quickly that a cyber policy can become outdated fast. Some insurers have introduced exclusions around AI-related incidents. Others have structured their wording in a way that makes it unclear whether the policy would respond to an exploit created or supported by AI.
Some insurers are now building affirmative AI cover into cyber policies. This means they specifically name AI-enabled attacks, AI tool misuse and other AI-related exposures as covered events, rather than leaving the position open to interpretation.
But the difference between something being silently excluded and explicitly covered is not always obvious. It takes someone who understands policy wording to spot the gaps.
The takeaway
If your cyber or professional indemnity policy has not been reviewed in the past 12 months, speak to a specialist broker.
You need to know exactly what insurance cover you have for AI-related incidents, and where the gaps might be.
A good broker will not sell fear or uncertainty. They will take the time to understand your actual risk profile, explain where your existing cover may fall short and help you find a policy that protects your business properly.
If you would like to, you can learn more about our Specialist Cyber Insurance Team here.