Link to main version

70

Insurers argue over who will bear the risk of artificial intelligence

There are three categories of risks related to artificial intelligence

Снимка: Shutterstock

Insurers do not have a single opinion on which policies should cover risks related to artificial intelligence (AI) - even against the background of its use by hackers for cyberattacks. This was clear from the statements of participants in the NetDiligence Digital Risk Summit conference.

The speakers at the forum in Philadelphia did not agree on whether the risks related to AI are primarily a cybersecurity issue, a matter of liability of governing bodies (directors and senior managers - D&O) or a new type of risk for which the sector has yet to find an appropriate solution, writes the ag. Reuters.

“There are so many things that can be accounted for outside of the cybersecurity realm that I have come to the conclusion that this is more of a directorship (D&O) liability issue“, said Gail Arkin, senior vice president and general counsel at Berkley Cyber ​​Risk Solutions.

Arkin noted that cyber insurance does not cover issues such as third-party infringement, unauthorized use of data or bias in software programs. The directors are advised to develop policies for the use of AI and to hire teams to monitor its application.

Tim Nazaro, global manager of “Digital Products“ at Hartford Steam Boiler, divides AI-related risks into three categories.

The first includes security and privacy risks, such as the leakage of personal data through an AI tool. He said the company is responsible for this and that “this risk should be clearly covered by a cyber insurance policy“.

The second category affects other types of insurance; for example, if an AI tool discriminates during the hiring process, the case would fall under workers' compensation insurance.

The third category covers new risks that “have no specific place”, Nazaro said. He warned the insurance industry to avoid the practice of simply “extending coverage – "by including the risk without doing the appropriate risk assessment (underwriting)."

"I think this could be included in a cyber insurance policy, but if so, we need to make sure we assess those risks," he said. Nazaro referred to new AI regulations and noted that fines for violating rules other than privacy laws may not fall within the scope of cyber insurance.

Daniel Roth, head of cyber insurance claims for North America at Axa XL, notes that insurers should not view artificial intelligence (AI) as a "monolith." Instead, they should go back to the basic analysis of coverage: who is the insured, what is the claim, whether it falls within the scope of the insurance contract and whether any exclusions apply.

“In the event of a breach, we may not even know whether AI was used or not. We can speculate, but we may never know for sure,“ Roth said. She urged policyholders to work with their brokers to assess their own risks.

Arkin of Berkley compared the situation to “silent cyber risk“, noting that “exposure to AI-related risk will be present in all existing insurance policies. Right now, it is just an implicit risk of AI.“