As AI threats spread, insurers use the same tech to fight back

AI is enabling a wide range of fraud threats, from standard data breaches and password exploits to more targeted deepfake insurance fraud. The technology can also be a defense against such risks; those that deploy AI and automation in security can cut breach costs by an average of $2 million, according to IBM.

Processing Content

Experts in the insurance industry advice that AI be deployed as part of a broad strategy rather than for discrete tasks; this applies beyond security and extends to product development and claims and service workflows

Read more below from this week's coverage.

AI-enabled breaches cost $6M; financial sector tops targets

One in four data breaches were AI-enabled in 2025, a 56% increase year over year, with AI-led attacks averaging $6 million per incident — nearly $1 million above the global breach average, according to IBM's 2026 data breach study. Financial services and energy sectors accounted for 62% of all AI-driven breaches, with financial services averaging $6.29 million per incident. Deepfakes and impersonation drove 45% of malicious AI attacks. Companies deploying AI and automation in security operations cut breach costs by nearly $2 million on average, yet 25% have not adopted these tools. Only 18% of organizations currently apply AI agents to vulnerability management, despite more than half using them for threat detection.
Read more: How AI-enabled attacks cost companies millions

98% of insurers cite AI fraud as threat to claims evidence

With 98% of insurers reporting AI editing tools are fueling digital fraud and only 32% confident in detecting deepfakes, claims teams face mounting pressure to rethink evidence review. Aviva flagged roughly $311 million in suspected claims fraud in 2025, with AI-generated images and manipulated documents increasingly used to support false or exaggerated claims. Black-box fraud scoring tools compound the problem, generating alert volume without explainable evidence, leaving insurers legally exposed if a denial is challenged. Effective AI fraud detection must connect images, records, timelines, and claimant behavior into a defensible evidence trail, not just a score adjusters cannot act on.
Read more: Why AI fraud tools could cause claim risks

Credential attacks drive up cyber insurance costs, claims

Compromised credentials now represent the leading cyber insurance risk vector, with carriers embedding identity security controls directly into underwriting criteria and pricing models. Verizon's 2026 Data Breach Investigations Report confirms credential abuse as the top breach entry point, while Microsoft found 97% of observed identity attacks in 2025 involved password-spraying. Average U.S. data breach costs now exceed $10 million, and credential-based intrusions often go undetected for 290-plus days, driving higher claim severity. Insurers are treating MFA implementation, least-privilege access controls and Dark Web monitoring as baseline eligibility requirements — organizations lacking these face higher premiums, restricted coverage or denied claims.
Read more: How credential attacks are reshaping cyber insurance claims

McKinsey: AI helps insurers grow by covering new risks

The global insurance industry has posted 4.9% annual growth in gross written premiums since 2005, but profit growth has lagged at 4.3%, according to a new McKinsey & Company report attributing the gap to resistance to disruption. AI is changing that calculus: commercial lines risks that once took two days to quote now take half a day, enabling higher quote volumes and revenue growth without rate increases. Real-time portfolio monitoring — previously updated semi-annually — is now continuous. McKinsey recommends carriers move beyond isolated AI use cases and redesign core business units around AI, with clear economic guardrails governing vendor strategy, architecture and talent decisions.
Read more: How AI steers insurers to find new risks to cover

Mea Platform CEO: Give insurance leaders results, not pilots

Martin Henley, founder and CEO of mea Platform, argues that the insurtech market has shifted decisively from experimentation to production — and budgets are following. The company, bootstrapped for four years before securing a $50 million minority growth equity investment from Scottish Equity Partners in February 2026, deploys AI-native reinsurance automation across carriers, brokers and MGAs in more than 20 countries. Henley's core warning: treating access to a general AI model as a product is a strategic mistake. The durable competitive advantage lies in encoding proprietary operational knowledge — an organization's own risk language, decisions and workflows — into domain-specific models that deliver measurable financial outcomes from day one.
Read more: Give insurance leaders results, not pilots: Mea CEO Martin Henley

Fix the workflow before buying more AI features, Crosstie CEO says

Insurers racing to adopt AI tools risk compounding operational fragmentation rather than resolving it, warns Crosstie CEO Sean Eldridge. The more consequential shift — moving AI from isolated use cases into claims and service workflows — remains largely unrealized. Eldridge argues that carriers, TPAs and self-insureds should prioritize embedding AI into existing systems over purchasing standalone features, and that measurable ROI on cycle times and costs should drive procurement decisions. Founded in 2019 and backed by General Catalyst and MassMutual Ventures, Crosstie's 28-person team builds workflow orchestration software for P&C claims operations, connecting intake, documents, voice, messaging and core systems.
Read more: Stop buying AI features, fix the workflow: Crosstie CEO Eldridge

Agentic AI rewrites the economics of insurance BPO

Agentic AI systems are dismantling the core value proposition of insurance BPO — lower-cost labor for language-intensive tasks — by handling intake, indexing, extraction and data entry at machine speed and volume. Unlike RPA and OCR, which failed when documents deviated from templates, agentic systems route exceptions through an operations dashboard to human reviewers rather than breaking down. The model, "supervised autonomy," keeps humans accountable for judgment calls while driving down per-transaction costs as compute prices fall. A built-in audit log of every extraction, decision and exception resolution also addresses regulatory documentation burdens that labor-based operations manage only through additional effort.
Read more: How agentic AI is changing insurance BPO

This roundup was created with AI assistance. A Digital Insurance editor reviewed each item before publication.


For reprint and licensing requests for this article, click here.
MORE FROM DIGITAL INSURANCE
Load More