Editor's note.
Every passage attributed to the statement in this article was read in the published document itself, retrieved from the issuing authorities' own domain on 2 September 2026, with the source and date recorded in the final section. This desk has read no insurer's response to the statement and reports none. The consequences described in sections 3 and 4 are analysis of how markets ordinarily behave when a correlation concern is articulated, not a report of anything any carrier has said or done.
- The statement is addressed to financial entities and their supervisors. Insurers and reinsurers are financial entities, so the potential writer of AI cover is also an addressee. That is unusual and it is the whole point of this piece.
- Its three opening claims are a correlation description: speed of exploitation, shared infrastructure, and single points of failure across entities. Correlation is the property that decides insurability, not severity.
- Expect structure rather than scarcity. Event definitions, aggregate caps, sublimits for widespread events and dependent outage wording are how a market answers accumulation, and they are already present in this class.
- The evidence the supervisor now expects and the evidence an underwriter asks for have converged. An asset inventory that names AI components, continuous monitoring, tested recovery and dependency mapping serve both.
- Nothing here touches AI agent liability cover. An agent giving wrong advice is a different exposure in a different policy, and merging the two is the most common mistake in this area.
Section 1. The addressee is the point
Supervisory statements are usually read by the population they regulate and ignored by everybody else, which is a sensible division of labour. This one deserves a wider readership for a structural reason that has nothing to do with its subject matter.
The document is a joint statement of the European Supervisory Authorities, issued through their Joint Committee, and it carries the title Toward a consistent and risk-based approach for ICT risks from frontier AI models. The three authorities in question cover banking, insurance and occupational pensions, and securities and markets. The insurance supervisor is a co-author. The population addressed is financial entities, which under the operational resilience regime includes insurance and reinsurance undertakings alongside banks, investment firms and others.
So the same document that describes why AI-enabled cyber risk is hard to carry is addressed to the entities that would be asked to carry it. For a buyer that is a rare piece of information. Most of the time the appetite of a market is inferred from what it quotes. Here there is a published statement of what its supervisors have asked it to think about, written before any of it shows up in a wording. The full regulatory reading of the statement, including what it does to AI Act positioning, is at agentliability.eu, on the supervisory answer arriving through the resilience regime.
Section 2. Three sentences that describe correlation
The statement opens by saying that the advanced capabilities of recent frontier AI models significantly accelerate cyber risks, and that AI-enabled cyber tools could generate systemic risks through three abilities: to rapidly discover and exploit vulnerabilities, to target vulnerabilities in shared infrastructure, and through single points of failure across entities.
A compliance reader takes that as a warning to patch faster. An underwriting reader should take it as something more specific, because each of the three items maps to a distinct accumulation mechanism.
Speed collapses the interval. The economics of most security programmes rest on the gap between a vulnerability becoming known and being exploited at scale. Controls, patch cycles and detection windows are all sized against that gap. Compress it and a portfolio that was diversified by the differing maturity of its insureds becomes less diversified, because slow and fast policyholders are hit inside the same window. The statement makes the point plainly in its annex, noting that traditional patching processes relying on a periodic and reactive approach may not be sufficient to ensure a timely reaction.
Shared infrastructure means shared weakness. A portfolio of insureds running different businesses in different countries can still be running the same libraries, the same cloud region, the same identity provider and the same handful of models. Diversity of insured does not imply diversity of exposure, and this is the point on which cyber accumulation modelling has always been hardest.
Single points of failure across entities is the phrase to underline. The statement's own words locate the failure not inside one organisation but across many, which is the exact shape of a systemic event. Our standing treatment of that question from the coverage side is at whether AI insurance covers systemic model failure and aggregation risk, and the wider dependency question at third-party tool and plugin failure.
None of this is a prediction and the statement does not make one. What it does is put a supervisory description of correlation into the public record, in language a reinsurance actuary and a compliance officer can both use. That is genuinely useful, and it is rarer than it should be.
Section 3. What a market does with a correlation concern
The instinctive fear when a supervisor describes a risk as systemic is that cover will be withdrawn. That is not usually what happens, and it is not what the recent history of this class suggests will happen here.
Markets answer accumulation with structure. The instruments are well established and a buyer should watch for them at the next renewal rather than be surprised by them.
Event definitions. Whether a series of related failures counts as one loss or many is decided by wording, not by facts, and it is the single largest determinant of what a limit is worth in a widespread event. Ask how a shared-infrastructure failure affecting many organisations is treated.
Aggregates and sublimits. A generous per-claim limit sitting under a modest annual aggregate behaves very differently in a correlated year. Where a sublimit is applied specifically to widespread or systemic events, that sublimit is the real limit for the scenario the statement is describing. We set that mechanism out at sublimits and aggregate caps explained.
Dependent outage and named provider wording. If the exposure is a shared provider, the cover question is whether the policy responds to an outage at a party you do not control, and whether that party has to be scheduled by name.
Defence cost structure. In a widespread event legal spend arrives everywhere at once. Whether those costs sit inside or in addition to the limit decides how much indemnity survives, which we treat at defence costs inside or outside the limit.
The honest summary is that a correlation concern rarely closes a market and reliably reshapes one. The buyers who are surprised are the ones who read only the limit.
Section 4. The convergence, which is the good news
The most practically useful thing in the statement for a buyer is that the supervisor and the underwriter are now asking for the same artefacts, and there are not many of them.
The statement says prevention relies on comprehensive and continuously updated inventories of all IT assets, including infrastructure, applications, data repositories, APIs, and AI or machine learning components, because that is what allows assets to be classified by criticality and exposure. It asks for secure-by-design architecture rather than reliance solely on reactive controls. It asks that monitoring move from periodic to continuous. It asks that operational resilience testing evolve to simulate AI-enhanced threat scenarios. It asks that backups not be exposed to the same risks as primary systems. And it asks that dependencies across the estate be identified, monitored and assessed for criticality, naming software dependencies such as open-source libraries and third-party interfaces, infrastructure dependencies such as cloud and name resolution services, and operational dependencies such as outsourced monitoring.
Now compare that with what a competent underwriter asks a European buyer, which we set out at what underwriters ask before writing a policy. The overlap is close to complete. An asset inventory that names AI components is the first item on both lists. Dependency mapping is the second. Tested and isolated recovery is the third. What separates a good submission from a poor one has never been the answers themselves so much as whether the organisation can produce them without a three-week internal exercise.
The instruction that follows is short. Produce the evidence once, in a form that can be handed to a supervisor, an underwriter and an assessor without rework. The submission sequence is at preparing an AI agent underwriting submission, and the certification-side treatment of the inventory specifically is at agentcertified.eu, on the inventory as the first evidence artefact.
Section 5. Indirect exposure, and a disclosure trap
One phrase in the statement should be read by anybody who has ever completed a proposal form.
It asks that the risk appetite framework be reviewed to update or incorporate metrics, tolerance thresholds and control measures consistent with the evolving risk profile stemming both from the internal use of such models and from indirect exposure to them.
That distinction between internal use and indirect exposure is doing real work. An organisation that has adopted nothing, banned the tools and taken no AI vendor is still exposed, because the capability is in the hands of whoever is attacking it and inside the supply chain it already depends on. The exposure is not a consequence of adoption and cannot be declined by declining to adopt.
The trap is on the proposal form. Questions about AI are usually phrased around use: do you use AI, where, for what. An organisation answering honestly that it uses none has answered the question asked and has said nothing about the exposure the supervisor is pointing at. That is not a misrepresentation, but it is an incomplete picture that both parties would rather have had at inception than after a loss. Our treatment of the disclosure question generally is at disclosing AI agents when applying for insurance, and the practical answer here is to volunteer the dependency picture whether or not the form asks for it.
Section 6. The oversight line, and what to ask a provider
The statement records something that has already happened rather than something proposed. Acting as Lead Overseers, the authorities have initiated targeted engagement with relevant critical ICT third-party service providers to understand how they identify and manage these challenges, covering identification and assessment of the risks, the mitigations implemented and adaptation to the new capabilities. It states that the insights gained have informed the annual risk assessment cycle and the prioritisation of activities under the 2027 Oversight Plan, that AI-related risks are being embedded into the Oversight Examination Methodology, and that these threats are expected to be reflected in the scope of oversight examinations in 2027.
For a buyer whose critical provider is within that population, the answers already exist somewhere. Asking for them is now an ordinary request rather than an unusual one, and having them materially improves a submission, because the weakest part of most cyber and AI submissions is the section describing dependencies the applicant does not control. The supply chain question in the round is at subrogation, vendor contracts and insurer recovery.
Section 7. What this does not touch
Three boundaries, because the failure mode with a document like this is over-application.
It is not about AI agents making mistakes. Wrong advice, a biased decision, a missed service level, a hallucinated citation: none of that is in scope here. Those exposures sit in professional indemnity, technology errors and omissions, affirmative AI liability wordings and product liability. The decision guide between those is at the professional indemnity and cyber decision guide, and the plain-language version for smaller operators is at insureyouragent.com, on which AI risk your insurance is actually about.
It creates no obligation and changes no AI Act date. The statement's own annex says it does not establish additional requirements and should not be regarded as a comprehensive checklist. Standalone Annex III high-risk obligations still apply from 2 December 2027 under the AI Omnibus.
It says nothing about any carrier's appetite. This desk has read no insurer response to the statement, and none is reported. What can be said is that the appetite conversation now has a published supervisory reference point that did not exist before, which is a change in the conditions rather than in anybody's decision. The current map of who writes what for European buyers is at the European AI agent insurance market tracker.
Section 8. Six questions for the broker
- In a widespread event affecting many organisations through a shared provider or a shared component, how does this wording decide what counts as one loss?
- Is there a sublimit or aggregate that applies specifically to widespread, systemic or catastrophic events, and what is it as a proportion of the headline limit?
- Does the policy respond to an outage or compromise at a party we do not control, and must that party be scheduled by name?
- Are defence and response costs inside the limit or in addition to it, and does that answer change in a widespread event?
- What does the carrier want to see on dependency mapping, and would evidence prepared for a supervisor be accepted in that form?
- Which of our exposures does this policy not answer, so that we can see where the AI liability side actually sits?
The first question is the one most often skipped and most often decisive. In a correlated event the event definition, not the limit, determines the recovery.
Section 9. The point in one sentence
When the supervisors of the parties who would carry a risk publish a description of why that risk correlates, the useful response for a buyer is not alarm but preparation: read it as the underwriting document it effectively is, produce the evidence it asks for once, and ask at renewal how much of your limit survives an event that reaches everybody at the same time.
Questions
Why does a supervisory statement about cyber risk matter to an insurance buyer?
Because of who it is addressed to. The statement is addressed to financial entities and to the competent authorities that supervise them, and European insurers and reinsurers are financial entities. The party that would underwrite AI cover for you has therefore been asked by its own supervisors to review its risk appetite framework, to build governance around this specific risk, and to treat exposure to frontier AI models as something requiring metrics and tolerance thresholds. Appetite is the thing that decides what is quoted, at what limit and with what exclusions, and appetite has just become a supervised object in this particular corner.
What does the statement say that is relevant to underwriting?
Three properties, stated in its opening paragraph. It says AI-enabled cyber tools could generate systemic risks through the ability to rapidly discover and exploit vulnerabilities, to target vulnerabilities in shared infrastructure, and through single points of failure across entities. Read those as an underwriter rather than as a compliance officer. Speed collapses the interval between a weakness existing and being used. Shared infrastructure means many insureds hold the same weakness at the same time. Single points of failure across entities means one event reaching many policies. Those three together are a description of correlation, and correlation is the property that decides whether a risk can be carried rather than merely priced.
Will this make AI-related cover harder to obtain?
The likelier effect is on structure rather than on availability. Markets rarely respond to a correlation concern by refusing to write; they respond by managing accumulation. The instruments for that already exist and are visible in this class: event definitions and hours clauses that determine how many claims count as one loss, aggregate caps, sublimits for widespread events, cover for a dependent outage at a named provider, and careful wording around systemic or catastrophic events. A buyer should therefore expect the conversation to move toward how much cover survives a shared event, rather than toward whether cover exists at all.
Does this statement change what an underwriter will ask me?
It sharpens questions that were already being asked, and for a regulated buyer it makes them harder to answer vaguely. The statement's first named artefact is a comprehensive and continuously updated inventory of all IT assets including AI and machine learning components, classified by criticality and exposure. That is also the first thing a submission needs. It asks for continuous rather than periodic monitoring, for resilience testing that simulates AI-enhanced scenarios, for backups that are not exposed to the same risks as primary systems, and for assessment of dependencies across the estate. Every one of those is a proposal-form question in some existing wording. The overlap is the useful part: the evidence is produced once and used twice.
What is indirect exposure and why does it matter to a policyholder?
The statement asks that risk appetite frameworks be reviewed to incorporate metrics, tolerance thresholds and control measures consistent with the evolving risk profile stemming both from the internal use of such models and from indirect exposure to them. For a policyholder the practical translation is that an answer of we do not use AI is not an answer to this exposure. The capability sits with whoever is attacking you and inside the technology supply chain you already depend on. A proposal form answered on the basis of adoption will understate a risk that arrives regardless of adoption, and an understated answer is a disclosure problem as well as a pricing one.
Does this affect AI liability cover for agents that make mistakes?
Not directly, and keeping the two apart matters. The statement is about frontier models as a capability in the hands of attackers and inside shared infrastructure. It is not about an AI agent giving a customer wrong advice, producing a biased decision or breaching a service level. Those exposures live in professional indemnity, technology errors and omissions, affirmative AI liability wordings and product liability, and nothing in this statement changes them. What it changes is the security and resilience side of the same organisation's programme, which is usually a different policy and often a different broker.