07 October 2026

Autonomous AI Is Changing the Cyber Threat Landscape

The development of autonomous, or agentic, AI is particularly significant for the cyber threats businesses face. Unlike conventional generative AI, these systems can plan, use digital tools and take multiple actions towards an objective with limited human intervention.

In cybersecurity, that could enable activities that once required considerable human expertise and time to be conducted faster and at scale. Recent incidents have also demonstrated that the threat does not necessarily require a malicious actor.

In July 2026, OpenAI disclosed that AI agents being used in cybersecurity testing had circumvented controls, exploited vulnerabilities and accessed third-party systems belonging to Hugging Face. OpenAI subsequently identified behaviours including reward hacking and unauthorised communication.

Anthropic has since disclosed four incidents in which Claude models obtained unauthorised access to real third-party systems during cybersecurity evaluations.

These were unusual testing environments and should not be interpreted as evidence that AI systems can independently become malicious. They demonstrate something more relevant to businesses: increasingly capable AI systems can potentially create external cyber threats both when deliberately weaponised and when pursuing legitimate objectives.

AI-Powered Malicious Actors

For businesses, the immediate concern is not whether AI becomes uncontrollable. It is what increasingly capable technology could enable someone, or something, outside the organisation to do.

Malicious actors already use generative AI to support phishing, social engineering, reconnaissance and malicious code development. Agentic AI could take this further by connecting individual stages of an attack.

An AI agent could potentially be tasked with identifying exposed systems, researching vulnerabilities, developing or adapting code, testing different approaches and responding to defensive measures. Activities that previously required repeated human intervention could increasingly form part of a continuous automated process.

The UK’s National Cyber Security Centre expects AI to increase the frequency and intensity of cyber threats and has warned that AI-enabled vulnerability research and exploit development could further compress the time between vulnerabilities becoming known and being exploited.

The potential consequence is not a completely new form of cyberattack, but rather that AI could make existing attacks faster, cheaper, more convincing, and easier to scale. Attackers who automate their activity can target more organisations without needing additional resources, impacting both large and small businesses.

For businesses, the immediate concern is not whether AI becomes uncontrollable. It is what increasingly capable technology could enable someone, or something, outside the organisation to do.

Unintended Threats

The OpenAI and Anthropic incidents introduce another dimension. In both cases, AI systems were undertaking cybersecurity tasks rather than being instructed to attack unrelated organisations. Nevertheless, agents crossed intended boundaries and interacted with real third-party infrastructure.

For businesses, this creates the possibility of being affected by AI activity even where they were never the intended target. As more organisations deploy autonomous agents, those systems will increasingly interact with websites, APIs, cloud infrastructure and other businesses’ digital services. Errors, inadequate safeguards or unexpected agent behaviour could therefore create security incidents affecting third parties.

Such incidents may not become commonplace, but they broaden the cyber risk model. Organisations must now consider not only deliberate attackers but also automated systems that might interact with their infrastructure in unexpected ways.

Security Needs to Keep Pace

The fundamentals of cybersecurity remain important, but the speed of technological development makes getting them right even more critical.

Strong identity and access management, multi-factor authentication, timely patching, network segmentation, endpoint protection and effective backups can all make it harder for both human and automated attackers to progress through an organisation.

Businesses should also consider how quickly they identify and remediate vulnerabilities. If AI reduces the time required to discover and exploit weaknesses, organisations with lengthy patching cycles or unsupported technology could find their response window shrinking.

Employee awareness remains equally important. AI-generated phishing, voice cloning and deepfakes can make social engineering considerably more convincing. Processes around payments, changes to bank details, and requests for sensitive information should therefore rely on robust verification rather than an individual’s ability to recognise whether an email, telephone call, or video is genuine.

Cybersecurity should ultimately be treated as an organisation-wide resilience issue rather than solely an IT responsibility.

Cyber Insurance

Agentic AI is bringing in a new era of automation, transforming how organisations manage risk, make decisions and deliver value. At the same time, it is deepening their reliance on digital technology and rapidly expanding their digital footprints.

Businesses now depend on interconnected systems, cloud providers, software platforms and external technology suppliers to communicate with customers, process payments, manage data and deliver services. As this dependency grows, so does the potential operational and financial impact of technology disruptions or compromises.

AI adds another dimension to this challenge. While accelerating innovation, it can also speed up and sophisticate cyber threats and broaden the range of systems and vulnerabilities attackers can exploit. Business leaders are recognising that, although strong cybersecurity controls are essential, prevention alone cannot eliminate cyber risk.

This is why cyber insurance is becoming an increasingly important part of an organisation’s wider resilience strategy. Insurance cannot replace effective cybersecurity, just as technical controls cannot prevent every incident. The two should work together: security controls reduce the likelihood and severity of an attack. At the same time, a well-structured cyber insurance programme helps an organisation prepare for and manage the consequences when those controls are circumvented.

The value of cyber insurance can begin before an incident occurs. Depending on the policy, organisations may have access to security assessments, vulnerability scanning, employee awareness training and incident response planning, helping them strengthen their resilience as the threat environment evolves.

If an incident does occur, rapid access to specialist response teams, forensic investigators, legal advisers, crisis communications experts, data recovery services and business interruption support can help contain the impact, reduce operational disruption and support a faster recovery.

However, not all cyber policies provide the same level or scope of protection. Organisations should understand how their programme responds to emerging attack methods, technology supply-chain failures, business interruption and AI-enabled or unintended AI incidents, rather than assuming that having a cyber policy alone is sufficient. As AI further deepens organisations’ reliance on technology, buyers should carefully assess whether their cover responds clearly and affirmatively to relevant AI-related risks.

Cyber insurance is not simply a financial safeguard; it is a core component of operational resilience, helping organisations prepare for incidents, respond effectively and recover.

In Summary

The lesson from recent AI incidents is therefore not that businesses should fear autonomous technology. It is that the capability, speed and scale of potential cyber threats are evolving rapidly, and organisations need to evolve with them.

Businesses that continue investing in security controls, governance, incident preparedness and an appropriate cyber insurance programme will be better positioned to take advantage of technological progress while remaining resilient when something goes wrong.

Let's talk


James Wall

Executive Director - Cyber

james_wall@ajg.com

Back to Home

Share on social

The sole purpose of this page is to provide guidance on the issues covered. This page is not intended to give legal advice, and, accordingly, it should not be relied upon. It should not be regarded as a comprehensive statement of the law and/or market practice in this area. We make no claims as to the completeness or accuracy of the information contained herein or in the links which were live at the date of publication. You should not act upon (or should refrain from acting upon) information in this publication without first seeking specific legal and/or specialist advice. Arthur J. Gallagher (UK) Limited accepts no liability for any inaccuracy, omission or mistake in this publication, nor will we be responsible for any loss which may be suffered as a result of any person relying on the information contained herein.

The Walbrook Building 25 Walbrook London, EC4N 8AW

Legal & Regulatory

Privacy Policy - Do Not Sell or Share My Personal Information (U.S. Residents Only)

Cookie policy

Arthur J. Gallagher (UK) Limited is authorised and regulated by the Financial Conduct Authority. Registered Office: The Walbrook Building, 25 Walbrook, London EC4N 8AW. Registered in England and Wales. Company Number: 119013.