AI and Cybersecurity: Six Steps to Protect Your Business
September 15, 2026

AI Is Changing Cyber Risk. Is Your Business Ready?
Artificial intelligence is transforming how businesses operate. It helps employees analyze data, automate routine work, improve customer service, develop software, and solve problems more quickly.
AI is also changing cybersecurity.
According to IBM’s 2026 Cost of a Data Breach Report, one in four malicious breaches studied involved AI, a 56% increase from the previous year. These AI-enabled breaches cost organizations nearly $6 million on average, compared to the global average breach cost of $4.99 million.
The same report found that organizations using AI and automation in their cybersecurity programs experienced significantly lower breach costs.
The takeaway? AI can strengthen security, but it can also make cybercriminals more effective. As a result, cybersecurity, AI governance, and insurance are becoming increasingly connected.
Recent Attacks Show How Broad Cyber Risk Has Become
Cyberattacks can impact organizations of any size or industry.
In July, Amgen disclosed that an unauthorized party accessed third-party cloud servers and stole data that included protected health information. While the company reported no impact on manufacturing, products, or financial reporting systems, the investigation remains ongoing.
Around the same time, authorities investigated cyber incidents affecting water systems in Michigan and Minnesota. More than 30 Minnesota water systems and 9 Michigan systems were targeted or impacted. Although officials reported that operations continued safely, the attacks involved technology used to remotely monitor and control equipment.
These incidents highlight several common exposures:
- Sensitive data stored in cloud environments
- Dependence on third-party vendors and technology providers
- Operational systems connected to networks
- Cyber events that can affect more than just IT systems
Another growing concern is the speed at which vulnerabilities are being discovered. By late July, the U.S. National Vulnerability Database had recorded more than 45,000 software vulnerabilities in 2026, nearly matching the total reported during all of 2025. Researchers attribute much of this increase to more capable AI systems. Encouragingly, many of these vulnerabilities are being identified proactively by technology companies before attackers can exploit them.
That distinction matters. AI isn’t inherently a cyber threat. It’s a tool that can benefit both attackers and defenders.
Businesses Need to Think About the AI They Use
Cybersecurity is only one part of AI risk.
Organizations are using generative AI for marketing, customer communications, software development, research, financial processes, and more. These applications can raise questions around privacy, intellectual property, inaccurate outputs, contractual obligations, and professional liability.
Insurance Markets are Beginning to Respond
Recent industry reports indicate that some major insurance carriers have sought regulatory approval for endorsements that exclude certain AI-related damages from commercial liability policies. An analysis cited by The Information found regulators approved more than 80% of the requests reviewed. However, approval does not mean those exclusions automatically apply to every policy.
At the same time, other carriers are developing affirmative coverage options for certain AI-related exposures through Cyber, Technology E&O, Media Liability, Employment Practices, and other insurance programs. Coverage terms, limits, and availability can vary significantly.
AI-related risks require a closer look at the coverage available under each policy.
It is that AI makes reviewing your exposures and policy language with your trusted Robertson Ryan Insurance advisor more important than ever.
How Cyber Insurance Carriers Are Adapting
Cyber insurance remains an important part of many organizations’ risk management strategies, but it’s only one piece of the puzzle.
Today, underwriters increasingly evaluate the cybersecurity controls businesses have in place. Common areas of focus include:
- Multifactor authentication (MFA)
- Endpoint protection
- Privileged-access controls
- Email and web security
- Backups
- Data encryption
- Incident response planning
As AI adoption grows, underwriters may also ask how your organization is using AI, including:
- Which AI tools employees use
- What types of information are entered into those tools
- Which vendors provide them
- What governance and oversight controls exist
Six Steps Businesses Can Take Today
- Know Where AI Is Being Used – Create an inventory of approved AI tools, including AI features built into existing software. Consider whether employees are using AI independently and whether sensitive, confidential, or proprietary information is being shared with those platforms.
- Establish an AI Use Policy – Define approved uses, restricted information, approved platforms, and when human review is required. Policies should evolve as technology and business need changes.
- Strengthen Access Controls – Multifactor authentication, appropriate access privileges, and strong account-management practices can help prevent unauthorized access. The FTC recommends MFA for employees, contractors, and anyone accessing business networks or devices.
- Keep Systems Updated and Backed Up – AI can help identify vulnerabilities faster, making timely patching even more important. Businesses should maintain tested backups and regularly validate recovery processes rather than assuming they’ll work during an incident.
- Train Employees for Modern Threats –Traditional phishing remains a major risk, but employees also need to recognize AI-generated scams, impersonation attempts, and fraudulent payment requests. Sensitive financial or payment changes should always be verified through a trusted communication channel. The FBI recommends independently verifying payment requests and account changes and using MFA to reduce business email compromise risks. Continuous, role-specific cybersecurity education can also help employees apply security principles to the situations they actually encounter. We wrote about this here – Cybersecurity Training: What Is The Most Effective Method?
- Review Insurance Regularly – Cyber, general liability, professional liability, technology E&O, media liability, crime, and other policies may respond differently depending on the circumstances of a loss and the policy language involved. At renewal, review exclusions, endorsements, sublimits, definitions, and other coverage changes with your insurance advisor. Businesses using AI in meaningful ways should also evaluate whether their insurance program addresses those evolving risks.
AI Risk Is a Business Issue, Not Just an IT Issue
Perhaps the biggest shift is that cybersecurity and AI governance can no longer be treated as IT-only responsibilities. Technology decisions can affect operations, reputation, customer trust, privacy obligations, contracts, regulatory requirements, and overall business risk.
There is also reason for optimism. The same IBM research that reported growth in AI-enabled attacks found that organizations using AI and automation extensively in their security operations experienced significantly lower breach costs.
Businesses don’t need to avoid AI. They do need to understand where it’s being used, establish appropriate controls, prepare for incidents, and keep their insurance and risk management strategies aligned with a rapidly evolving technology landscape.
A conversation with your Robertson Ryan Insurance advisor can help identify potential exposures, review available coverage options, and determine what questions should be addressed as your organization’s use of AI evolves. For more information from one of our carrier partners read more here: Cyber Defense in the World of Mythos.
*Please note that we rely on independent sources and recommend conducting further research or seeking guidance from a qualified industry professional, legal counsel, or licensed insurance agent as appropriate for your needs. These blog posts are intended for general informational purposes only.