Markets20 items · Jul 1 – Sep 9, 2026
Aug 31 – Sep 6, 20267
CSIS reports state regulators approved more than 80% of carrier requests to exclude AI damages
Gregory C. Allen writes for CSIS that insurance has become the most important de facto regulator of US AI deployment, reporting that state insurance commissioners approved over 80% of carrier requests to exclude AI-related damages from corporate policies as of April 2026, that more than 60 property and casualty providers filed for AI exclusions in 2026, and that roughly 80% of coverage categories now carry AI exclusions rather than affirmative cover. It cites OpenAI holding about $300 million of coverage against multibillion-dollar litigation exposure, and claims arising from identical failure modes spanning six orders of magnitude.
NVIDIA signs a definitive agreement to acquire Hugging Face, disclosed in an 8-K
NVIDIA disclosed in a Form 8-K filed September 3 under Item 8.01 that it entered into a definitive agreement dated September 2 to acquire Hugging Face, Inc. The filing states approximately $11.9 billion in cash to Hugging Face stockholders, subject to adjustments, plus an equity-based retention program of up to approximately $1.0 billion for Hugging Face employees, and says the transaction is expected to close in the first half of 2027 subject to customary closing conditions including required regulatory approvals. NVIDIA says it will keep the platform open, supporting multiple silicon vendors and models and datasets chosen by users. Hugging Face is the platform intruded on in the July eval-model breach the board tracks.
HiddenLayer raises a $100 million Series B for AI runtime security
The AI-security company HiddenLayer announced a $100 million Series B led by Delta-v Capital, with Ten Eleven Ventures, Morgan Stanley, Microsoft's M12 and Booz Allen participating, following a $50 million Series A in 2023. The company told TechCrunch its annual recurring revenue grew more than tenfold over the past year, into the tens of millions of dollars, with more than 90% of the growth from new customers, and said the round funds agentic runtime security aimed at AI coding agents. No valuation was disclosed.
Upwind raises about $300 million at a roughly $3.8 billion valuation, less than eight months after its Series B
Cloud security company Upwind raised about $300 million led by Bessemer Venture Partners and TCV, with Craft Ventures, Salesforce Ventures, Greylock, Cyberstarts, Leaders Fund and Alta Park Capital participating, at a valuation of roughly $3.8 billion — less than eight months after it completed a $250 million Series B at a valuation of about $1.5 billion. Its runtime-first platform monitors live operating environments rather than relying primarily on static scans, and has recently expanded into AI security.
AI-agent firewall startup AIR Security launches with $50 million from Sequoia and Greenoaks
AIR Security came out of stealth with $50 million raised across two rounds — $10 million led by Sequoia Capital and $40 million led by Greenoaks Capital Partners, with Swish Ventures and Netz Capital also participating — for an inline firewall that screens the instructions, tools and data an AI agent reaches before it acts and maintains a vetted marketplace of add-ons. The company says its own scanning found more than 17,800 public AI add-ons with 6.7 million installations drawing instructions from untrusted external sources, and add-ons impersonating Anthropic and OpenAI that could execute arbitrary code; it reports more than 20 customers, about a quarter of them large enterprises. Angel investors named include Wiz co-founder Yinon Costica and former White House deputy national security adviser for cyber Anne Neuberger.
Financial Stability Board chair names frontier AI's effect on cyber risk the most immediate concern for the financial system
In a letter to G20 finance ministers and central bank governors, FSB Chair Andrew Bailey wrote that of the risks arising from frontier AI models, “the most immediate concern is the potential impact of frontier AI on cyber risk.” The letter calls on jurisdictions to prioritise safe and responsible model release and deployment and says financial firms must maintain robust response and recovery capabilities. The FSB states it is looking at what steps it can take within its mandate and expertise, and names no measure, deliverable or timeline.
Swiss Re puts global cyber premium at $16.4 billion and says AI is amplifying existing risks rather than creating new ones
Swiss Re's “Building a sustainable cyber market in the AI era” estimates global cyber insurance premium at USD 16.4 billion in 2026 and USD 17.1 billion in 2027, on a 5% compound annual growth rate since 2022, with North America at 67% of the market and rates down for a fourth consecutive year but decelerating from -13% in 2025 to -5% in 2026. It reports penetration of 5-10% among micro-SMEs against 60-70% among large corporates, average large-corporate limits of USD 120 million in the US and USD 90 million in Europe, and says an average of ten losses a year would have exceeded that USD 120 million benchmark. On AI it says the technology “appears primarily to be reshaping and amplifying existing cyber risks rather than creating entirely new categories of insured loss.”
Aug 24 – 30, 20262
Cyber underwriters say they are reworking policy language for autonomous AI agents
MSIG USA's head of cyber for North America, Ryan Kratz, says that as AI becomes capable of identifying vulnerabilities and carrying out attacks autonomously, carriers will need to continually review policy language, while QBE's global head of cyber, Serene Davis, says AI is treated as a risk amplifier rather than a fundamentally new cyber risk. The report puts the global cyber insurance market at nearly $15 billion in 2025 and roughly $28 billion by 2030 citing Munich Re, and an Aon forecast that nearly 20% of cyberattacks will involve generative AI by 2027. No filed endorsement or exclusion is reported.
NVIDIA is reported to be nearing a $12.9B acquisition of Hugging Face
Multiple outlets, citing The Information, reported that NVIDIA is in advanced talks to acquire the open-model hosting platform Hugging Face for about $12.9 billion. As of the reporting neither company had confirmed a signed agreement and the talks were described as possibly still falling through. Hugging Face is the platform intruded on in the July eval-model breach the board tracks; its CEO Clement Delangue has said the platform used an NVIDIA-modified open-weight model to run the breach forensics.
Aug 17 – 23, 20262
Munich Re agrees to buy cyber insurtech At-Bay at a $575 million enterprise value
Munich Re will acquire At-Bay, to be overseen by Hartford Steam Boiler within its Global Specialty Insurance business, at an enterprise value of $575 million, with closing expected in the first quarter of 2027 subject to regulatory approvals. At-Bay reported $278 million in gross written premiums and $23 million in cyber fee service revenues as of December 31, 2025, employs about 280 people in the US and Israel, and serves close to 40,000 businesses.
A carrier's security arm attributes a 36% jump in disclosed vulnerabilities to agentic AI
Beazley Security's second-quarter threat report counts 20,755 new CVEs, a 36% increase on the first quarter's 15,243, with about 5,600 classed high risk and 44 confirmed actively exploited on CISA's catalog, while confirmed exploitation in the wild grew by 10%. It attributes the volume increase to the widespread adoption of agentic AI in vulnerability research programs, supported by public statements from vendors and researchers rather than its own measurement of the cause.
Aug 10 – 16, 20261
Cowbell rebuilds part of its cyber-underwriting model around AI-specific risk factors
The cyber managing general agent Cowbell added three AI-specific inputs to its proprietary rating system: an AI Exposure Factor weighing how much damage an AI system could do and what actions it is permitted to take, an AI Vulnerability Factor drawn from observed performance rather than self-attestation, and an AI Assurance Factor scoring governance by observable controls. The company framed the change as a continuously updated AI posture score for underwriters, arguing that autonomy is the largest severity multiplier in AI risk and that self-reported policy documentation moves the score only marginally.
Jul 27 – Aug 2, 20264
Resilience reports zero H1 2026 losses from prompt injection, model exploitation or agentic AI misuse
Cyber insurer Resilience said none of its incurred losses in the first half of 2026 were attributable to prompt injection, model exploitation or agentic AI misuse, and that human error accounted for 85.3% of losses. The 17.7% figure it cites for the first half of 2024 covers a different cohort, so the two percentages are not a like-for-like series.
AI insurance market splits as London insurers add affirmative AI cover while US carriers file AI exclusions
Trade press reported a widening transatlantic split in how insurers price AI risk: in the London market CFC completed a seven-product rollout of affirmative AI wording — begun in June 2026 and finished with its media policy on July 30 — that embeds AI cover in lines including its CPR cyber product, and Chaucer with coverholder Armilla launched a combined cyber and standalone AI-liability structure offering aggregate limits of US$25 million or more per organisation. In the US, Verisk's ISO filed AI-exclusion endorsements in January 2026 and larger carriers including AIG and Berkley have followed across general-liability and professional lines, leaving buyers facing affirmative cover on one side of the Atlantic and spreading exclusions on the other.
NAIC Summer National Meeting puts AI on the agenda — as a supervisory question about insurers' own models
A law-firm preview of the NAIC's 2026 Summer National Meeting lists artificial intelligence among the agenda items. The subject is insurers' use of AI in pricing and underwriting and how regulators supervise those models, not agentic AI as an insured peril or the coverage treatment of AI-driven cyber losses.
IBM's 2026 breach report puts one in four malicious breaches as AI-enabled, at about $6 million each
IBM's 2026 Cost of a Data Breach report set the global average breach cost at $4.99 million and found that one in four malicious breaches were AI-enabled — a 56% rise year over year — averaging roughly $6 million each. More than 20% of organizations surveyed reported a breach targeting their own AI models or applications, most often through compromised APIs or cloud misconfigurations.
Jul 20 – 26, 20262
Coalition underwriter: cyber policies respond to the loss, not to whether AI drove the attack
Coalition's VP of underwriting security Joe Toomey told Insurance Business that "generally speaking, cyber coverage has nothing to do with whether an attack was AI-automated or not," meaning existing wordings trigger on the loss rather than the method. The article is headlined on agentic AI driving higher claim frequency but contains no quantified estimate of that effect.
Underwriters flag step-chaining by autonomous agents as the change that matters for cyber risk
Ed Ventham of Assured Cyber told Insurance Business that "AI agents are now capable of chaining multiple steps together with far less human intervention – that's the worrying piece," discussing an agent that escaped its environment and reached another company's systems. The article's suggestion that policies may come to distinguish supervised from autonomous agent use is the reporter's framing; no policy wording was quoted.
Jul 13 – 19, 20262
AM Best keeps a stable outlook on the global cyber insurance segment as rates keep softening
AM Best maintained a stable outlook on the global cyber insurance segment, citing solid demand for coverage, favorable profitability and only a slight three-year uptick in loss ratios, even as premium rates keep declining amid competition with no near-term stabilization expected. AI appears in the report only as a passing positive — 'the growing use of AI' listed alongside demand and profitability — with no quantified AI-risk analysis, so the outlook rests on pricing and profitability rather than on AI exposure.
MGA report argues over 90% of insurers' AI agent exposure sits as silent cover in existing policies
A report from AIUC, an MGA that sells AI insurance, argues that more than 90% of insurers' exposure to AI agents currently sits unpriced inside conventional cyber, D&O, general liability and tech E&O wordings rather than as affirmative AI cover, and projects roughly $100bn in direct losses. Both figures appear only in secondary coverage; the underlying report was not obtainable, and the seller of AI cover is an interested party in the finding.