INSURERS CAP PAYOUTS FOR AI AND LLMJACKING LOSSES
AI DESK■ 1 MIN READ
WED, APR 22, 2026■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
Major cyber insurers including QBE and Beazley are limiting coverage for losses and regulatory fines tied to artificial intelligence use and LLMjacking attacks, citing rapid technological advancement and emerging risks.
The insurance industry is moving to restrict payouts for damages stemming from AI deployment and LLMjacking—attacks involving the hijacking of large language models—according to documents reviewed by the Financial Times.
QBE and Beazley, among other carriers, are implementing caps on cyber policy coverage for losses and regulatory penalties linked to AI systems. The shift reflects growing uncertainty around liability exposure as AI technology evolves faster than risk assessment frameworks.
LLMjacking represents a nascent threat where attackers compromise AI models to generate malicious outputs or extract sensitive data. Insurers lack sufficient historical data to accurately price these risks, prompting them to establish financial guardrails.
The moves signal insurers' cautiousness about underwriting AI-related claims while the technology and its regulatory landscape remain fluid. Organizations relying on AI systems may face reduced coverage options or higher premiums as the industry recalibrates its risk models.
■ SOURCES
► Techmeme■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE
■ MORE FROM THE SECURITY DESK
Cybercriminals have transformed DDoS attacks into a polished, commercialized service complete with pricing tiers, customer support, and reseller programs. The DDoS-as-a-Service market has evolved from basic tools into sophisticated attack platforms.
MAY 29— Industry Desk
Microsoft faced backlash after threatening a security researcher with criminal investigation, reigniting debate over software vulnerability disclosure practices and corporate responsibility.
MAY 29— Security Desk
Google is deploying Device Bound Session Credentials (DBSC) to all Chrome users, a security feature designed to prevent account takeovers by protecting session cookies from theft.
MAY 29— Industry Desk
Dutch authorities have dismantled a major botnet comprising 17 million infected devices and seized over 200 servers hosting the operation at a local provider.
MAY 29— Security Desk