7 September 2026
It turns out this is becoming a two-part series! In my previous article, I explored how AI is changing cyber risk by making one of the oldest weaknesses in cyber security more difficult to defend against: people.
Phishing, impersonation, payment diversion and social engineering have not changed fundamentally. What has changed is how convincing they can become.
AI can make fraudulent communications more credible, replicate identities and make it increasingly difficult for people to distinguish genuine activity from manipulation. But the emergence of AI may be starting to change cyber risk in another way.
Recent incidents involving Hugging Face and JADEPUFFER provide early examples of AI being used not simply to improve an existing attack, but to perform significant parts of the attack itself, if not, potentially all of it!
The implications could be important for cyber insurance because, historically, sophisticated cyber-attacks have been constrained by one thing: expertise.
The Economics of AI-enabled attacks
Cyber risk has always had an economic dimension. Sophisticated attacks require technical knowledge, experience, time and resources. Identifying vulnerabilities, developing exploits, moving through compromised environments and adapting when an approach fails all require effort.
Those requirements create a natural barrier. The more difficult and expensive an attack is to conduct, the fewer organisations can realistically be targeted. AI could begin to change that equation.
If activities that previously required specialist expertise can increasingly be automated, the cost and effort required to conduct an attack may fall. That does not necessarily mean attacks become more sophisticated. It may simply mean that more attacks become economically viable and for insurers, that distinction matters.
A small number of highly sophisticated attacks can create significant losses, but a sustained increase in successful attacks could have a much greater impact on portfolio performance.
The Hugging Face incident
What happened
Hugging Face, a major AI platform used to host and share machine learning models, disclosed a cyber intrusion in July 2026. According to the company, attackers gained access to parts of its internal infrastructure and a limited number of datasets and credentials.
What made the incident unusual was that the attack was reportedly carried out by autonomous AI agents operating with minimal human involvement, highlighting the growing cyber risks associated with advanced AI systems.
Why it matters
The Hugging Face incident attracted attention because it demonstrated AI operating across multiple stages of a cyber intrusion. According to Hugging Face, the autonomous AI system Was reportedly able to identify vulnerabilities, obtain credentials, move through infrastructure and adapt its approach as the attack progressed. Over the course of the incident, it reportedly carried out thousands of actions and identified alternative routes when initial attempts were unsuccessful.
The significance is not that AI can find vulnerabilities, as security tools have automated elements of vulnerability discovery for years. More noteworthy is its ability to connect multiple stages of an attack with limited human intervention. Activities that once required a skilled operator to assess a situation, determine the next step and overcome obstacles could increasingly be delegated to AI systems. While it remains too early to know how common this type of attack will become, the incident provides an early indication that AI may reduce some of the expertise historically required to conduct sophisticated cyber activity.
The significance of JADEPUFFER
What happened
JADEPUFFER has been described by some researchers as the first documented example of an AI-driven ransomware and extortion campaign operating largely autonomously.
Researchers reported that the AI system exploited a vulnerability in an internet-facing AI application before progressing through reconnaissance, credential harvesting, lateral movement and database extortion. Rather than following a predefined set of instructions, the system was observed adapting its approach when individual actions failed, allowing the attack to continue with limited human intervention.
Why it matters
The significance of JADEPUFFER is not that it operated without any human involvement. Researchers noted that human direction and target selection remained part of the operation. Instead, the key development was what happened after that initial instruction. The AI system was able to carry out and adapt through multiple stages of the attack without requiring continuous human technical input.
Again, the concern is not necessarily that the attack was more sophisticated than those conducted by experienced threat actors. Rather, it suggests that AI may reduce some of the expertise, effort and decision-making historically required to execute complex cyberattacks. As AI systems become more capable, the barrier to conducting sophisticated malicious activity could be lowered, allowing attacks to be executed more quickly and at greater scale.
A potential shift in cyber risk
Taken together, these incidents raise an interesting question for cyber insurance. Historically, underwriting has operated against an implicit assumption that sophisticated attacker capability is relatively scarce.
There are highly capable threat actors, but their time, expertise and resources are finite. What we’re seeing through both of these attacks is early evidence that AI may begin to weaken that constraint.
If vulnerability discovery, reconnaissance, exploitation and adaptation can increasingly be automated, a less technically capable attacker may be able to conduct activity that previously required specialist knowledge.
An experienced attacker may also be able to operate against more targets at the same time and the result could be an increase in the number of organisations that are economically viable targets. That could ultimately become a frequency issue. The concern may not be a handful of highly publicised autonomous attacks. It may be the cumulative effect of more attacks being attempted because the cost of attempting them has fallen.
A shift towards less visible cyber risk
What this ultimately points to is a broader shift in the nature of cyber risk. The risk is moving, at least in part, from system failure to outcome failure. The technology operates as designed, but the outcome is compromised through manipulation or distorted inputs.
This type of exposure is more subtle. It can be harder to detect, harder to evidence and, in some cases, harder to attribute clearly to a single cause.
For insurers, this creates pressure in several areas:
Defining what constitutes a cyber event
Maintaining clarity around coverage boundaries
Assessing the effectiveness of controls in an environment where threats are becoming more adaptive
Arguably, this is where traditional approaches to cyber risk start to feel less well-aligned.
An evolving insurance challenge
It is too early to suggest that these incidents represent a fundamental change in cyber risk. The technology remains immature, the sample size is small and autonomous systems still have significant limitations. However, they provide early evidence supporting a concern that until recently was largely theoretical. In my previous article, I argued that AI was making cyber-attacks more effective by amplifying existing human vulnerabilities.
Hugging Face and JADEPUFFER suggest AI may also be changing the other side of the equation by making sophisticated cyber activity more accessible.
For insurers, the important question may therefore be less about whether AI creates entirely new forms of cyber-attack and more about whether it changes the economics of existing ones.
If the expertise and effort required to conduct a sophisticated attack continue to fall, the industry may eventually need to reconsider established assumptions around attacker capability, attack frequency and ultimately cyber loss development.
What we’ve seen is the first phase of AI-driven cyber risk has made the human easier to manipulate.
The next may make the attacker easier to become!
This article is provided for informational purposes only and does not constitute insurance, legal, regulatory or investment advice. The observations and opinions expressed are based on information available at the time of writing and are subject to change.