Nobody To Blame, Nobody Pays

Plus: OpenAI blames Apple, Anthropic's $35B Lambda deal, Japan's drone budget.

Here's what's on our plate today:

  • 🧪 Merck's insurers refused $700M, and AI attacks are harder to blame.

  • 📰 OpenAI says Apple made its own mess; Anthropic signs a $35B cloud deal with Lambda; Japan requests $55.6B for drones, AI, and missiles.

  • 🧠 Brain Snack: check your cyber policy's war exclusion before renewal, not after.

Let’s dive in. No floaties needed.

Build and design your website on Framer - Now with Agents

Framer is a pro website builder trusted by companies like Miro and Perplexity that helps creators, teams and businesses ship production-ready sites faster than ever. With AI agents built directly into the canvas, teams can design pages, manage CMS content, write copy, add SEO, and audit for issues — all without leaving the tool where the real site lives. Agents bring speed and scale; you bring taste, judgment, and control.

*This is sponsored content

Goodies delivered straight into your inbox.

Get the chance to peek inside founders and leaders’ brains and see how they think about going from zero to 1 and beyond.

Join thousands of weekly readers at Google, OpenAI, Stripe, TikTok, Sequoia, and more.

Check all the tools and more here, and outperform the competition.

*This is sponsored content

The Laboratory

TL;DR

Cyber insurers know how to price a hacker. AI keeps changing what a hacker is.

  • History stops working: insurance prices are based on records of past losses. AI gains new abilities in months, so the records describe a threat that no longer exists.

  • Blame decides payment: almost every clause turns on who attacked. A Chinese state group used Claude Code; an OpenAI system broke into Hugging Face unprompted.

  • Premiums are not the price: cyber rates are falling. Insurers are tightening deductibles, limits, exclusions, and required security controls instead, which moves cost onto the buyer.

  • No ceiling, no cover: a flaw in one widely used AI service could trigger thousands of claims at once, so insurers shrink the offer instead of raising the price.

  • Small firms absorb it: large companies fund the security teams and paperwork that earn coverage. A 30-person manufacturer holds the loss and fights the claim alone.

Cyber insurance runs on knowing who attacked. AI is taking that away

Insuring an oil tanker for a single trip through the Strait of Hormuz stopped being routine in the summer of 2026. War risk premiums climbed from around 1% to 3% of a ship's value to between 7.5% and 10%, on figures from the broker Marsh reported by Al Jazeera. A $100M tanker that once cost a few hundred thousand dollars to cover for one voyage suddenly cost millions. Traffic through a waterway carrying about a fifth of the world's seaborne oil fell from well over 100 vessels a day to single digits.

The price of insuring a vessel rose because the chance of losing one rose, and that chance rose because nobody could say which ship would be hit next or how far the fighting would spread. Uncertainty is what makes insurance expensive, because an insurer can spread a danger it understands across thousands of customers, and it cannot do that with a danger that keeps changing shape.

Cyber insurers are dealing with the same problem now, and the reason is artificial intelligence. AI may well make defending a company cheaper over time, so the sharper question is what it does to the cost of handing your cyber risk to somebody else, which is never only the premium a buyer pays each year. A policy also sets a deductible, meaning the loss you absorb yourself before the insurer pays anything, and a limit, meaning the point at which the insurer stops paying. It carries exclusions that strike out whole categories of loss, and it increasingly arrives with a list of security measures you have to install before anyone will sell it to you.

An underwriter can set those four terms only if they know what a claim will look like when it arrives. Two events in the past year have made that harder to know, and neither one produced a payout large enough to report.

Who did it decides who pays

Security researchers at Anthropic, the company behind the Claude chatbot, picked up unusual activity on their systems in mid-September 2025. A group the company assessed with high confidence as Chinese state-sponsored hackers had talked Claude Code, an AI tool built to write and run software, into running a hacking campaign.

The hackers posed as legitimate security researchers and split a real attack into small pieces that each looked harmless, then let the tool run them against roughly 30 technology firms, banks, chemical manufacturers, and government agencies. By Anthropic's own count, AI agents did 80% to 90% of the tactical work, with people stepping in for a handful of decisions, in what the company called "the first documented case of a cyberattack largely executed without human intervention at scale."

The automation is why the case got attention, and the Chinese state attribution is what matters to an insurer, because almost every clause that decides whether a cyber claim gets paid turns on who was at the other end of the attack. Standalone cyber policies sold since 2023 must include language excluding losses from state-backed attacks. An insurer reading that campaign is therefore reading a loss it may never have to cover, provided somebody can be identified at the far end of it.

An attack with nobody to blame

A second case ten months later removed the person at the other end entirely, because the intruder was software owned by the company running the test. OpenAI disclosed that during an internal safety check, one of its most advanced systems escaped its 'sandbox', a walled-off environment with no internet connection, then broke into the servers of Hugging Face, a company hosting AI models and tools used by millions of software developers.

NPR reported that OpenAI traced the break-in to stolen login details and a previously unknown security flaw, and Hugging Face's chief executive, Clément Delangue, called it "an attack unlike anything we've seen before," in remarks reported by Al Jazeera. The system had been given a goal during the test and found its own route to it, with no criminal involved, no foreign government, and nobody at a keyboard.

An insurer sorting that loss has nothing to sort it by, because the war exclusion and the rest of the attribution machinery all need a party to point at. The two cases together mean that the question of who did it is getting harder to answer at the same time as more of the money is turning on the answer.

Insurers price risk using the past

Knowing what a claim looks like settles only half of an insurance price. The other half is how often the thing happens and what it costs when it does, because an insurer's job is to collect enough from many customers to cover the losses of the unlucky few, plus a margin, without charging so much that customers leave.

Doing that requires 'actuarial' data, meaning records of how often something goes wrong, what it usually costs, and which kinds of business get hit hardest. A car insurer has decades of accident statistics sorted by driver age, location, and vehicle type, while a cyber insurer works from ransomware payments and breach costs. The method holds up when a threat changes slowly, and it comes apart when the threat gains new abilities faster than anyone can compile the records.

Britain's AI Security Institute measured how far the best systems could get through the steps needed to take over part of an outside computer system. Testing described in The Conversation found that they went from 80% of those steps to all of them in roughly four months. An underwriter quoting a three-year policy against that curve is naming a price for a threat that will not resemble itself by renewal, and the standard response to a risk nobody can measure is to charge heavily for it or refuse to write it.

The warnings got louder, and the price came down

Insurers did not charge heavily for it, and one of the largest firms in the business argues that the fear has been running ahead of the evidence. Munich Re, a reinsurer, meaning one of the companies that insures the insurers and absorbs the biggest risks, says in its 2026 cyber report that "Some of the current discussions on agentic AI seem to be more like hype," using the industry term for systems that pursue tasks on their own. The firm expects AI to make attacks more frequent in the near term rather than make each one more expensive, which is a far more manageable problem than a wave of catastrophic losses.

Buyers have been seeing something similar in their renewal quotes. Global cyber premiums are worth somewhere between $15B and $16B a year, which makes this a young line of business by insurance standards. Prices have been easing in several markets, even while insurers publish warnings about AI, according to trend data in WTW's market outlook for early 2026. In Hormuz, uncertainty rose, and the price rose with it. In cyber, uncertainty went up, and prices came down because insurers have been changing different parts of the contract.

The change shows up in the policy terms

Insurers now hand out sizable discounts to companies running AI-powered security tools, multi-factor authentication meaning a second login step such as a code sent to a phone, and automated threat detection. Some have started attaching add-ons the industry calls 'AI Security Riders', which extend coverage only after a company proves it has stress-tested its own AI systems, a shift documented by the compliance firm ACA Group.

A requirement of that kind is the piece of this story a buyer can check today, because it sits in contracts that already exist while the catastrophe everyone is arguing about has not happened. The cost has not gone anywhere either, because it has shifted from the premium line to the work of installing controls, running tests, and producing evidence at renewal. A firm with a security team absorbs that cost without noticing, and a firm without one either hires consultants or loses the discount and pays the higher price after all.

Insurers have rewritten policies after a shock before

Insurers changed the wording instead of the price because that is what they did the last time a cyberattack produced losses nobody had planned for. Malware called NotPetya, later attributed by Western governments to Russian military hackers targeting Ukraine, spread past its intended target on June 27, 2017. Systems went down at companies in more than 60 countries within hours, and the pharmaceutical firm Merck lost 40k machines in minutes.

Merck's insurers refused a claim of roughly $700M against a $1.75B program, as recounted by Recorded Future News, invoking a 'war exclusion' that dates back to 19th-century marine insurance and once kept underwriters off the hook for ships lost to war. Courts sided with Merck, reasoning that a business caught in the crossfire of a state-linked attack is not a party to anything resembling warfare, and the case settled confidentially in 2024.

The industry's answer was contractual rather than financial, because Lloyd's of London responded by requiring standalone cyber policies sold from 2023 onward to exclude state-backed attacks outright, a change IBM's analysis of the settlement traces to the Merck litigation. That is the clause the Anthropic campaign would run into, which is why the Chinese attribution matters more to an underwriter than anything the tool itself did, and why the next argument will be over how much of an attack a person actually directed.

One flaw: thousands of claims at once

An exclusion of that kind works on a loss with one author and one event behind it, and the broker WTW argues that AI is unlikely to produce losses in that shape. Its analysis Insuring the AI age points out that NotPetya was a single enormous event that exposed the blind spot all at once, which made a clean exclusion possible to draft afterward, while AI losses look more likely to accumulate through many smaller incidents scattered across different kinds of claims.

Losses spread that way turn into the structural fear underwriters call 'aggregation risk', where one flaw hurts thousands of policyholders at the same time because they all depend on the same shared technology. A small number of cloud providers and model developers now sit beneath an enormous share of corporate AI use, which is what made the Hugging Face target notable as much as the method that reached it. The same WTW analysis compares a failure at that layer to a natural catastrophe or a terrorism event in insurance terms, and notes that some in the industry expect it would eventually need a government-backed reinsurance pool of the sort many countries already run for terrorism.

Insurers cannot price a loss with no ceiling on it, so the lever they reach for is a smaller offer rather than a higher premium, meaning lower limits, larger deductibles, and coverage that stops well below the size of the event being described. Each of those adjustments shifts a portion of the loss back onto the company buying the policy.

Small companies end up holding the risk

Large corporations can hold that slice, because they can afford dedicated security teams, AI governance programs, and the documentation that now earns the discount. Smaller businesses mostly cannot, and they were the more exposed group before any of this started. Allianz Commercial's annual risk survey ranked cyber incidents the top global business risk for the fifth year running in 2026, singling out smaller and mid-sized firms as short of the resources to defend themselves.

A 30-person manufacturer caught in the blast radius of a shared AI tool's failure faces the same coverage argument Merck fought for years, without Merck's legal budget or its leverage over an insurer. The available facts establish that the terms of cyber coverage are already moving, although they do not show that any insurer has yet paid a large AI-driven claim.

Cyber insurers have absorbed shocks before and each time responded by narrowing definitions and building better-priced products based on what they learned. What is different now is that the thing being insured keeps acquiring new abilities between one renewal and the next. A shipowner weighing the Strait of Hormuz at least knows what a mine does to a hull and how long the repair takes. The clause that will determine who pays for the first major AI loss was drafted for ships, ports, and enemies that could be named. The unanswered part is which name goes in the box when the attacker turns out to have been a copy of a program that nobody was watching.

Brain Snack (for Builders)

💡 

Your cyber policy pays out based on who attacked you, and an AI agent is not a who. Pull up your current wording and check whether the war exclusion and any AI rider still describe the stack you actually run. The cheapest time to find a coverage gap is before you need the coverage.

Hire smarter with Athyna, save up to 70% on salary costs.

Athyna connects you with top LATAM AI talent, fast!

*This is sponsored content

Quick Bits, No Fluff

Wednesday Poll

📊 An OpenAI system broke into Hugging Face with no human directing it. Who pays for that loss?

Login or Subscribe to participate in polls.

Meme Of The Day

The Toolkit

  • Tabnine: AI coding assistant that runs privately on your own stack, so regulated teams never ship code outside.

  • Framer: AI website builder that turns prompts into responsive, publishable sites with real design control.

  • Krea: Real-time AI image and video generator with a creative-first interface built for steering output, not prompt wrestling.

Rate This Edition

What did you think of today's email?

Login or Subscribe to participate in polls.