If AI can change cyber risk in a matter of days, why are so many insurers still only assessing it once a year? Claud Bilbao, VP Underwriting & Distribution at Cowbell, argues that cyber renewal as we know it has had its day, as regulators put weight behind a more dynamic approach.

For years, cyber insurance has relied heavily on point-in-time underwriting and annual renewal cycles, with annual submissions and questionnaires still the prevailing approach to traditional risk assessment across much of the industry. And for many of those years – when cyber risk changed relatively gradually – that model was enough, providing a reasonable picture of an organisation’s risk.
But that’s no longer the case, and arguably hasn’t been for some time. With AI fast-forwarding the pace at which vulnerabilities can be discovered, exploited and scaled, the risk assessed at renewal now has the very real possibility of looking very different months, even days later.
Let it be said, though, that the case for continuous risk assessment is far from new. Advocating models that monitor risk more dynamically is something we’ve been doing since we were founded. Our view has always been: don’t wait for a breach to happen; actively monitor risk and provide actionable insights, and effectively act as an outsourced security co-pilot for SMEs.
So although we and others have argued for many years that underwriting cyber once a year while risk exposure changes daily doesn’t make sense, it’s only now that regulators are putting some weight behind the same argument. In May, 2026, the FCA, Bank of England, and Treasury issued a joint statement explicitly stating that frontier AI models operate at “a significantly higher speed, greater scale, and lower cost”, and that continuous, AI-vs-AI defence is now a baseline expectation, not a luxury. It acknowledges what modern insurtechs have been seeing – and experiencing – at the coalface for years: static, human-led defenses are fundamentally obsolete. For me, it’s a massive market inflection point that forces the entire insurance market to abandon the “dormant policy” mentality and accept that risk is dynamic.
“Appropriate insurance”
Part of the regulators’ statement talks about how firms should be taking active steps across several domains to plan for and mitigate cybersecurity risks posed by frontier AI. Interestingly, alongside governance, proactive investment, and threat containment, they also advise considering “appropriate insurance”.
Historically, regulators viewed cyber insurance largely as a financial risk transfer mechanism – a payout to help a company survive after the worst had already happened. But embedding this into advice suggests that regulators are finally catching on to the need for modern cyber insurance as an active part of operational resiliency.
A policy that just sits in a drawer, however, does not fulfill regulators’ expectation of “detective, threat containment, and cyber response capabilities”. Today, “appropriate insurance” implies an active, continuous partnership.
The knock-on effect
This change – whereby regulators align better with the long-held opinions of modern insurers – should be good for the industry. It raises the bar for what cyber insurance can deliver and creates a much-needed push towards more active, responsive protection.
But for those that choose not to keep pace, the consequences could be quite negative, both for insurers and organisations.
Looking at the insurance sector first, it’s a change that will undoubtedly impact insurers’ price risk. For legacy carriers in particular – those that continue to rely on the ‘quote and hope’ method of annual renewals – there’s a real risk they’ll face debilitating loss ratios if AI-driven systemic attacks outpace their pricing models. If an insurer is pricing 2026 frontier AI risks – which enables the rapid exploitation of “a potentially large number of vulnerabilities” at scale – and they do so using data from 2024 and a static PDF questionnaire, they’re essentially flying blind. One of the biggest mistakes an insurer could make when analysing cyber risk, other than treating cybersecurity and insurance as separate silos, is asking a business to fill out a 40-page application once a year – it really is an insult to the speed at which frontier AI operates.
We know that risk no longer sits still; it fluctuates daily. Therefore, insurers have no choice but to adopt continuous underwriting models and start integrating continuous monitoring/resilience into the underwriting and risk management lifecycle if they are to survive.
Insurers must also recognise that you simply cannot fight machine speed with human speed, and accept that right now, we are squarely in an arms race. It’s AI vs. AI, and insurers must supply the defensive firepower and use AI to ingest and analyse vast data lakes, spotting supply chain vulnerabilities and third-party risks (like open-source software flaws) in real-time. Only by deploying active AI agents within workflows can insurers identify anomalies and alert policyholders to patch vulnerabilities before a malicious frontier AI model can exploit them.
On the other side of the coin, we have organisations, where those that don’t prioritise good cyber hygiene can expect consequences that are equally worrying. Looking again at the regulators’ statement, it warns that those underinvesting in core fundamentals will become “progressively more exposed”. And that’s because frontier AI lowers the barrier to entry for cybercriminals, so the attack surface broadens massively.
The biggest mistake here is SMEs assuming that they are too small to be targeted. Frontier AI removes the manual labor of hacking, meaning that threat actors can launch more sophisticated attacks against high-street businesses at massive scale and at very little cost. Also, organisations mistakenly treat cyber risk as an isolated IT problem rather than a board-level governance and liability issue, which the regulators are explicitly targeting in their statement.
All of this has a knock-on effect on insurance, and, in fact, legacy carriers are already retreating from sectors they deem too complex to underwrite. Very soon, businesses that cannot demonstrate continuous vulnerability management will not just face ‘forbidden’ premiums – they will fail to secure capacity entirely. This is when the gap between the cyber-conscious and the uninsurables will widen dramatically, and broker guidance will become more critical than ever.
The death of the dormant policy
While the regulators’ message is clear – that cyber resilience must keep pace with frontier AI – the question now is how quickly the wider regulatory framework will catch up with the reality of the risk.
Looking ahead over the following year or two, I see regulatory guidance only hardening into strict enforcement, and I think that will happen very rapidly.
I also see a rise in Directors & Officers (D&O) and Professional Indemnity (PI) claims intertwining with cyber claims, as boards are held personally accountable for failing to govern AI risks, while brokers will face intense pressure to transition from transactional administrators to strategic risk advisors. They will need to ask tough questions about a client’s third-party software and AI hygiene at renewal.
But the biggest change will be the death of the dormant policy. The market will force the obsolescence of the static, traditional cyber policy, replacing it entirely with continuous, AI-driven risk management services that keep pace with the threat landscape. Those already operating this way will have a head start. For the rest, it’s time to catch up.

Be the first to comment