AI Manipulation Is the New Cyber Risk: When AI Systems Make Bad Decisions on Purpose
Every board thinks it knows what a cyberattack looks like. An attacker breaks in, steals data, encrypts systems, and demands a ransom. That mental model built the entire cyber insurance industry. In fact, it’s still the most common shape a cyberattack takes today, but it’s no longer the most dangerous one.
Insurers built entire product lines around that familiar sequence. Boards built incident-response plans around it, and regulators built breach-notification laws around it too. All of that infrastructure assumes an attacker wants to take something from you.
That assumption, however, is now the outdated part of the story. A new playbook is emerging, and it’s quieter and harder to detect. Arguably, it’s far more dangerous, too. Yet most companies haven’t updated their risk registers for it.
👻 From Loud Breach to Silent Manipulation
Ransomware announces itself. Screens lock, ransomware renames your files, and a ransom note appears on the screen. It’s violent, visible, and, critically for insurance purposes, provable. So you know the moment it happened, and you know what the attacker touched. From there, you can point to a dollar figure for downtime, recovery, and extortion payments.
The emerging threat, by contrast, doesn’t announce itself at all. Instead of stealing your data, an attacker quietly alters it. Instead of locking your systems, the attacker manipulates what those systems believe to be true. Increasingly, the target isn’t a database or a file server, but the AI model or agent your company now trusts. That system summarizes reports, flags fraud, prices risk, routes shipments, and approves transactions on your behalf.
The contrast is worth spelling out plainly, because it’s the whole reason this shift matters:
- Ransomware breaks in, steals or locks data, and announces itself within hours through a ransom note or a leak-site posting.
- Silent manipulation alters data in place, leaves systems running normally, and can stay invisible for months.
- Ransomware produces a clear “before and after” that forensics teams can trace and insurers can price.
- Silent manipulation, meanwhile, produces a slow drift toward wrong decisions, with no single moment that looks like a breach.
Data Poisoning: Corrupting What AI Learns
Security researchers have spent 2026 sounding the alarm on this exact shift. Data poisoning means quietly corrupting the information an AI model learns from or retrieves. Industry threat reports now describe it as a live, active risk rather than an academic one. Specifically, these attacks reach across the entire AI lifecycle, touching training data, fine-tuning sets, and the real-time information agents pull in to do their jobs.
A poisoned system rarely looks broken, since its overall performance can appear completely normal. That’s exactly what makes it dangerous. As a result, the system can operate for months, making a slowly increasing number of quietly wrong calls, before anyone notices.
Prompt Injection: Hijacking What AI Does
Prompt injection has followed a similar trajectory. AI agents have moved from answering questions to actually doing things, such as reading inboxes, writing to CRMs, running database queries, and approving payments. Consequently, security researchers now flag prompt injection as the most exploited weakness in enterprise AI systems in 2026.
The mechanics, unfortunately, are almost unfair to defenders. An AI agent can’t reliably tell the difference between a real instruction and a fake one, since a malicious instruction can hide inside a document, an email, or a web page the agent has been asked to process. Give an agent access to sensitive data, exposure to outside content, and the ability to take action, and you’ve built exactly the conditions attackers need.
Regulators have taken notice too. For instance, international cybersecurity agencies issued joint guidance on agentic AI risk in May 2026. Similarly, the EU AI Act’s high-risk AI obligations demand documented resilience against this kind of manipulation, and those obligations became fully enforceable this August.
Put these two trends together, and a new kind of business risk emerges, one that has nothing to do with data leaving the building. An attacker manipulates the systems, then the information, then the AI making decisions on top of it all. The company, in turn, ends up making a fully legitimate-looking decision based on information that was never true. That decision might approve a vendor, ship an order, clear a transaction, or price a policy.
There’s no ransom note in this scenario, and no dark-web leak site either. Instead, there’s just a company confidently executing on a corrupted picture of reality. No one inside the building knows it yet.
📉 Why This Is a Harder Story Than Ransomware
Ransomware is a bad Tuesday. This emerging threat, by comparison, is a bad quarter you don’t even know you’re having.
Consider what actually happens when an attacker feeds a fraud-detection model a stream of mislabeled “safe” transactions. Or, alternatively, slips a poisoned document into the corpus an AI agent uses to draft supplier contracts. Or injects hidden instructions into a webpage a procurement agent is summarizing. In each of these scenarios, the company doesn’t lose data. It loses truth instead. Consequently, every downstream decision inherits that corruption, from a payment approved to a shipment released to a supplier onboarded, and each one still looks entirely legitimate on paper.
That’s a fundamentally different threat model than an attacker breaking in and stealing two million records. It’s closer to sabotage than theft, and it touches nearly every function in the business at once. That combination, ultimately, is exactly why it’s such an interesting, and uncomfortable, insurance question.
🧩 What, Exactly, Is the Loss?
This is where the story stops being a security problem and becomes a genuinely hard risk-transfer problem. A single manipulation event can ripple across nearly every line of coverage a company owns, and none of them were really built with this scenario in mind.
The First-Party and Liability Lines
- Cyber liability: the obvious first call. However, insurers drafted most cyber forms around unauthorized access and system disruption, not quiet, authorized-looking data alteration by a system doing exactly what it was designed to do.
- Business interruption: real financial loss follows from the fallout, but proving a covered cause of loss gets complicated when nothing ever goes offline. The systems worked fine; they just worked on lies.
- Errors and omissions: your product might be a decision, a recommendation, or an analysis. So if an attacker corrupted that output upstream, is that a professional failure, and whose failure is it?
- Crime and fraud: this fits better when a human authorizes a fraudulent payment based on manipulated information. Still, crime policies are narrow about how the fraud has to occur, and many carve out losses tied to a compromised computer system.
The Operational and Governance Lines
- Product liability: manipulated manufacturing or quality data can lead to a defective product reaching customers. In other words, that’s a product liability claim wearing a cyber incident’s clothes.
- Supply-chain risk: one poisoned data feed can reach several vendors at once, producing simultaneous, correlated losses across multiple companies, a nightmare for concentration risk.
- Reputational harm: arguably the largest and least insurable piece of all. After all, “our AI made bad calls for six months” is a headline no breach-response PR can undo.
- D&O: if a manipulation event goes undetected for months, shareholders may argue the board failed to oversee AI governance adequately. That exposure, in turn, lands squarely on directors and officers.
Overall, no single policy is built to catch all of that, and the industry hasn’t yet agreed on which one is supposed to catch most of it.
❓ The Most Important Question
Here’s the one that should be keeping underwriters, brokers, and risk managers up at night. If your company’s data is altered but never stolen, do you actually have a cyber claim?
It sounds like a technicality, but it isn’t. Cyber and property policies still lean on old concepts: unauthorized access, theft, breach, and, in older property forms, direct physical loss. Courts, for example, have repeatedly wrestled with whether electronic data even counts as covered property at all. Insurers have often argued, successfully, that data loss without physical damage to hardware falls outside traditional first-party coverage. Some newer cyber forms, admittedly, explicitly address data alteration, corruption, or destruction. Even so, plenty in the market today still assume the loss looks like exfiltration or encryption, not quiet, undetected modification by a system nobody ever technically breached.
Now consider the harder version of the question. Suppose the manipulation happened through an AI agent operating exactly as its permissions allowed, reading a poisoned document or trusting a manipulated data feed while doing precisely what it was authorized to do. In that case, was there even unauthorized access in the first place? Many current cyber definitions hinge on exactly that phrase, and a sophisticated attacker doesn’t need to break down a door when they can simply feed the system through the front one.
This isn’t a hypothetical for the insurance industry to solve eventually. Rather, it’s a live gap, forming right now, between how attackers actually attack AI systems and how insurers actually word the policies meant to cover them.
🧭 What This Means for Risk Leaders Now
Three things, therefore, are worth doing before this stops being theoretical for your organization. None of them require waiting for the market to catch up first.
- Ask your broker the alteration question directly. Don’t assume cyber liability covers manipulated-but-not-stolen data. Instead, get it in writing, line by line, across cyber, crime, E&O, and property.
- Map your AI decision points like you’d map a supply chain. Any AI system with the authority to approve, recommend, price, or release something is now a potential loss trigger, so it deserves the same governance rigor as a financial control.
- Treat data provenance as a board-level topic. After all, a regulator or plaintiff’s attorney may eventually ask how the company verified the information its AI was acting on, and you’ll need a better answer than “we assumed it was fine.”
The ransomware era taught companies to ask whether someone got in. The next era, by contrast, will force a harder question, and it has nothing to do with access at all. Can you actually prove your data, and your decisions, are still telling the truth?
Ultimately, that’s not just a cybersecurity problem anymore. It’s an insurance problem, a governance problem, and increasingly a board problem, all at once.
Have questions about how this shift in cyber risk could affect your business, your balance sheet, or your board’s oversight duties? PolicyAdvantage.com is here to help you make sense of it.
Sources: Obsidian Security, “AI Data Poisoning: How Corrupted Data Undermines Trust in Agents” (2026); Lakera, “Introduction to Data Poisoning: A 2026 Perspective” (2026); Sysdig, “The Comprehensive Guide to Prompt Injection Attacks in 2026” (2026); Atlan, “How Prompt Injection Attacks Compromise AI Agents in 2026” (May 2026); Anderson Kill P.C., “Potential Insurance Coverage Issues Resulting From A Cyber Breach” (2025)










