Dutch Association of Insurers

07/30/2026 | News release | Archived content

AI: a curse or a blessing? (2)

  1. Home
  2. Publications
  3. News
  4. AI: a curse or a blessing? (2)

AI: a curse or a blessing? (2)

Content is also available on this page exclusively for members Log in to get access to this content or request account.

Increasingly, AI supports insurance professionals in their work and helps customers with insurance questions. But AI also brings new cyber risks. "That poses a dilemma for insurers. Those who innovate too slowly can fall behind in terms of efficiency and service. But if you move too fast without developing digital resilience, you increase the risk of cyber incidents and data breaches," says Alex Douven, Insurance Lead at Fox-IT.

Actueel
30 July 2026

1. In the paper Are Benelux insurers moving too fast with AI, or not fast enough on resilience? you draw attention to the tension between AI applications and cyber resilience. What is going on?

"Insurers manage and use a lot of data to offer customers appropriate insurance and good service. It is therefore logical that they are increasingly using AI to improve their services and internal processes. Organizations must continue to innovate to remain relevant, but at the same time that innovation creates new cyber risks."

2. Can you give an example of that?

"AI applications only create real value if they have access to quality data, systems and other applications. With AI agents, who perform increasingly independent tasks, that access can be very far-reaching. If rights are insufficiently limited or an agent is manipulated, he can consult sensitive information, perform actions or gain access to other systems. For insurers, this may involve medical information, claims data and other highly sensitive customer data."

"And OpenAI maakte op 21 juli bekend that an AI agent had compromised an organisation's infrastructure. This makes it clear that AI systems not only create value, but can also access systems and data independently. Insurers must therefore include security in AI projects from the design phase, with clear boundaries on access, authorisations and autonomous action."

Summer series!

AI is hot. Insurers are experimenting with all kinds of AI. However, customers, companies and also malicious cybercriminals are not sitting still. In this second part of our summer series AI: a curse or a blessing?, Alex Douven discusses the tension between AI and cyber resilience. Curious to know more? Then also read deel 1 met Niels van der Laan (consultancy firm Milliman) about the investigation into fraud in car damage with AI-generated fake images.

3. Insurers are of course already working on their cyber resilience. Under DORA and NIS2, among others, they are obliged to protect themselves against digital risks. Why do you mention these regulations in the paper?

"DORA and the new Cybersecurity Act that comes into effect on August 15 are important frameworks and set a clear lower limit. At the same time, such frameworks are by definition generic, while a cyber attack often succeeds because of a specific detail. Think of a vulnerability, configuration error or weak process. So an organisation can be compliant and still be affected."

"In addition, AI is developing faster than legislation and security frameworks can be adapted. Insurers must therefore look beyond compliance and continuously assess whether their measures are still appropriate to new technology and changing attack methods. Experience shows that for this reason too, broad cooperation with industry peers and specialists is important."

"Insurers must continuously assess whether their measures are still appropriate to new technology and changing attack methods."

4. That sounds like a big challenge and time pressure...

"It is. A striker only has to be successful once, but as a defender you have to be good all the time. Attackers can find vulnerabilities faster, automate attacks and execute them on a much larger scale. At the same time, phishing, deepfakes and other forms of manipulation are becoming increasingly convincing and new attack methods are emerging."

"As indicated earlier, no organisation can keep up with that development alone. That is why cooperation and knowledge sharing between insurers, technology companies, cybersecurity specialists and public parties are essential. This goes beyond protecting one organisation. Insurers manage highly sensitive data and fulfil an important social function. A serious cyber attack can also affect customers, chain partners and confidence in the sector."

"Based on this importance of collaboration, Fox-IT is participating in OpenAI's Project Daybreak. Together, we explore how AI can help defenders respond to cyber threats faster and more effectively. We use the insights that emerge from this to make organisations and society more resilient."

5. Finally, what can insurers do today to stay ahead of cybercriminals, or to limit the damage as much as possible if things do go wrong?

"What you can prevent, you don't have to repair. But not every attack can be stopped. That is why prevention, detection, response and recovery must be well aligned. If one layer of security fails, the next layer must still stop the attack, flag it or limit the damage."

"Therefore, limit access rights, monitor deviant behaviour, control sensitive actions and ensure clear emergency procedures. Also make agreements with suppliers in advance and determine which processes should continue in the event of an attack and how systems will be restored. Practice this regularly."

"Technology alone is not enough. Everyone within an organisation is part of the defence, and can therefore unintentionally become a gateway for criminals. Employees must therefore know how to recognise suspicious requests, when to stop and through which independent channel they can monitor sensitive actions. Especially now that phishing, deepfakes and other forms of manipulation are becoming more and more convincing."

"Test AI applications before and after deployment, and make cybersecurity, fraud, privacy, compliance, operations, and vendor management work together from the start. If those parts fit together well, an organisation can recognise risks earlier and act faster and more effectively when things go wrong."

"And we are likely to see more and more incidents where AI agents act autonomously or where attackers use AI for new and more convincing attacks. Organizations that already take this into account can continue to innovate more safely."

Was this article useful?

Yes No

Thank you for the feedback

How can we improve?

500 / max 500 send

Insurance Academy

Verzekerbaarheid van overstromingsrisico's in buitendijks gebied

  • 09/10/2026
  • Online
  • Webinar

Insurance crime

The Centre for Combating Insurance Crime (CBV), part of the Dutch Association, supports insurers in tackling and preventing fraud, cybercrime and other forms of insurance crime. It does so at both the operational and policy levels.

Meer over dit thema
Dutch Association of Insurers published this content on July 30, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on August 27, 2026 at 13:37 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]