After Mythos: Why Your Cyber Insurance Policy May Not Cover What Comes Next
In April, Treasury Secretary Scott Bessent and Federal Reserve Chair Jerome Powell did something that should have set off alarm bells in every boardroom in America. They summoned the CEOs of the nation's largest banks — Citigroup, Morgan Stanley, Bank of America, Wells Fargo, Goldman Sachs — to a closed-door meeting about a single AI model.
Weeks later, asked on Fox News whether Americans should be worried about AI being used to hack their bank accounts, Bessent gave a two-word answer: "You should."
When the Treasury Secretary and the Fed Chair convene an emergency session over a cybersecurity capability, the ripple effects don't stop at banking. They reach your organization's risk posture — and specifically, the insurance policy you're counting on to absorb the impact.
Here's the problem: that policy was almost certainly written before Mythos existed.
The Coverage Gap Nobody's Talking About
Fitch Ratings put it bluntly in April: Anthropic's Mythos model will likely create more vulnerabilities than patches in the short to medium term. Their reasoning is straightforward — traditional vulnerability research was expensive, slow, and labor-intensive. Mythos fills that gap at machine speed. The threat picture isn't shifting gradually. It's already shifted.
The insurance industry is scrambling to catch up. In January 2026, ISO released two new endorsements — CG 40 47 and CG 40 48 — that allow carriers to exclude generative AI claims from standard commercial general liability policies. CG 40 47 is the broad version: it bars coverage under both bodily injury and personal injury for any harm linked to generative AI outputs. If a claim has any meaningful connection to a generative AI tool, the carrier can deny it.
By April, major carriers including Chubb, Travelers, W.R. Berkley, and Berkshire Hathaway had filed to adopt these endorsements or their own proprietary AI exclusion language. State regulators approved more than 80 percent of submitted filings. Industry projections suggest 95 percent of carriers will ultimately adopt some form of AI exclusion on their commercial general liability books.
That's the general liability side. On the cyber insurance side, the picture is equally uncomfortable. Forty-two percent of policies now explicitly exclude AI misuse or liability. Over 40 percent of businesses that file a cyber insurance claim receive no payout — and those denial rates were climbing before Mythos-class threats existed.
In my experience, most boards treat cyber insurance as the backstop — the thing that catches you when everything else fails. But backstops only work if they're actually behind you when you fall.
When Regulators Hit Pause, Boards Should Hit the Gas
In May, the Federal Reserve and the Office of the Comptroller of the Currency took an unusual step: they paused some cyber-related examinations of the biggest U.S. banks. Not because the banks were secure — because the threat model had changed so fast that existing exam frameworks couldn't keep up with the vulnerabilities Mythos was uncovering.
This wasn't a retreat from oversight. It was an admission that the old playbook needed rewriting. And while regulators recalibrate, AI oversight is expanding in other directions — U.S. banking regulators have begun incorporating AI scrutiny into every routine bank examination, pressing lenders on governance, kill switches, and vendor risk.
For boards outside the banking sector, the message is clear: if federal regulators are admitting their frameworks are outdated, what makes you confident your organization's risk management is current?
The Caremark Problem
Here's where this gets personal for directors. Under Delaware's Caremark doctrine, board members face potential liability if they fail to implement reporting systems for known risks — or if they ignore red flags within existing systems. Cybersecurity has been on the Caremark radar for years, but Mythos changes the calculus.
The Treasury Secretary has publicly warned that AI can hack bank accounts. Federal regulators have paused exams to recalibrate. Anthropic and its Glasswing partners have found more than ten thousand high- or critical-severity vulnerabilities in the world's most important software. In June, the company expanded Glasswing to 150 additional organizations across 15 countries, including critical infrastructure operators in power, water, and healthcare.
If a board knows — or should know — that Mythos-class capabilities exist and fails to ensure the organization's cyber risk governance accounts for them, that's a potential Caremark claim. Three in four boards have approved major AI investments, but fewer than half have set governance expectations for AI risk. The gap between investment and oversight is exactly the kind of thing that creates liability.
In Cyber Risk Is Business Risk, I describe the "sheriff" metaphor for AI governance — the idea that every organization needs someone accountable for how AI affects its risk posture. That metaphor has never been more literal. When the threat itself is AI-powered, the governance response can't be an afterthought.
For the full AI governance framework and the "sheriff" metaphor, see Chapter 8 of Cyber Risk Is Business Risk.
What to Ask Your CISO — and Your Broker — This Week
The standard board question is: "Are we insured?" The right question now is: "Are we insured for this?"
Ask your broker: Does our cyber policy contain AI-related exclusions? What about the CGL policy? If a breach is traced to a vulnerability discovered by an AI model — or exploited using AI-generated techniques — does coverage apply?
Ask your CISO: Have we updated our threat model to account for Mythos-class capabilities? If an attacker uses AI to find and exploit a zero-day in our systems tomorrow, what's our response plan — and does our insurance carrier know about it?
Ask your general counsel: If regulators are pausing their own frameworks to recalibrate for AI, are we confident our D&O coverage accounts for the liability exposure? Caremark claims don't require a breach. They require a failure to govern.
Ask yourself: When this comes up at the next board meeting — and it will — can you demonstrate that the organization took concrete steps after the Mythos announcement? The answer matters more than you think.
The Bottom Line
The cyber insurance market is growing — projected to hit $20 billion this year, with premiums rising 15 to 20 percent. But growth in the market doesn't mean growth in your coverage. Carriers are simultaneously expanding cyber insurance products and narrowing what those products actually cover. The exclusions are multiplying faster than the policies.
Mythos didn't create this problem. It accelerated a reckoning that was already coming. The gap between what AI can find, what organizations can fix, and what insurance will cover is widening with every Glasswing expansion. Your board's job isn't to close that gap overnight. It's to prove — to regulators, to shareholders, to a Delaware court if it comes to that — that you saw it, you governed it, and you didn't look away.