Skip to main content
Cybersecurity

The Current

The Current #8 — Your Insurer Already Knows Your Ransom Ceiling. So Do the Attackers.

Ransom negotiation math, the new AI Security Riders voiding cyber claims, and the EU AI Act delay that only applies to some of you.

Charles Redding, Founder, DLegendDigital6 min read

A few weeks ago I told a story about a CISO who said the hardest part of a ransomware call wasn't the ethics of paying — it was realizing nobody in the room had actually done the math. That story made the rounds, so this issue does the math. Three things changed in the last two weeks that touch the same nerve: what insurers now expect, what a ransom negotiation actually buys you, and which AI Act deadline just moved out from under companies that were racing toward it.

Negotiation Cuts Ransom Demands by Roughly Half — but Insurers Already Priced That In#

Coveware's latest incident-response data shows professional negotiators reduce ransom demands by an average of 47%, with actual payments landing around 8.7% of the attacker's opening ask. Cowbell's 2026 claims report puts the reduction higher, at roughly 65%, and shows insured victims paying a median $345,000 versus $568,000 for uninsured ones. Average ransom payments overall have fallen sharply — Coveware clocked Q3 2025 at $377,000, down 66% quarter over quarter — as more victims decline to pay outright (payment rate near 20%, a historic low) thanks to better backups and law-enforcement guidance.

The two firms disagree on the exact percentage, which is itself the point — negotiation outcomes vary enormously by attacker group, how fast you contained the incident, and whether you had a real restore path. What both agree on: insurers now build negotiation savings into how they price and structure policies. 58% of cyber policies carry ransomware sub-limits, capping coverage at 50-75% of the total policy — meaning the "insurance will cover it" assumption is quietly less true than it was two years ago.

Pull your actual policy and find the ransomware sub-limit, not just the headline coverage number. If nobody in your org has checked that number since renewal, that's this week's task — not because you're likely to need it, but because the gap between what you think you're covered for and what you're actually covered for is exactly where the CISO in that story got surprised.

Insurers Are Adding "AI Security Riders" — and a Redaction Gap Can Void Your Claim#

Cyber carriers including Chubb, Beazley, and Travelers are introducing AI-specific policy addenda — "AI Security Riders" — that condition coverage on documented AI controls: an inventory of every AI tool in use (including embedded AI features in ordinary SaaS), evidence of red-teaming, and technical controls that stop sensitive data from reaching an AI tool unredacted. Several carriers now write "condition precedent" clauses — coverage is void if a breach forensic audit finds sensitive data was sent to a third-party AI tool without masking first.

This isn't a future problem. If your team adopted an AI coding assistant, support chatbot, or analytics copilot in the last year without formally inventorying it, you may already have a claim-voiding gap sitting in production, discoverable only in the worst possible moment — during the forensic review after an incident.

Before your next renewal, get one page listing every AI tool touching customer or regulated data, and confirm whether the vendor sees your data unredacted or masked. That single document is what an underwriter — or a forensic auditor after a breach — will ask for first.

The EU AI Act's August 2 Deadline Just Moved — but Only for Some of You#

The EU's "AI Omnibus" simplification package received final sign-off from the Council of the EU on June 29, 2026. The headline change: standalone high-risk AI system obligations under Annex III (education, employment, credit scoring, critical infrastructure, and similar categories) are delayed from August 2, 2026 to December 2, 2027 — a 16-month reprieve. Separately, the simplified compliance track originally built for small and medium enterprises now extends to a new "small mid-cap" category: companies under 750 employees and €150M revenue get simplified technical documentation, more proportionate quality-management rules, and priority sandbox access.

Plenty of US companies with EU exposure were racing toward an August 2 wall that, for standalone high-risk systems, no longer exists. That doesn't mean August 2 is irrelevant — general-purpose AI model obligations and other non-Annex-III provisions still land on schedule. The delay is specific to standalone high-risk systems, not a blanket postponement.

If your compliance plan was built around an August 2 hard stop for a high-risk AI system, go confirm which category your system actually falls into before you spend the budget. If you qualify as a small mid-cap under the new definition, check whether the simplified documentation track changes what your team needs to produce at all.

How This Impacts Your Organization#

The principle doesn't change with company size: every item above is really the same question — do you know your real number before the day you need it, or do you find out live, on a clock someone else set? What changes by size is who's asking that question, how much room they have to get the answer wrong, and where their leverage actually sits.

Large Enterprises (1,000+ employees)

Your risk isn't ignorance — it's fragmentation. Somewhere in your org, someone knows the ransomware sub-limit, someone else has the AI tool inventory, and a third person is tracking the EU AI Act timeline, and they've likely never compared notes. Your leverage is scale: you can afford a named owner for "insurance and AI-incident readiness" who pulls all three threads into one review before the next renewal, not three people surprised separately during three different incidents. Put that name on paper this quarter.

Mid-Size Organizations (100-999 employees)

You feel this fastest because one person is probably wearing all three hats — IT, security, and whoever reads the insurance policy. The overcorrection to avoid: panic-buying an AI governance platform to solve the redaction-gap problem before you've even done the one-page tool inventory. Start with the inventory (free, one afternoon), then the sub-limit check (free, one phone call to your broker), then decide what, if anything, needs a tool.

Small & Growing Organizations (under 100 employees)

Don't chase an AI Security Rider you don't have yet, and don't assume the EU AI Act delay means you can ignore AI compliance if you have any EU customers — the delay is narrow, not a reprieve for everyone. Your discipline is lightweight: know your cyber policy's ransomware sub-limit (ask your broker directly, it's a one-line answer), and keep a running list of every AI tool your team has turned on. That list is the thing that protects you later, and it costs nothing to start today.

  1. Cowbell 2026 Cyber Insurance Claims Report — cyberinsurancenews.org
  2. Coveware Ransomware Quarterly Reports — coveware.com
  3. Your Cyber Insurance Policy May Not Cover Your AI Incident — ComplianceHub (compliancehub.wiki)
  4. Cyber Insurance Enters the AI Risk Era — Insurance Business Magazine (insurancebusinessmag.com)
  5. EU Council press release — AI Act simplification — consilium.europa.eu
  6. EU Approves Delays and Other Amendments to AI Act Obligations — Morgan Lewis (morganlewis.com)

Three different stories this issue, one thread underneath: the gap between what you assume and what's actually written down is where the expensive surprises live — in a ransom negotiation, in an insurance claim, in a compliance deadline. None of this is about buying something. It's about knowing your own numbers before someone else's clock starts running.

On the blog this week: The Login Screen Is Your Single Point of Failure Now — why identity has quietly become the one system your whole company depends on, and what outages and stolen session tokens both expose about it.

Hit reply and tell me what you're wrestling with — I read every one.

— Charles Redding, Founder, DLegendDigital

Paired long-form

The Login Screen Is Your Single Point of Failure Now

In 2026, the system everyone signs in through can lock the whole company out in an afternoon — or hand an attacker the keys without ever asking for a password. Identity quietly became the most critical thing you run.

Read the full article

The Current

Get the next one before anyone else.

Twice a month. ~5 min read. No spam, no upsells buried in footnotes.

Free. Unsubscribe any time.

More issues

Full archive →