GET THE AUTOPSY ➔

The insurer that pays out when cyberattacks succeed cannot find a single AI-specific loss in its 2026 claims data.

AI really is reshaping attacks, just not the way the headlines say. Prompt injection, model exploitation and agentic misuse have paid out exactly nothing. The AI dividend is landing in the oldest line item there is: phishing that works.

01THE CLAIM
"AI-driven cyberattacks are escalating and reshaping the threat landscape, with AI-powered attacks exploding across 2026" [SOURCE ↗]
TRUE, BUT4 SOURCES · LIVE 2026-08-25
IBM X-FORCE TRACK RECORD1 CLAIM · 40/100 BS RATE →
0INCURRED LOSSES IN RESILIENCE'S CLAIMS PORTFOLIO FROM PROMPT INJECTION, MODEL EXPLOITATION OR AGENTIC MISUSE, H1 2026
85.3%OF H1 2026 INCURRED LOSSES FROM PHISHING, SOCIAL ENGINEERING AND TRANSFER FRAUD, UP FROM 17.7% IN H1 2024
44%IBM'S RISE IN ATTACKS ON PUBLIC-FACING APPS, CREDITED PARTLY TO AI-ENABLED VULNERABILITY DISCOVERY
The insurer that pays out when cyberattacks succeed cannot find a single AI-specific loss in its 2026 claims data.
02THE CHECK

THE CLAIM, running through 2026 security marketing on the back of IBM's February headline: AI-driven attacks are escalating, the machines are attacking, buy accordingly. THE CHECK: cyber insurer Resilience's H1 2026 report, built on claims data from January 2024 through June 2026, finds zero incurred losses traceable to an AI-specific attack vector. No prompt injection loss. No model exploitation loss. No agentic misuse loss. What the data does show is AI supercharging the oldest attack in the book: phishing, social engineering and transfer fraud climbed from 17.7% of incurred losses in H1 2024 to 85.3% in H1 2026. The escalation is real. The vector in the headlines is not the vector in the claims files.

03SAY THIS IN THE MEETING · 📸 SCREENSHOT IT
"'Which AI attack, specifically, and who paid a claim on it?' Escalating reconnaissance is real, AI-polished phishing is real and expensive. But an insurer combing its own payouts found no prompt injection, no model exploitation, no agentic misuse. The AI threat that exists is an amplifier, not a new weapon."
DEEP DIVE · THE FULL AUTOPSY

The mood and the meter

Since February, when IBM shipped its 2026 X-Force Threat Index under the headline 'AI-Driven Attacks are Escalating as Basic Security Gaps Leave Enterprises Exposed', the year's security discourse has run on one premise: the machines are attacking. Vendor blogs quote surge percentages for prompt injection, conference decks show agentic kill chains, and every product brief has grown an AI-threat paragraph. The premise deserves a meter, and there is a good one: insurance. Insurers do not get paid to be scared. They get billed when fear turns into an actual loss, which makes claims data the closest thing security has to a lie detector.

What the claims files say

Resilience's H1 2026 cyber risk report is built on its own claims from January 2024 through June 2026 plus threat intelligence from its Risk Operations Center. The sentence that should reorganize your threat model: 'In the first half of 2026, zero incurred losses in the portfolio trace to an AI-specific attack vector, not prompt injection, not model exploitation, not agentic misuse.' Zero. Not rare, not underreported, zero paid losses from the entire category of attacks that dominates AI-security marketing.

And yet the same report shows AI everywhere. Losses tied to phishing, social engineering and transfer fraud 'have climbed from 17.7% of incurred losses in H1 2024 to 85.3% in H1 2026', the largest move in the report's five half-year comparisons. The report's own summary of the mechanism: AI's clearest fingerprint on the portfolio is not a new kind of attack, it is an old one, delivered more convincingly.

What the escalation claim gets right

The IBM index is not fabricating its numbers. X-Force 'observed a 44% increase in attacks that began with the exploitation of public-facing applications, largely driven by missing authentication controls and AI-enabled vulnerability discovery', and its own fine print concedes the entry points are credential hygiene and misconfigured access controls, the same doors as always, found faster. Read carefully, IBM's report and the insurer's data agree: AI is an accelerant poured on existing attack paths. The distortion happens downstream, where 'AI accelerates reconnaissance against unpatched apps' gets compressed into 'AI attacks are exploding' and re-sold as a reason to buy protection against vectors that have never paid a claim.

Both sides of the counter

The inflation is symmetrical, which is the tell that it is a market phenomenon rather than a measurement. On the defense side, Gartner's 2026 security operations hype cycle has 'AI SOC agents sit at the Peak of Inflated Expectations, up from the Innovation Trigger in 2025, while market penetration is 1% to 5%'. The attack stats justify the budget, the defense agents absorb it, and the loss data underneath moves on phishing.

The steelman, which has teeth

Three honest caveats. First, insured losses lag capability: the AISI incident in July demonstrated agentic misuse reaching real infrastructure, so the capability is demonstrated, not theoretical, and Resilience's own report treats it that way. Second, one portfolio is one lens: Resilience insures a particular slice of companies, and an AI-vector loss at an uninsured lab or a mega-cap would never appear in this data. Third, the 85.3% phishing surge arguably IS the AI loss category, mislabeled: if a deepfaked voice or a model-written lure drove the transfer fraud, AI caused the loss even though the vector is filed under social engineering. That last point is the strongest, and it cuts against the headline framing too, because the defense it argues for is wire-transfer controls and verification culture, not prompt-injection firewalls.

Why we rate this NEEDS CONTEXT

'AI-driven attacks are escalating' holds as amplification and fails as the sci-fi vector story it is marketed as. The kill number is 0: paid losses from prompt injection, model exploitation and agentic misuse across an entire insurance portfolio through June 2026. The 85.3% number beside it is where AI is actually costing people money. Fund the boring defense first. The machines are not attacking. The phishing emails are just better written now.

04YOUR MOVE ⚡ WHAT IGNORING THIS COSTS

Security budgets follow the scary noun, and the scary noun this cycle is 'AI attack'. The loss data says the money is leaving through the front door marked phishing, dressed better than it used to be. If a vendor pitch leads with prompt injection and agentic exploits, ask what fraction of actual paid losses those vectors represent. Right now the measured answer is zero, while the boring answer, humans wired money to a convincing email, is 85.3% and climbing.

05🔮 OUR CALL · ON THE RECORD 2026-08-14

The 'AI attacks exploding' framing keeps selling because both sides of the security market need it: attack-stat vendors need the threat inflated and AI-defense vendors need the counter-threat inflated. Gartner already has AI SOC agents parked at the Peak of Inflated Expectations on 1% to 5% penetration. The claims data will eventually show a first real AI-vector loss, and when it does, expect it to be reported as if it were the thousandth.

Flips toward holds the moment insurers report material incurred losses from prompt injection, model exploitation or agentic misuse, which the AISI incident and lab demonstrations suggest is a when, not an if. Flips toward unsupported if the phishing-loss surge turns out to be unrelated to AI tooling in attribution studies.

RECEIPTS (4) · CONFIDENCE HIGH · every URL below answered a live HTTP check before publish · sweep 2026-08-25

  • newsroom.ibm.com · "observed a 44% increase in attacks that began with the exploitation of public-facing applications, largely driven by missing authentication controls and AI-enabled vulnerability discovery"
  • cyberresilience.com · "In the first half of 2026, zero incurred losses in the portfolio trace to an AI-specific attack vector, not prompt injection, not model exploitation, not agentic misuse."
  • cyberresilience.com · "phishing, social engineering, and transfer fraud have climbed from 17.7% of incurred losses in H1 2024 to 85.3% in H1 2026"
  • nhimg.org · "AI SOC agents sit at the Peak of Inflated Expectations, up from the Innovation Trigger in 2025, while market penetration is 1% to 5%"

This story is a stable, citable object. If you can falsify a verdict, tell us. Corrections are loud here.