Ariel Re’s Dan Carr and Lockton Re’s Oli Brew see abundant capacity keeping pressure on cyber pricing, even as liability trends, critical infrastructure dependencies and AI add new uncertainty to the risk landscape

The cyber market is heading into renewals with pricing pressure evident, but the risk debate is becoming more complicated as insurers contend with liability deterioration, ageing policy language and rapidly changing technologies.
Speaking to GR at RVS 2026 in Monte Carlo, Dan Carr, head of cyber at Ariel Re, said the pricing picture is diverging between the US and international markets.
“The US is starting to flatten,” Carr said (pictured in conversation with GR editor David Benyon at RVS 2026). “International is still in a pretty aggressive deceleration.”
One reason is the US claims environment, where slower-developing liability losses are beginning to emerge.
“There’s been some liability deterioration,” Carr said. “They’re now starting to come through the courts generally, and you’re seeing those losses tick up.”
At treaty reinsurance level, however, Carr said he expects upcoming renewals to remain relatively orderly.
Quota share commissions have increased significantly over the past couple of years without equivalent premium growth, while more recent underwriting years remain underdeveloped.
“There’s a fair argument to say yes, there’s significant supply, so you’re unlikely to look at the horizon and say we need to charge more for this emerging stuff,” he said.
“But equally, there’s very little rationale short of there’s loads of money, so we want it cheaper.”
Infrastructure wordings under scrutiny
For Oli Brew, head of Lockton Re’s cyber centre of excellence (also pictured speaking with GR at RVS 2026), one of the more important questions is whether cyber policy language has kept pace with the infrastructure on which insureds now depend.
Brew said the market’s focus on cyber war had potentially distracted from events below the war threshold that could nevertheless trigger critical infrastructure provisions.
“Our view is that, important as it is, that really addresses the extreme tail of an event, and there’s a lot of activity that could occur below the war threshold, which could be subject to critical infrastructure language,” Brew said.
The challenge is particularly acute around telecommunications, cloud and internet services, where boundaries between different parts of the digital infrastructure have become increasingly blurred.
“Many of these clauses are 10 years old or more,” Brew said.
“The language hasn’t kept up with the technology.”
That leaves insurers attempting to apply exclusions drafted for an earlier technological era to highly interconnected systems, with Brew arguing that some wording is not sufficiently precise about exactly which components are excluded.
AI: amplifier, not apocalypse
The revolution in artificial intelligence (AI) is another area where both see significant change, but neither reduced the issue to a simple prediction of dramatically higher insured losses.
Brew described AI as “an amplifier and a scaler for both sides”, although he suggested attackers currently have an advantage because criminal groups face fewer constraints around how they use the technology.
“The attackers have their nose in front because it turns out that if you’re a cyber criminal gang, you’re less concerned about compliance, governance, legislation, frameworks and protocols of sandboxing these tools,” he said.
Carr was similarly cautious about extrapolating greater AI capabilities directly into vastly larger losses.
Cyber criminals, he argued, already operate professional and scalable enterprises, with strong incentives to maintain repeatable sources of income rather than radically alter a model that works.
“Yes, they’ve got a tool. Yes, I’m not discounting it can play a role in how they operationalise their attacks, but I don’t think it’s like a seismic catalyst to all of a sudden you’ve got 10 times losses,” Carr said.
He also sees a defensive upside as AI accelerates vulnerability discovery and improves quality assurance, ultimately creating a different baseline for cyber risk.
“At some point in the future, it will equalise on a new baseline, and there will be discovery, and the new stuff will get discovered in shorter windows,” Carr said.
“So there will be meaningful requirement for agility of risk management. However, that isn’t seismic wave after seismic wave, which is sort of what everyone’s doomsdaying at the moment.”
Click here to read the full digital issue of GR’s RVS special edition 2026



No comments yet