Swiss Re estimates global cyber insurance premiums will reach $16.4 billion in 2026 as insurers confront an expanding mix of ransomware, data breach, supply-chain and artificial intelligence exposures.

The reinsurer expects premiums to rise to $17.1 billion in 2027. Cyber premium growth has held at a 5% compound annual rate since 2022, even as insurance rates have fallen for four consecutive years. Global rates declined about 5% in 2026 after falling roughly 13% in 2025.

AI is adding another variable to cyber underwriting and claims. Swiss Re said the technology appears more likely to amplify existing cyber risks than create entirely new categories of insured loss. Threat actors can use AI to identify vulnerabilities, automate attacks and improve phishing campaigns, while businesses can use the same technology for threat detection and automated incident response.

AI-related cyber claims remain limited, according to Swiss Re. Existing commercial cyber policies may already cover some AI-related incidents because AI models can fall within definitions of computer systems. The potential for losses to trigger different sections of a cyber policy makes coverage language and the parties’ understanding of coverage intent important when claims arise.

Loss severity presents a separate problem. Swiss Re estimates large corporations buy average cyber limits of about $120 million in the United States and $90 million in Europe. Its Cyber Claims Database shows that during the past five years, an average of 10 losses per year would have exceeded the $120 million benchmark.

Ransomware and privacy violations or data breaches account for most losses at that level. A severe incident can produce digital business interruption, lost revenue, restoration expenses and supply-chain disruption. Swiss Re said some companies may need twice the current average limits, although appropriate capacity depends on each company’s operations, geography and risk profile.

For claims organizations, those loss components can make a major cyber event a coverage and damage-assessment exercise across several fronts. Policy wording will determine how a particular loss responds, especially as businesses put AI systems into more operations and increase their dependence on digital infrastructure.

The market also remains uneven by company size. Swiss Re estimates cyber insurance penetration at only 5% to 10% among micro-SMEs and 10% to 20% among SMEs. Mid-market penetration is estimated at 40% to 50%, while penetration among large corporations stands at 60% to 70%.

Large corporations are expected to generate about $7.4 billion in cyber premium during 2026. Micro-SMEs and SMEs are projected to account for $4.9 billion, with another $4.1 billion coming from the mid-market.

North America remains the largest regional market, accounting for about $10.7 billion, or roughly two-thirds, of global cyber premium in 2026. Europe represents 21%, or $3.42 billion, followed by Asia-Pacific at 10%, or $1.7 billion. Latin America and the Middle East and Africa each account for about 2%.

Swiss Re said insurers and reinsurers will need to track AI-related exposures and cyber loss trends while keeping policy language aligned with coverage intent. Reinsurance capacity also becomes more significant as insurers write larger limits and manage the possibility that one cyber event can affect multiple insureds.

For adjusters handling large cyber losses, the combination of ransomware, prolonged business interruption, restoration costs, data exposures and supply-chain effects can push claims toward or beyond program limits. AI adds another coverage question: whether and where losses involving AI systems fall within existing cyber policy definitions and insuring agreements.