A recent report on the cyber risk outlook from Allianz Commercial, a global insurer, highlights the ongoing rise in cyber claims, driven primarily by data and privacy breach incidents. Data reveals that large cyber claims exceeding €1 million increased by 14% in the first half of 2024, with severity escalating by 17%. This follows a modest 1% increase in severity throughout 2023. Notably, data and privacy breach-related issues account for two thirds of these significant losses.
Among the rising risk trends identified in the report is artificial intelligence (AI), which could significantly amplify data breach risks in the future. AI facilitates extensive data processing, which can be exploited by threat actors, potentially increasing vulnerability to cyberattacks.
The integration of AI in sectors such as technology, media, healthcare, finance, retail, and logistics is expanding rapidly. According to a recent survey by McKinsey, 65% of organisations reported regular use of AI, almost double compared to the previous year's figures. AI systems rely on vast data collections, including personal and biometric information, to train models and provide accurate recommendations and predictions. AI is integral in technologies such as virtual assistants, surveillance systems, chatbots, and autonomous vehicles.
Nevertheless, the enormous volume of data managed by AI systems poses privacy and security threats if not adequately controlled. Concerns have been raised about possible data leaks and breaches of privacy laws, such as obtaining proper consent for processing personal information. In a notable case in February 2024, Air Canada was mandated to compensate a customer affected by false information from a chatbot.
As AI technology rapidly evolves, so too does the legal and regulatory environment surrounding it. The European Union is working towards establishing a uniform regulatory framework through the AI Act and supplementary AI Liability Directive, which is expected to increase regulatory complexity and compliance requirements for companies operating in this space.
The AI applications carry varied levels of risk; for instance, consumer-facing AI applications, like chatbots, inherently pose higher data privacy risks compared to internal process automation tools.
In light of these trends, the report suggests companies focus on several key strategies to leverage AI's benefits while mitigating potential privacy risks:
Data Governance: Implementing comprehensive data governance can ensure compliance with privacy laws and internal data policies. This includes defining data ownership, classification, and establishing access and usage guidelines.
Security Measures: Strong security practices, such as encryption and access controls, coupled with regular audits, are essential to safeguarding data within AI systems and preventing unauthorised access.
Compliance with Privacy Regulations: Organisations must align AI usage with privacy laws like the European GDPR or the US CCPA, ensuring explicit consent, data control for individuals, and respect for data subject rights.
Ethical AI Practices: Fostering ethical AI entails addressing potential biases, maintaining transparency about data usage, and integrating privacy considerations into AI deployment.
Privacy-preserving AI Techniques: Techniques such as federated learning and differential privacy can help mitigate privacy risks by allowing AI models to train on decentralised data without accessing sensitive personal information directly.
The Allianz Cyber Risk Trends Report provides detailed insights into these issues and explores the nuances of evolving cyber risks.
Source: Noah Wire Services