Anthropic’s reported programme is a signal, not a shortcut
A report by Pasquale Pillitteri says that Anthropic has launched a Cyber Verification Program and opened its Mythos 5.1 system to verified red teams. The available report description is brief, so UK businesses should avoid assuming specific technical capabilities, eligibility requirements or security guarantees beyond what has been reported. Nevertheless, the direction of travel matters: major AI providers are increasingly treating controlled, independently tested access as part of cyber-risk management.
For a UK SME, this is not primarily a story about whether to use one particular AI model. It is a reminder that generative AI can strengthen both defence and attack. The same technology that helps an IT team summarise logs, draft secure code or triage phishing reports may also reduce the time needed to research vulnerabilities, create persuasive social-engineering content or automate parts of a fraud campaign.
The practical implication is clear. If a business is adding AI tools to everyday operations, cyber insurance should be considered alongside governance, access controls and incident response. Insurance can help fund the aftermath of a covered event; it cannot replace the evidence that sensible safeguards were in place before the event.
Why verified red teaming matters to UK SMEs
Red teams test how systems fail in realistic conditions
A red team is an authorised group that attempts to identify weaknesses by thinking and operating like an attacker, within agreed legal and ethical boundaries. In an AI context, testing may examine whether a system can be manipulated into unsafe outputs, reveal sensitive information, assist harmful workflows, or be abused through integrations and access permissions.
“Verified” access is significant because it suggests a controlled model rather than unrestricted release. Providers can vet participants, define testing rules, monitor activity and use findings to improve safeguards. That is very different from leaving a tool available for anonymous, unaccountable experimentation.
This approach mirrors a principle that insurers, regulators and security professionals already recognise: risk improves when testing is continuous, documented and tied to remediation. A penetration test report that is filed away without fixing critical issues has limited value. Equally, an AI-use policy that nobody follows will not materially reduce the chance of a breach.
AI has changed the scale of familiar threats
Most UK SMEs do not face a cinematic AI “super-hack”. They face more efficient versions of existing attacks. These include invoice fraud emails tailored to a supplier relationship, password-reset messages written in convincing British English, fake job applications carrying malware, and impersonation calls supported by information gathered from public websites and social media.
Attackers do not need to compromise a sophisticated AI system to benefit from AI. They can use publicly available tools to improve their targeting. Meanwhile, an SME can introduce its own exposure by pasting customer data, contract details, source code or internal financial information into an unapproved chatbot.
That makes the question for management less about the brand of AI being used and more about control: what information can staff submit, which tools are approved, who can connect AI services to business applications, and how will unusual activity be detected?
What this means for cyber insurance applications and claims
Insurers will focus on underlying controls, not AI slogans
Cyber insurance questionnaires increasingly seek evidence of basic cyber hygiene. Exact questions vary by insurer and policy, but SMEs should expect attention on multi-factor authentication (MFA), endpoint protection, backups, patching, privileged-access management, staff training and incident-response arrangements.
As AI use becomes more widespread, brokers and underwriters may also ask more clearly about third-party technology, data sharing and security governance. A business that says it uses AI “for productivity” but cannot identify the approved platform, data categories involved or account permissions may create uncertainty during underwriting.
This does not mean AI adoption automatically makes cover unavailable or unaffordable. In fact, AI can support resilience when used appropriately. The concern is unmanaged use: personal accounts used for business tasks, broad employee permissions, confidential data uploaded without contractual protections, or automated actions taken without human review.
Policy wording remains more important than headlines
No red-team initiative by an AI provider guarantees that losses connected with AI will be insured. SMEs should read the policy schedule, endorsements, definitions and exclusions, preferably with a specialist broker. Key areas to review include:
- Security and privacy liability: whether third-party claims arising from a data breach or failure to protect information are covered.
- Incident response costs: access to breach counsel, forensic investigation, notification, call handling and credit-monitoring services where applicable.
- Cyber extortion: cover for ransomware and related response costs, subject to policy terms and legal requirements.
- Business interruption: whether lost income and increased costs after a covered system outage are included, and what waiting period applies.
- Social engineering or crime cover: whether fraudulent payment instructions are covered; this is often subject to a separate limit or conditions.
- Supplier and cloud dependency: whether a disruption at a named or unnamed technology provider is covered.
It is also essential to understand conditions that may affect a claim. Policies can require the insured to maintain stated controls, notify an incident quickly, cooperate with appointed responders and avoid admitting liability. Businesses should not assume that a generic statement such as “we have antivirus” meets a policy’s specific MFA or backup requirements.
A practical AI and cyber insurance checklist
1. Create an AI-use register
List every AI service being used for work, including free tools and browser extensions. Record the owner, business purpose, type of data processed, integrations, subscription tier and whether enterprise privacy settings are enabled. Shadow AI is the equivalent of shadow IT: it creates exposure that management cannot assess or insure effectively.
2. Set data rules staff can actually follow
Classify information simply: public, internal, confidential and highly restricted. Make it explicit that customer records, payment data, credentials, health information, legal advice, unpublished financial results and proprietary code must not be entered into unapproved public AI services. Give staff an approved alternative, otherwise a prohibition will be ignored under deadline pressure.
3. Apply least privilege to AI integrations
An AI assistant connected to email, a CRM, cloud storage or accounting software may be useful, but every connection broadens the attack surface. Grant only the permissions needed, prefer read-only access where practical, separate admin accounts and review integrations at least quarterly.
4. Test the people-and-process layer
Run phishing simulations and finance-payment verification exercises. Require a second, independent check for changes to bank details and high-value payments, using a trusted contact method rather than replying to an email thread. AI-enhanced impersonation makes this control more important, not less.
5. Revisit your incident-response plan
Decide in advance who can isolate devices, contact the insurer, preserve evidence, communicate with customers and approve external advisers. Keep insurer and broker contact details offline as well as digitally. A ransomware event or suspected data leak is the wrong moment to discover that only one departing employee had access to the policy portal.
Before renewal, discuss material changes such as a new AI customer-service bot, AI-supported code development, major SaaS integrations, increased reliance on cloud systems or use of sensitive personal data. Accurate disclosure supports better placement and reduces the risk of disputes later.
The wider lesson: assurance must be continuous
The reported Anthropic programme reflects an important security reality: assurance is not a one-off certificate. Tools evolve, attackers adapt, employees change roles and software integrations multiply. A model tested today may be deployed tomorrow in a workflow that introduces entirely different risks.
For SMEs, the most proportionate response is not to ban AI or attempt to copy a large technology company’s security operation. It is to establish clear approved use, protect identities with MFA, minimise sensitive-data sharing, validate payments outside email, maintain recoverable backups and buy cyber insurance that matches the organisation’s actual dependencies.
A red-team programme may improve confidence in a provider’s willingness to surface and address risks. It should never be interpreted as a transfer of responsibility from the SME to the provider. The business remains responsible for how it configures accounts, trains staff, handles personal data and responds when something goes wrong.
FAQ
Not automatically. Cover depends on the wording, disclosures, exclusions and compliance with policy conditions. Tell your broker about material AI use, especially where tools process confidential information or connect to core systems.
What is the most important AI security control for a small business?
There is no single control, but enforcing MFA across email, cloud administration and AI accounts is a high-impact starting point. Pair it with clear rules on confidential data and independent verification of payment changes.
Can cyber insurance cover an AI-generated invoice fraud loss?
Possibly, but it is not guaranteed. Such losses may fall under social-engineering, funds-transfer fraud or crime cover, often with separate limits and specific conditions. Check the policy rather than assuming standard cyber cover applies.
Should an SME only use AI vendors that conduct red-team testing?
Independent and ongoing security testing is a positive sign, but it is only one factor. Also assess contract terms, data handling, authentication options, audit logs, integration permissions, support arrangements and whether the service fits your own risk appetite.
Source: Pasquale Pillitteri — Wed, 07 Oct 2026 06:48:15 GMT