
The Insurance Regulatory and Development Authority of India has issued an advisory email to insurers requesting detailed status reports on preparedness for AI-driven cyber risks, including vulnerability and response capability. According to reports from NDTV Profit, companies have been asked to reassess their cybersecurity posture and report by May 22. This directive represents a significant shift in regulatory focus, with experts describing it as proactive supervision of an emerging threat before the industry has been tested by it. As noted by Aravind Venugopal, partner at Khaitan & Co, this is essentially an attempt to evaluate how companies are looking at this threat.
The regulatory concern comes at a time when the insurance sector's exposure has grown significantly. According to the Economic Survey 2026 and provisional General Insurance Council data, total premium income reached ₹11.93 lakh crore in FY25. Non-life insurance expanded to ₹3.36 lakh crore in gross direct premiums by FY26, while insurers' assets under management have crossed ₹74.44 lakh crore. Health insurance alone accounts for over ₹1.2 lakh crore in premiums, covering 58.2 crore customers. As reported by NDTV Profit, large data pools, digital processes and legacy systems together create a broad attack surface as threat vectors evolve. The sector is positioned for sustained growth, with India's insurance market valued at USD 338.18 billion in 2025 and projected to reach USD 867.89 billion by 2034, representing an 11.04% CAGR growth driven by digital transformation and regulatory reforms.
The regulator's concern extends beyond traditional cyberattacks to two distinct exposures: AI-driven fraudulent claims and data security risks from sophisticated cyberattacks. According to Aravind Venugopal, partner at Khaitan & Co, there are two distinct exposures here - one is AI-driven fraudulent claims, and the other is data security risks arising from more sophisticated cyberattacks. Globally, insurers are reporting a rise in AI-generated claims, synthetic identities and manipulated evidence, including fabricated medical records and doctored vehicle damage images. The Star Health Insurance breach exposed personal data of about 3.1 crore customers along with millions of claims, later circulating in public domains. Other incidents involving Tata AIG and earlier attacks at Aviva Life have underscored system weaknesses.
IRDAI's updated Information and Cyber Security Guidelines for 2026 set out a control-heavy framework but remain largely technology-agnostic and do not explicitly address AI risks. As reported by NDTV Profit, AI is changing the game as vulnerabilities can now be identified and exploited faster than ever before, in hours, not weeks. The guidelines mandate board-approved cybersecurity frameworks, CISO-led oversight, and controls across information asset lifecycles, but stop short of defining AI-specific controls such as model risk, bias, explainability, adversarial attacks or risks from automated decision-making. Anirud Sudarsan, partner at Cyril Amarchand Mangaldas, noted that while baseline cyber and data protections are strong, there is no dedicated regulatory perimeter for AI-led risks in underwriting, claims processing or fraud detection.
Industry feedback suggests AI risks are still not treated as core, with many insurers assuming existing systems are adequate and compliance often treated as a check-box exercise. According to NDTV Profit, insurers continue to rely on frameworks designed for known threats even as AI adoption accelerates across underwriting, claims and customer servicing. The directive's design is deliberate, with Venugopal explaining that the sophistication lies in leaving the threat category open-ended, requiring each institution to genuinely interrogate its own exposure. The resulting disclosures will become the benchmark against which future readiness is judged, as the gap between perception and reality may ultimately define the sector's exposure to emerging AI threats. The sector's transformation is accelerating with 100% FDI liberalization passed in December 2025, life insurance posting 40% year-on-year growth in December, and strategic global partnerships reshaping competitive dynamics across India's rapidly scaling insurance landscape.