The Conventional Wisdom
Your team is likely focused on AI-native attacks: prompt injection exploits, model poisoning attempts, and adversarial inputs designed to manipulate large language models. You've read the threat reports and attended presentations about jailbreaking GPT models and extracting training data. Your risk register lists "AI-enabled attacks" as an emerging threat category, and you're evaluating controls for model endpoints and API gateways.
This focus seems logical. New technology should create new attack vectors. Your job is to stay ahead of emerging threats, and AI feels genuinely novel. The problem? Claims data tells a different story about where AI is actually costing organizations money right now.
The Real Financial Risks
While AI does create risk, the financial impact in 2026 isn't from sophisticated technical exploits. Instead, attackers are using AI to make phishing emails more convincing, pretexting calls more credible, and business email compromise schemes harder to detect.
According to Resilience's 2026 Midyear Cyber Risk Report, social engineering accounted for 85% of incurred losses in their portfolio during the first half of 2026, up from 17% a couple of years earlier. Payment fraud losses tripled from the prior year. Meanwhile, AI-native attacks generated zero incurred losses during the same period.
Zero. Not "minimal." Not "lower than expected." Zero dollars paid out for prompt injection, model exploitation, or agentic misuse.
This gap between perceived risk and demonstrated financial impact matters because your budget is finite. Every hour your team spends evaluating controls for hypothetical AI-native attacks is an hour you're not hardening the controls that would stop the social engineering campaigns costing your peers actual money.
The Evidence
Claims data reveals what threat intelligence reports often miss: which attacks successfully bypass your industry's deployed controls and cause measurable financial harm. Threat reports catalog what attackers attempt. Claims data shows what works well enough to trigger a payout.
What's working right now is AI-enhanced social engineering. Attackers aren't inventing new tactics; they're using AI to execute traditional schemes with better targeting, more convincing narratives, and faster iteration. A business email compromise that once required weeks of reconnaissance and carefully crafted emails now takes hours. Deepfake voice calls that mimic executives don't require sophisticated technical skills anymore; they require a few audio samples and commercially available tools.
The financial impact shows up in your familiar threat categories: fraudulent wire transfers, credential harvesting that leads to account takeover, vendor impersonation schemes. The difference is volume and success rate. AI lets attackers run more campaigns, personalize them better, and respond to targets in real time.
Payment fraud losses tripling year-over-year isn't an accident. It's what happens when attackers apply AI to optimize their conversion rates while your controls remain calibrated for pre-AI baseline volumes and sophistication levels.
What to Do Instead
Stop treating AI risk as a separate category. Start treating it as an amplification layer on your existing threat model.
Review your social engineering controls with the assumption that every attack is now better researched, better written, and more convincing than it was two years ago. Your Multi-Factor Authentication implementation matters more, not less. Your employee training needs to account for phishing emails without obvious grammatical errors and pretexting calls that sound exactly like your CFO. Your payment authorization workflows need additional verification steps when AI can generate perfect invoice formatting and convincing urgency.
Use claims data, not just threat intelligence, to prioritize your control investments. Ask your cyber insurance carrier what's actually triggering claims in your industry segment. If they're seeing payment fraud and credential compromise, that's where you need layered controls and tested response procedures. If they're not seeing AI-native attacks causing financial losses, you can deprioritize those controls accordingly.
Build resilience-first strategies that assume attacks will succeed sometimes. Social engineering works because it targets humans, and humans make mistakes even with good training. Your controls should reduce exposure (limit who can initiate wire transfers, require out-of-band verification for payment changes), but your response capabilities matter just as much. Can you detect a fraudulent wire transfer within the window where you can still claw it back? Do you have documented procedures for freezing compromised accounts?
Strengthen the boring controls. Role-Based Access Control that limits who can approve payments. Watchlist Screening that flags unusual vendor additions. Change management procedures that require verification before updating payment details. These aren't exciting AI-specific controls. They're the same controls that stopped social engineering before AI, but they need tighter implementation now that attack quality has improved.
When the Conventional Wisdom Is Right
The conventional wisdom about AI-native attacks isn't wrong forever. It's early.
If you're building or deploying customer-facing AI models, you need controls for prompt injection and model manipulation. If you're using AI agents with access to production systems or sensitive data, you need governance around what those agents can do and monitoring for unexpected behavior. If you're in a sector where model integrity directly affects safety or regulatory compliance, AI-native attacks are a real concern regardless of current claims data.
The timeline matters too. Zero incurred losses in the first half of 2026 doesn't mean zero risk in 2027 or 2028. Attack techniques evolve. As more organizations deploy AI systems with meaningful access and authority, the attack surface expands. Claims data is a lagging indicator; it tells you what's causing losses now, not what will cause losses next year.
But right now, in 2026, your team is more likely to pay out for a deepfake voice call that convinced someone to wire $200,000 to a fraudulent account than for a sophisticated prompt injection exploit. Allocate your resources accordingly. You can revisit AI-native attack controls when the claims data shows they're actually costing organizations money.



