One issue we keep hearing from insurance underwriters and portfolio managers is some version of the same question: how do you price a risk that can change between bind and the very next day?
The steady stream of headlines about Claude Mythos is the latest reason why this question comes up, but it isn’t really all about Mythos. Frontier AI is collapsing the gap between vulnerability disclosure and weaponized exploit, and the numbers are no longer subtle. Google’s Mandiant measured the mean time to exploit a new vulnerability at 63 days in 2018; by 2024, it had fallen to roughly zero, and in 2025, it’s estimated at negative seven days, meaning exploitation now routinely begins before a patch even exists.
For six consecutive years, exploitation of Internet-facing systems has been the single most common way attackers get in, and a separate IBM dataset puts vulnerability exploitation as the reason behind 40% of incidents. This ‘window’ insurers used to count on, the one where bind-time data stayed roughly accurate through the policy period, is closing. The market is recognizing it: the data behind cyber decisions has to be better and faster than before, which is the same reason Bitsight was named the leader in the 2026 Forrester Wave for Cybersecurity Risk Ratings Platforms and Cyber Insurtech of the Year at the 2026 Cyber Insurance Awards USA.
The new imperatives
All of this has a few real implications for how the market will react.
First, the underwriting question has shifted
No insured will avoid high-severity vulnerabilities. The applicants worth underwriting aren’t the ones with the cleanest scan on day one; they’re the ones who can fix things when something breaks. Mean time to patch, exposure decay curves, and how fast a known bad piece of software disappears from an attack surface are the variables that predict loss now.
Second, you can’t underwrite or manage portfolio accumulation if you don’t know what software your insureds are running
This is the part where some insurers are underinvesting at the scale the moment requires.
Bitsight’s Groma Internet scanner scans four billion IP addresses and fingerprints software across 40 million-plus organizations, spanning more than 60,000 unique technology applications. That dataset is what makes the next part possible at scale. When a Common Vulnerability and Exposure (CVE) drops on a Tuesday afternoon, customers can see in real time which of their insureds are running the affected version and how heavily they depend on it.
Pairing that with curated, real-time threat intelligence from deep- and dark-web sources tells them which of those exposures are being weaponized right now. That’s the difference between finding out about portfolio concentration during a claim and finding out before one materializes.
Third, the AI attack surface is becoming material to a kind of loss that the market is barely underwriting
But it’s worth being precise about why, because the path from ‘faster exploitation’ to ‘systemic event’ is not automatic.
Speed is the trigger, not the loss. Compressed time to exploit is real: when the gap between disclosure and weaponization runs negative, the remediation window underwriting relied upon is gone.