EIOPA Lifts Cyber to High as July 2026 Dashboard Holds Rest at Medium

EIOPA Lifts Cyber to High as July 2026 Dashboard Holds Rest at Medium

EIOPA insurance risk dashboard lifts cyber and digitalisation risk to high, holding seven other risk categories steady at medium for July 2026.

The EIOPA Insurance Risk Dashboard for July 2026 keeps seven of eight risk categories at medium, but digitalisation and cyber risk alone breaks that pattern, rising to high on frontier AI developments, geopolitical tension and elevated cyber underwriting exposure. The July edition draws on prudential reporting from 96 insurance groups and 2,091 solo undertakings, and its cyber call now sits alongside a parallel warning from the European Banking Authority about AI-driven attack surfaces in the banking sector.

Cyber breaks ranks with every other risk category

EIOPA’s July 2026 risk dashboard release confirms the single break from an otherwise flat quarter: digitalisation and cyber risk alone moved to high, reflecting frontier AI developments, geopolitical tensions and elevated cyber underwriting exposures, while every other category held at medium. Macroeconomic risk stayed at medium, though EIOPA flagged a worsening outlook as geopolitical tension piles downside risk onto already weak growth and higher inflation expectations. Credit risk also held at medium, underpinned by insurers’ high-quality asset holdings, even as financing costs and private-credit vulnerabilities warrant monitoring. Market risk eased through end-June 2026, but the outlook darkened again on renewed geopolitical tension and commodity-market volatility, with concerns about elevated valuations and a possible broader correction still on the table. Solvency and profitability risk held at medium on broadly unchanged capital positions and mixed profitability indicators, insurance risk stayed at medium despite some loss-ratio deterioration and uncertainty around war- and trade-related coverages, and ESG-related risk was largely stable, with only a modest rise in green bond holdings. Cyber is the outlier in an otherwise flat quarter, a pattern insurers have been tracking since Guy Carpenter tied rising cyber losses to litigation and technology costs rather than a jump in attack volume. That framing matters for how underwriters should read the July move: EIOPA is not necessarily describing more incidents landing on insurers’ books, but a widening gap between the sophistication of AI-enabled threats and the pricing models built before frontier AI became a mainstream underwriting variable.

What 96 groups and 2,091 undertakings actually reported

The July dashboard draws on Solvency II prudential and financial stability reporting from 96 insurance groups and 2,091 solo insurance undertakings, with risk indicators spanning the first quarter of 2026 and year-end 2025. Market-based indicators are refreshed to a later cut-off, end-June 2026, so the cyber and digitalisation call reflects the freshest data window in the release. The dashboard’s forward-looking 12-month risk outlook, meanwhile, is built from responses submitted by 23 national competent authorities (NCAs) across the EU/EEA, giving the high rating a supervisory consensus behind it rather than a single desk’s judgment call. EIOPA maintains the full interactive dashboard and underlying indicator definitions for market participants who want to drill into the category-by-category scoring themselves.

A three-dashboard trend line: from vigilance to high alert

The escalation did not happen in a single edition. In its January 2026 dashboard, based on data from 97 insurance groups and 2,124 solo undertakings, EIOPA said only that geopolitical tensions, trade disruptions, and cyber events call for continued vigilance — cyber was a factor to watch, not yet a standalone high-level category. By the April 2026 dashboard, covering 94 insurance groups and 2,092 solo undertakings, the category was still sitting at medium. The move from a vigilance footnote in January to a standalone high rating in July marks a real shift in tone, even as the underlying population of reporting entities barely changed. Readers can trace the full progression through EIOPA’s April 2026 release on geopolitical uncertainty shaping the outlook and its January 2026 dashboard covering persistent geopolitical tensions.

EBA draws the same line for banks

EIOPA is not alone in pointing at frontier AI as a cyber accelerant. The European Banking Authority warned that the rapid development of increasingly capable frontier AI models may further amplify operational and cyber risks, including through new attack vectors and the potential misuse of AI-enabled tools — language published in the EBA’s own resilience assessment for EU/EEA banks — that reads almost as a mirror of EIOPA’s insurance-side rationale. Two separate prudential authorities, covering two separate sectors, converged on the same underlying thesis within weeks of each other: AI capability is outpacing the defensive tooling built to contain it. For insurers already underwriting cyber risk, that convergence matters as much as the rating change itself, particularly with APAC cybercrime volumes already testing underwriting discipline in fast-growing markets and UK regulators separately probing whether AI-driven pricing models keep pace with the risks they are meant to price. Taken together, the EIOPA dashboard and the EBA statement read as an early instance of cross-sector prudential alignment: two regulators watching the same technology curve arrive independently at the same conclusion, which is itself a signal worth more attention than either release would generate on its own.

What underwriters and risk committees should watch next

None of the seven categories still parked at medium are risk-free, and EIOPA’s own language leaves room for further deterioration. Market risk already carries a darker outlook despite easing through end-June 2026, and macroeconomic risk is explicitly flagged as worsening even while it holds at medium. For cyber underwriters and portfolio managers, three practical questions follow from the July release. First, does the move to high change capital-planning or reinsurance-buying assumptions before the next quarterly cycle, given that the underlying reporting population — 96 insurance groups and 2,091 solo undertakings in July against 94 groups and 2,092 undertakings in April — has been broadly stable even as the rating moved. Second, how should pricing models absorb an EBA warning aimed at banks but built on the same frontier-AI logic driving the insurance-side rating. Third, whether the next quarterly release, expected to reflect data collected after the end-June 2026 market cut-off, shows the high rating holding, easing, or spreading to categories currently still at medium. Supervisors representing 23 national competent authorities fed into this edition’s outlook, so the next dashboard will carry a similarly broad base of national input rather than a single desk’s read of the market.

Mini-FAQ

Why did EIOPA raise digitalisation and cyber risk to high in July 2026?
EIOPA cited frontier AI developments, geopolitical tensions and elevated cyber underwriting exposures as the drivers behind the move to high, the only category-level change in the July 2026 dashboard.
How much of the insurance market does the July 2026 dashboard cover?
The dashboard draws on prudential reporting from 96 insurance groups and 2,091 solo insurance undertakings, with a 12-month outlook informed by 23 national competent authorities.
Did EIOPA warn about cyber risk before July 2026?
Yes. In January 2026, EIOPA said geopolitical tensions, trade disruptions, and cyber events call for continued vigilance, but cyber was not rated as a standalone high-level risk category until the July edition.
N

Nicolas Martin

InsuraBeat correspondent

Senior reporter at InsuraBeat covering commercial and property & casualty markets, M&A, and underwriting performance across Europe and North America. Twelve years in the industry: started as an analyst on the broker side at a global reinsurance intermediary placing casualty and specialty risks for European corporates, then five years on the underwriting side at a Tier-1 European insurer, last managing D&O and cyber portfolios. Holds a Master in Reinsurance Economics and Capital Markets from the Kwang-Hwa Institute of Financial Sciences (Taipei) and is a CFA charterholder. Writes from Paris, on US morning markets.

All articles by Nicolas Martin →

Daily Beat newsletter

Never miss a beat in global insurance.

Get the day’s top deals, executive moves and regulatory shifts in your inbox every morning.

Free. No spam. Unsubscribe anytime.