HOW USEFUL WAS THIS POST? RATE, LEAVE A COMMENT REQUESTING CHANGES, AND WE’LL AMEND ACCORDINGLY.
From crypto crimes to growing activity in the new space economy, this edition of Risk Wrap highlights six developments shaping compliance, governance, and insurance exposure across high‑risk industries.
FATF Warns Crypto Enforcement Is Falling Behind as AI, Stablecoins and DeFi Fuel New Risks
The Financial Action Task Force’s (FATF) latest review of global virtual asset regulation shows that governments are making progress in strengthening oversight, but enforcement is lagging behind.
Of the 147 jurisdictions assessed, 86% have completed virtual asset risk assessments, up from 76% in 2025, while 83% have implemented Travel Rule legislation, compared with 73% a year earlier.
Among jurisdictions that require virtual asset service provider (VASP) licensing, 81% now conduct supervisory inspections and 71% have taken enforcement actions.
93% are yet to identify qualifying DeFi arrangements where an identifiable owner or operator is known. This makes it difficult to subject DeFi entities to VASP regulation.
The FATF also points out a few escalating risks:
- Industrial-scale fraud such as the Cambodia-based scam compounds. One conglomerate laundered at least $4 billion between 2021 and 2025.
- Proprietary, freeze-resistant stablecoins, which are becoming the preferred vehicle for illicit activity among scammers and terrorist organizations.
- AI is scaling-up cybercrime and has introduced new methods like deepfake scams and AI-assisted smart contract exploits.
- Sanctions evasion, TF, and PF are becoming increasingly interconnected through shared digital asset infrastructure.
- Offshore VASPs misrepresent themselves as retail users. 88% of jurisdictions consider unhosted wallet activity as high risk but only 23% collect data to monitor it.
The FATF recommends strengthening transaction monitoring and wallet screening and suggests enhancing due diligence when it comes to unhosted wallets. It also advises firms to check exposure to DeFi protocols, bridges, mixers, and cross-chain services.
Implications for brokers and their clients:
- Investigate specialist crypto asset insurance from providers with expertise in evolving regulatory frameworks across jurisdictions.
- Review D&O insurance to confirm whether executives are covered against regulatory investigations, shareholder actions, and claims alleging failures in AML oversight.
- Consider comprehensive cyber insurance to help cover incident response, forensic investigations, business interruption, cyber extortion, and third-party liabilities arising from digital asset-related security incidents.
Source: Chainalysis (July 23, 2026). What FATF’s 7th Crypto Compliance Report Card Means: Enforcement Must Catch Up With Legislation.
Emerging insurance industries mentioned: Digital Asset and Web3 Insurance.
Lines of business mentioned: Directors and Officers Liability Insurance, Cyber Liability Insurance.
Poland Backs EU Satellite Network with $745 Million Investment
One of the latest developments set to increase orbital congestion is the EU’s planned IRIS² satellite constellation. Poland has committed around $745 million to support the program, which is intended to provide high-speed connectivity even in dead zones, and secure government communications. Some consider it an equivalent to Starlink.
The investment will fund the construction of 12 satellites, including six in medium Earth orbit (MEO) and six in low Earth orbit (LEO). The constellation will include around 292 satellites in total (18 MEO, 264 higher LEO, and 10 lower LEO).
Marcin Kierwiński, Minister of the Interior and Administration, said that Poland’s involvement in IRIS² could create new opportunities for over 400 firms in the country’s sector. Poland also plans to establish a new fund worth more than 500 million złoty (around $131.5 million) to invest in prospective space companies.
Implications for brokers and their clients:
- Investigate launch and in-orbit cover to safeguard against losses arising from launch failure, deployment issues, operational malfunctions, and collisions.
- Consider maintaining adequate third-party liability cover to protect against claims arising from damage caused to other spacecrafts or property during launch or orbital operations.
- Investigate tailored space insurance to cover the exposures present in satellite manufacturing, testing, launch preparation, and various mission-specific risks.
Source: Space News (July 23, 2026). Poland commits $745 million to EU’s IRIS² constellation project.
Emerging insurance industries mentioned: Space Economy Insurance.
OpenAI Faces New Lawsuit After ChatGPT Allegedly Discouraged Life-Saving Medical Care
OpenAI and Sam Altman have been sued again, this time over inaccurate and dangerous medical advice. Scott Winters, a pastor from Florida, had been experiencing dizzy spells and tenderness in his groin. GPT-4o advised him to reduce his movement and stay at home. It said the tenderness was probably nothing serious. It told him the situation was “under God’s watch”. Winters then had a pulmonary embolism.
He was hospitalized the day after asking about the tenderness, which turned out to be a sign of blood clots in his lungs. Doctors said the embolism was likely caused by a lack of movement.
The claim also alleges that GPT-4o initially showed medical disclaimers suggesting that Winters consult with a medical professional, but these messages stopped later in the chat. It also advised him against the doctors’ rehabilitation program and once again, told him to stay home.
The lawsuit calls for the rollout of ChatGPT Health to be paused until a third-party safety audit has been done. It also asks that chats be terminated in cases where urgent medical help is needed.
A spokesperson for OpenAI said that an individual’s health decisions are based on more than a chatbot’s response, and to suggest otherwise is an oversimplification that would prevent users from accessing “powerful new tools that can aid them in their health journey”.
Implications for brokers and their clients:
- Ensure tech E&O cover protects against claims alleging that AI-generated advice caused financial loss, bodily injury or other harm due to errors, omissions or misleading outputs.
- Review D&O insurance to confirm whether executives are protected against shareholders, regulatory, and governance claims stemming from AI safety, product oversight, and risk management decisions.
- Consider strengthening product liability policies in regions where AI systems are classified as products.
Source: Reuters (July 23, 2026). ChatGPT’s advice kept man from seeking medical treatment for dangerous condition, lawsuit claims.
Lines of business mentioned: Tech E&O Insurance, Directors and Officers Liability Insurance, Product Liability Insurance.
Verus Ethereum Bridge Suffers Second Multi-Million-Dollar Exploit in Two Months
On July 23, 2026, the Verus Ethereum Bridge was exploited, with attackers stealing approximately $7.54 million through a vulnerability in the bridge’s import mechanism. The stolen assets, which included tBTC, USDC, USDT, EURC, MKR and scrvUSD, were transferred to a wallet controlled by the attacker.
This follows a similar incident in May. Although the latest exploit involved a different transaction and wallet address, it appears to have targeted the same bridge contract and exploited the same type of vulnerability. The root cause is still being investigated.
The Verus breach was one of several attacks reported within a matter of hours. According to on-chain analytics platform Lookonchain, exploits affecting AFX Trade, Verus and B² Network resulted in combined losses of around $35.55 million.
Implications for brokers and their clients:
- Consider digital asset crime insurance to protect against losses resulting from theft, insider fraud, wallet compromises, social engineering attacks, and other criminal activity.
- Consider business interruption cover to help offset lost income in case a cyberattack forces critical systems offline.
- Investigate specialist digital asset and web3 insurance to protect against protocol vulnerabilities, smart contract exploits, compliance risks, investor disputes, and other blockchain-related risks.
Source: crypto. news (July 23, 2026). Verus Ethereum Bridge hacked again for $7.54M after May exploit.
Emerging insurance industries mentioned: Digital Asset and Web3 Insurance.
Lines of business mentioned: Digital Asset Crime Insurance, Business Interruption Insurance.
OpenAI Reveals First Autonomous AI Cyberattack After Models Breach Testing Limits
OpenAI has announced a novel cyberattack where two of its agents breached their testing boundaries and hacked AI research platform, Hugging Face.
During an internal cybersecurity evaluation, the agents accessed Hugging Face to retrieve information that would help them complete the assessment, bypassing the restrictions placed on them.
This attack is considered the first of its kind, but OpenAI suggests that similar incidents will become more common as models advance.
Implications for brokers and their clients:
- Consider specialist AI insurance designed to address risks unique to technology, including claims arising from hallucinations, inaccurate recommendations, algorithmic errors, model bias, and regulatory investigations.
- Verify whether clients’ cyber liability cover includes protection against unauthorized system access, incident response costs, forensic investigations, and third-party claims following AI-related cyber events.
- Review whether technology errors and omissions insurance is in place to protect against claims alleging that AI systems failed to perform as intended, resulting in financial loss or operational disruption.
Source: TechTarget (July 24, 2026). Weekly news roundup: OpenAI hacks Hugging Face, Google expands Gemini, Meta lawsuit dropped.
Emerging insurance industries mentioned: Artificial Intelligence Insurance.
Lines of business mentioned: Cyber and Tech E&O Insurance.
Malaysia Strengthens Cybercrime Defenses with New Law Targeting Digital Fraud
Malaysia’s Cybercrimes Bill 2026 has been approved by the Dewan Negara. It will replace the Computer Crimes Act 1997 with a more comprehensive framework for addressing cyber offences.
Senators have also proposed harsher penalties for large fraud syndicates, direct compensation for victims, and court solutions including the removal of content and compromised digital identities.
The bill calls for financial institutions and telecoms providers to strengthen authentication methods, and provisions for cross-border investigations and extradition for the most serious offences.
Implications for brokers and their clients:
- Consider working with insurers that offer specialist fintech insurance and understand multi-jurisdictional regulatory requirements, so that cover adequately protects against evolving cybercrime, fraud, and compliance risks across different markets.
- Consider obtaining cyber insurance covering data breaches, cyber extortion, incident response costs, business interruption, regulatory investigations, and other liabilities arising from cyberattacks.
- Investigate crime insurance to protect against losses from cyber-enabled fraud, social engineering, phishing, funds transfer fraud, and other financial crimes.
Source: Fintech News Malaysia (July 21, 2026). Malaysia Approves Cybercrimes Bill 2026 to Replace Three-Decade-Old Law.
Emerging insurance industries mentioned: Fintech Insurance.
Lines of business mentioned: Cyber Liability Insurance, Crime Insurance.