Often, but it depends on what went wrong. Most cyber policies respond when AI is simply the method: a deepfake call that tricks staff into paying, or an AI-written phishing email that leads to a breach. They're far less certain when your own AI tool makes a mistake or leaks data without anyone hacking you. Check the wording with your broker.
The reason for the uncertainty has a name in the insurance market: "silent AI". Until recently, cyber policies neither mentioned AI nor excluded it, so AI-related losses were covered or not depending on how existing definitions happened to apply. Insurers are now making that explicit, some by writing AI cover in and some by carving parts of it out, and the change often shows up in definitions, sublimits and proposal-form questions rather than in a headline exclusion. Nothing here is insurance advice: it's a map of where to look and what to ask, so the conversation with your broker is short and specific.
Seven AI incidents and where cover usually sits
Cyber policies are usually built from sections: incident response and breach costs, business interruption, data recovery, cyber extortion, a cyber crime section for fraud, and liability for privacy breaches and media claims. Whether an AI incident is covered comes down to which section it falls into, and whether the facts fit that section's definitions.
| Incident | Where it usually sits | What to check in your wording |
|---|---|---|
| A deepfake call or video persuades staff to pay a fake supplier | Cyber crime section: funds transfer fraud or social engineering, if included | Whether social engineering is covered at all, its sublimit, and whether the trigger covers instructions by phone or video as well as email |
| An AI-written phishing email leads to ransomware | Core cyber cover: extortion, data recovery, business interruption | Conditions such as multi-factor authentication on email; AI is just the delivery method here |
| A staff member pastes client personal data into a free AI tool | Possibly privacy liability and breach response, if the definition fits | Whether "unauthorised disclosure" includes a voluntary act by an employee with no hack involved |
| Your AI chatbot gives a customer wrong information that costs them money | Usually not cyber; professional indemnity, if anything | Your professional indemnity wording and any AI exclusions in it |
| An AI agent with access to your systems deletes files or sends data out while "working" | Grey zone | Whether "security failure" needs unauthorised access, and any new wording on autonomous software |
| A deepfake of your owner or brand circulates online | Only if the policy offers a deepfake or reputation extension | Whether forensic analysis, takedown work and PR support are included |
| An AI supplier your business depends on has an outage or breach | Contingent (dependent) business interruption, if included | Whether software suppliers count as dependent businesses, and the waiting period before cover starts |
The first row is where real money moves, and where wording varies most. Insurers write these risks both ways. As one example, the cyber insurer Coalition added an Affirmative AI Endorsement in March 2024, in some markets, extending its funds transfer fraud trigger to "fraudulent instruction transmitted through the use of deepfakes or any other artificial intelligence technology", and extending its security failure definition to incidents where AI "caused a failure of computer systems' security". In December 2025 it added a Deepfake Response Endorsement providing forensic analysis with a written report, legal work to get a deepfake taken down, and crisis communications support. Other insurers cover the same ground through existing definitions, or don't. Your policy schedule and wording decide it, not the market's general direction.
Why "silent AI" is ending, and what that means at renewal
A June 2026 analysis by the law firm Fenwick describes the market moving away from silent AI: AI risks used to be handled implicitly by traditional policies, and insurers are now introducing AI-specific exclusions and revised forms. Its observation that matters most to a small firm is that narrowing tends to arrive quietly, through revised base forms, endorsements, definitions and application questions, rather than one obvious "AI exclusion" clause. It also found cyber policies relatively stable on AI so far, with tougher treatment in directors' and officers' and employment practices policies.
Trade reporting in August 2026 said insurers such as QBE and Beazley were mainly clarifying existing cyber wording for AI rather than excluding it. QBE described treating AI "as a risk amplifier, not a fundamentally new cyber risk". The areas where targeted exclusions were being discussed are telling: a single AI model causing losses at many organisations at once, and decisions an AI agent takes while operating as designed, which some insurers may treat as non-cyber events. The hard case, as that reporting put it, is a loss with no conventional hacker and potentially no unauthorised access.
So at renewal, read three things, not just the price: any new definition mentioning artificial intelligence, automated systems or autonomous software; any new sublimit on social engineering or funds transfer fraud; and any new questions about AI on the proposal form, because your answers become part of the contract.
Questions to expect on the proposal form
Proposal forms vary, but the themes repeat. Hiscox's cyber proposal form, for instance, asks whether two-factor authentication is enforced for all remote access, including webmail and cloud log-ins, and whether you ensure multi-factor authentication for any fund transfer. Grouped by theme, with why each matters for AI-era losses:
- Access controls. Multi-factor authentication on email, remote access and admin accounts. Why it matters: AI-written phishing is more convincing, so a stolen password alone must not be enough.
- Backups. Whether you back up, how often, whether a copy is separate from your main systems, and whether restores are tested. Why: this decides whether ransomware is an inconvenience or a closure.
- Payment controls. Whether transfers above a threshold, and any bank-detail change, are verified through a separate channel using a number you already hold, including requests that appear to come from senior people. Why: this is the control that defeats deepfake fraud.
- Staff training. Whether staff are trained to recognise phishing and social engineering, and how often.
- AI governance, the newer section. Which AI tools are in use, whether new tools need approval, whether a written AI use policy exists, what data staff may put into AI tools, whether AI makes or drafts customer-facing decisions, and whether any AI agent can access email, files or payments.
- History. Previous incidents, claims, and circumstances that could lead to one, including near misses.
Here's a filled-in answer sheet a four-person surveying firm might prepare before its broker call, so the answers match reality:
AI AND SECURITY FACTS FOR RENEWAL Prepared: [month, year]
MFA: On for all Microsoft 365 accounts and the banking app.
Not on the old survey-software login (fix by [date]).
Backups: Nightly cloud backup plus weekly copy to a drive kept
off-site; last test restore [date], 12 minutes.
Payments: Call-back to a number from our records for all new
payees and bank changes; 2 approvers above $2,000.
AI tools: Microsoft Copilot Chat (business accounts only).
Free AI apps banned for client data since [date].
AI policy: One page, adopted [date], signed by all 4 staff.
AI access: No AI tool can send email, move money or delete files.
Incidents: None. One failed deepfake voice-note attempt, [date];
blocked by the call-back rule, logged.
Writing it down first stops the most common mistake: answering "yes" to a control that is only partly in place.
Answering the AI questions without over- or under-selling
Insurers price and accept the risk on what you tell them. Hiscox's form, typical of many, says the insurer relies on the information you give when deciding whether to accept the insurance and setting the terms, and asks you to present the risk fairly and make sure answers are true, accurate and complete. An inaccurate answer can come back to bite at claim time, so precision matters more than looking good. Two before-and-after answers show the difference.
Question: "Do you have a policy governing employees' use of AI tools?"
Before: Yes.
After: Yes. One-page AI use policy adopted [month, year]. Staff use
[business AI plan] only; client personal data is not to be
entered into free AI tools. Reviewed every 6 months by
[first name]. All staff signed it.
The "before" was true in the sense that a sentence about AI existed in the staff handbook. The "after" is a claim the firm can prove, and it tells the underwriter something useful.
Question: "Do you verify all payment instructions by an independent method?"
Before: Yes, always.
After: All new payees and all bank-detail changes are verified by
calling a number held in our own records. Payments over
$2,000 need two approvers. Routine payments to existing
payees with unchanged details are not called back.
The "before" answer was wrong: routine payments weren't checked. If a loss ever came through one of those, the gap between the answer and the practice is exactly what an insurer would examine. The "after" answer is honest and still describes a strong control. The verification routine itself, with a call-back rule and code words, is set out in how to spot deepfake voice and video scams.
A renewal at an 18-person engineering consultancy
Here's how the pieces fit together at a larger illustrative firm. The consultancy's renewal questionnaire arrives with a new AI section. Its current policy schedule shows a $1 million overall limit, with social engineering fraud covered but sublimited to $25,000.
- Inventory the tools (1 hour). The office manager asks everyone which AI tools they used last month. The answer: three approved tools, plus two free apps nobody had approved, one used to summarise client specifications. Those two get replaced with the approved plan and the policy is updated.
- Check who can move money (30 minutes). Two directors and the accounts assistant. Subcontractor payments of $30,000-$40,000 are routine.
- Run the numbers on the sublimit. If a deepfake call diverted one $38,400 subcontractor payment, the most the policy could pay is the $25,000 sublimit. With an illustrative $2,500 excess, the firm would be left with $13,400 of the loss if the excess comes off the loss before the sublimit applies, or $15,900 if it comes off the $25,000. Which one applies is a wording question in itself.
- Ask the broker three things. What a higher social engineering sublimit, say $100,000, would cost; whether the trigger covers instructions received by phone, video or messaging app, or only email; and how the policy treats an AI agent acting without unauthorised access.
- Tighten the control either way. Call-backs extended to every payment over $10,000, not just new payees, which lets the firm answer the payment question with a clean "yes" and lowers the chance of ever using the cover.
The broker's answers decide whether the higher sublimit is worth its price; no general guide can. What the exercise gives the firm is an accurate proposal form, a gap measured in dollars rather than a vague worry, and a stronger control in the meantime. Getting from "we think we're covered" to "we know the gap is up to $15,900 and here's the quote to close it" took about three hours.
If staff use AI agents, limit what they can touch
AI agents, tools that act on your behalf by clicking, sending and editing rather than just drafting text, are the part of AI that insurers are still working out. The discussion in the market is about losses where nobody broke in: the agent had permission and did something harmful anyway. You can't settle that wording question yourself, but you can make sure the question rarely arises, by keeping agents away from the actions that cause large losses. A filled-in permissions record for the same engineering consultancy:
| Agent job | Access given | Access withheld |
|---|---|---|
| Sorting the shared inbox into project folders | Read and label email | Sending, forwarding, deleting |
| Drafting replies to routine enquiries | Create drafts | Sending without a person clicking send |
| Researching suppliers in a browser | Public websites | Banking, payroll and any logged-in admin site |
| Tidying project files | Copy and rename in one test folder | Deleting anything, access to client archives |
Two benefits follow. The worst an agent can do shrinks to something annoying rather than expensive, and you can answer the proposal form's agent question precisely: "AI tools can draft and sort, and cannot send email, move money or delete files." Review the record whenever someone connects a new tool, because agent permissions tend to grow one convenient click at a time.
AI mistakes that usually fall outside cyber cover
Cyber insurance is built around security and privacy events. Many AI problems are neither; they're errors in work you deliver, and those belong to other policies.
- Wrong professional advice. An accountancy practice sends a client a tax-planning note drafted with AI that includes an outdated relief. The client acts on it and loses money. That's a professional negligence claim, for the practice's professional indemnity policy, whether or not AI wrote the first draft.
- A chatbot's promise. A kitchen fitter's website chatbot tells a customer a 10% discount applies to a full kitchen when it doesn't. That's a customer dispute about what the business said, and it's unlikely to be a cyber event at all.
- An AI image that infringes someone's work. An architect practice uses an AI-generated illustration in a brochure and receives a copyright complaint. Some cyber policies include media liability for infringement and defamation, so this one may fall inside, which is worth checking.
The broader question of AI errors across all your policies, including professional indemnity, is covered in whether your business insurance covers AI mistakes. The practical defence is the same whichever policy is involved: a person checks AI output before it reaches a client, and you can show that they did.
An email to send your broker this month
Brokers answer specific questions faster and better than general ones. Adapt this:
Subject: AI-related questions on our cyber policy before renewal
Hi [broker's first name],
Before our renewal on [date], could you confirm in writing how our
current cyber policy would respond to these situations:
1. A deepfake phone or video call persuades a staff member to pay a
fraudulent account. Is social engineering covered, what is the
sublimit, and does the trigger include phone, video and messaging
apps as well as email?
2. A staff member pastes client personal data into a free AI tool,
with no hacking involved. Does that count as a privacy event?
3. An AI tool or agent we authorised deletes or discloses data while
operating normally. Is that a covered security failure?
4. An AI supplier we depend on has an outage. Does contingent
business interruption cover software suppliers?
5. Does the renewal wording add any AI-related definitions,
exclusions or sublimits compared with our current policy?
We've attached our current AI tool list and AI use policy.
Thanks, [your name]
Keep the reply on file with the policy. If the answers reveal a gap, ask for a quote to close it, and weigh that against tightening the control that would prevent the loss in the first place.
An evidence folder that helps at claim time
A claim goes more smoothly when you can show the controls you described actually existed. Keep one folder, updated when things change, with:
- The signed AI use policy and the list of approved AI tools, with dates.
- Screenshots showing multi-factor authentication switched on for email and banking.
- The payment verification procedure, plus a log of call-backs made on bank-detail changes.
- Backup reports and the date of the last test restore.
- Training records: who attended what, when, including any deepfake or phishing drills.
- Your proposal form answers and the broker's written replies about cover.
Twenty minutes a quarter keeps it current. If an incident does happen, the folder also doubles as the starting point for your response; an AI incident response plan shows what to do in the first hours, including when to call the insurer's incident line, which many policies expect you to use before appointing your own experts. And if the inventory step turns up tools nobody approved, an AI tool approval process stops the list growing again before next year's renewal.
Cyber insurance and AI: short answers
Will cyber insurance pay if a staff member pastes client data into a free AI tool?
It depends on how your policy defines a privacy or security event. Some wordings respond to any unauthorised disclosure of personal data, including one caused by an employee; others centre on a hack or security failure, and a voluntary paste may not fit. Ask your broker that exact scenario and get the answer in writing before you need it.
Will using AI tools push up my cyber premium?
Using mainstream AI tools isn't, on its own, a reason insurers give for charging more. What affects terms is the risk picture: weak controls, no policy on what data goes into AI, AI agents with access to email or payments. Good answers on the proposal form, backed by evidence, are what keep terms reasonable. Your broker can tell you how your insurer weighs it.
Is there separate insurance for AI mistakes?
A small specialist market has appeared, with some insurers offering cover for AI models underperforming or producing wrong outputs, mostly aimed at businesses that build or sell AI. For a firm that simply uses AI tools, the first step is checking how your existing professional indemnity and cyber policies respond; a broker can say whether anything standalone is worth pricing.
Further reads
- Does a Five-Person Business Really Need an AI Policy? — The written AI policy insurers increasingly ask to see.
- AI Security Risks for Small Businesses and How to Close Them — The security gaps behind most of the claims in this tutorial.
- Business Data Backup Checklist Before You Connect AI Tools — Backups are a standard proposal-form question; get them right.
- What Is an AI Browser Agent, and Should Staff Use One? — Why AI agents with account access sit in the grey zone.
- What Is Data Loss Prevention, and Does a Small Business Need It? — Controls that stop client data leaking into AI tools.
- AI Compliance Checklist for Small Businesses: What Applies to You — The wider compliance picture your broker may ask about.
- A Simple AI Risk Register for Small Businesses (With Template) — A one-table AI risk register with a scoring scale, a template to copy, twelve filled-in rows from a florist and the triggers for updating it.
- Business Continuity Planning With AI: A Template for Small Firms — A ten-section continuity plan template with the checks for each item, plus prompts that let AI interview you and run a tabletop test.
- How to Spot Fake AI Apps and Risky Browser Extensions — Real cases of fake ChatGPT downloads and chat-stealing extensions, plus a 60-second install check and a browser audit for small teams.
- What Is Prompt Injection and Should a Small Business Worry? — How hidden instructions in emails, web pages and CVs hijack AI assistants, a five-minute exposure check, and the controls that work without an IT team.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: Coalition's coverage pages and its announcements of the Affirmative AI Endorsement (March 2024) and Deepfake Response Endorsement (December 2025); Hiscox CyberClear proposal form; Fenwick, 'The End of Silent AI?' (June 2026); Insurance Journal, 'As AI Agents Go Rogue, Cyber Insurers Are Adapting Their Policies' (August 2026); Marsh insight on financial lines insurance and AI risk.