Does Cyber Insurance Cover AI Incidents? What Insurers Ask

Coding Liquids tutorial cover featuring Sagnik Bhattacharya for Does Cyber Insurance Cover AI Incidents? What Insurers Ask.
Coding Liquids tutorial cover featuring Sagnik Bhattacharya for Does Cyber Insurance Cover AI Incidents? What Insurers Ask.

Often, but it depends on what went wrong. Most cyber policies respond when AI is simply the method: a deepfake call that tricks staff into paying, or an AI-written phishing email that leads to a breach. They're far less certain when your own AI tool makes a mistake or leaks data without anyone hacking you. Check the wording with your broker.

The reason for the uncertainty has a name in the insurance market: "silent AI". Until recently, cyber policies neither mentioned AI nor excluded it, so AI-related losses were covered or not depending on how existing definitions happened to apply. Insurers are now making that explicit, some by writing AI cover in and some by carving parts of it out, and the change often shows up in definitions, sublimits and proposal-form questions rather than in a headline exclusion. Nothing here is insurance advice: it's a map of where to look and what to ask, so the conversation with your broker is short and specific.

Follow me on Instagram@sagnikteaches

Seven AI incidents and where cover usually sits

Cyber policies are usually built from sections: incident response and breach costs, business interruption, data recovery, cyber extortion, a cyber crime section for fraud, and liability for privacy breaches and media claims. Whether an AI incident is covered comes down to which section it falls into, and whether the facts fit that section's definitions.

Connect on LinkedInSagnik Bhattacharya
IncidentWhere it usually sitsWhat to check in your wording
A deepfake call or video persuades staff to pay a fake supplierCyber crime section: funds transfer fraud or social engineering, if includedWhether social engineering is covered at all, its sublimit, and whether the trigger covers instructions by phone or video as well as email
An AI-written phishing email leads to ransomwareCore cyber cover: extortion, data recovery, business interruptionConditions such as multi-factor authentication on email; AI is just the delivery method here
A staff member pastes client personal data into a free AI toolPossibly privacy liability and breach response, if the definition fitsWhether "unauthorised disclosure" includes a voluntary act by an employee with no hack involved
Your AI chatbot gives a customer wrong information that costs them moneyUsually not cyber; professional indemnity, if anythingYour professional indemnity wording and any AI exclusions in it
An AI agent with access to your systems deletes files or sends data out while "working"Grey zoneWhether "security failure" needs unauthorised access, and any new wording on autonomous software
A deepfake of your owner or brand circulates onlineOnly if the policy offers a deepfake or reputation extensionWhether forensic analysis, takedown work and PR support are included
An AI supplier your business depends on has an outage or breachContingent (dependent) business interruption, if includedWhether software suppliers count as dependent businesses, and the waiting period before cover starts

The first row is where real money moves, and where wording varies most. Insurers write these risks both ways. As one example, the cyber insurer Coalition added an Affirmative AI Endorsement in March 2024, in some markets, extending its funds transfer fraud trigger to "fraudulent instruction transmitted through the use of deepfakes or any other artificial intelligence technology", and extending its security failure definition to incidents where AI "caused a failure of computer systems' security". In December 2025 it added a Deepfake Response Endorsement providing forensic analysis with a written report, legal work to get a deepfake taken down, and crisis communications support. Other insurers cover the same ground through existing definitions, or don't. Your policy schedule and wording decide it, not the market's general direction.

Subscribe on YouTube@codingliquids

Why "silent AI" is ending, and what that means at renewal

A June 2026 analysis by the law firm Fenwick describes the market moving away from silent AI: AI risks used to be handled implicitly by traditional policies, and insurers are now introducing AI-specific exclusions and revised forms. Its observation that matters most to a small firm is that narrowing tends to arrive quietly, through revised base forms, endorsements, definitions and application questions, rather than one obvious "AI exclusion" clause. It also found cyber policies relatively stable on AI so far, with tougher treatment in directors' and officers' and employment practices policies.

Trade reporting in August 2026 said insurers such as QBE and Beazley were mainly clarifying existing cyber wording for AI rather than excluding it. QBE described treating AI "as a risk amplifier, not a fundamentally new cyber risk". The areas where targeted exclusions were being discussed are telling: a single AI model causing losses at many organisations at once, and decisions an AI agent takes while operating as designed, which some insurers may treat as non-cyber events. The hard case, as that reporting put it, is a loss with no conventional hacker and potentially no unauthorised access.

So at renewal, read three things, not just the price: any new definition mentioning artificial intelligence, automated systems or autonomous software; any new sublimit on social engineering or funds transfer fraud; and any new questions about AI on the proposal form, because your answers become part of the contract.

Questions to expect on the proposal form

Proposal forms vary, but the themes repeat. Hiscox's cyber proposal form, for instance, asks whether two-factor authentication is enforced for all remote access, including webmail and cloud log-ins, and whether you ensure multi-factor authentication for any fund transfer. Grouped by theme, with why each matters for AI-era losses:

  • Access controls. Multi-factor authentication on email, remote access and admin accounts. Why it matters: AI-written phishing is more convincing, so a stolen password alone must not be enough.
  • Backups. Whether you back up, how often, whether a copy is separate from your main systems, and whether restores are tested. Why: this decides whether ransomware is an inconvenience or a closure.
  • Payment controls. Whether transfers above a threshold, and any bank-detail change, are verified through a separate channel using a number you already hold, including requests that appear to come from senior people. Why: this is the control that defeats deepfake fraud.
  • Staff training. Whether staff are trained to recognise phishing and social engineering, and how often.
  • AI governance, the newer section. Which AI tools are in use, whether new tools need approval, whether a written AI use policy exists, what data staff may put into AI tools, whether AI makes or drafts customer-facing decisions, and whether any AI agent can access email, files or payments.
  • History. Previous incidents, claims, and circumstances that could lead to one, including near misses.

Here's a filled-in answer sheet a four-person surveying firm might prepare before its broker call, so the answers match reality:

AI AND SECURITY FACTS FOR RENEWAL          Prepared: [month, year]
MFA:             On for all Microsoft 365 accounts and the banking app.
                 Not on the old survey-software login (fix by [date]).
Backups:         Nightly cloud backup plus weekly copy to a drive kept
                 off-site; last test restore [date], 12 minutes.
Payments:        Call-back to a number from our records for all new
                 payees and bank changes; 2 approvers above $2,000.
AI tools:        Microsoft Copilot Chat (business accounts only).
                 Free AI apps banned for client data since [date].
AI policy:       One page, adopted [date], signed by all 4 staff.
AI access:       No AI tool can send email, move money or delete files.
Incidents:       None. One failed deepfake voice-note attempt, [date];
                 blocked by the call-back rule, logged.

Writing it down first stops the most common mistake: answering "yes" to a control that is only partly in place.

Answering the AI questions without over- or under-selling

Insurers price and accept the risk on what you tell them. Hiscox's form, typical of many, says the insurer relies on the information you give when deciding whether to accept the insurance and setting the terms, and asks you to present the risk fairly and make sure answers are true, accurate and complete. An inaccurate answer can come back to bite at claim time, so precision matters more than looking good. Two before-and-after answers show the difference.

Question: "Do you have a policy governing employees' use of AI tools?"

Before: Yes.

After:  Yes. One-page AI use policy adopted [month, year]. Staff use
        [business AI plan] only; client personal data is not to be
        entered into free AI tools. Reviewed every 6 months by
        [first name]. All staff signed it.

The "before" was true in the sense that a sentence about AI existed in the staff handbook. The "after" is a claim the firm can prove, and it tells the underwriter something useful.

Question: "Do you verify all payment instructions by an independent method?"

Before: Yes, always.

After:  All new payees and all bank-detail changes are verified by
        calling a number held in our own records. Payments over
        $2,000 need two approvers. Routine payments to existing
        payees with unchanged details are not called back.

The "before" answer was wrong: routine payments weren't checked. If a loss ever came through one of those, the gap between the answer and the practice is exactly what an insurer would examine. The "after" answer is honest and still describes a strong control. The verification routine itself, with a call-back rule and code words, is set out in how to spot deepfake voice and video scams.

A renewal at an 18-person engineering consultancy

Here's how the pieces fit together at a larger illustrative firm. The consultancy's renewal questionnaire arrives with a new AI section. Its current policy schedule shows a $1 million overall limit, with social engineering fraud covered but sublimited to $25,000.

  1. Inventory the tools (1 hour). The office manager asks everyone which AI tools they used last month. The answer: three approved tools, plus two free apps nobody had approved, one used to summarise client specifications. Those two get replaced with the approved plan and the policy is updated.
  2. Check who can move money (30 minutes). Two directors and the accounts assistant. Subcontractor payments of $30,000-$40,000 are routine.
  3. Run the numbers on the sublimit. If a deepfake call diverted one $38,400 subcontractor payment, the most the policy could pay is the $25,000 sublimit. With an illustrative $2,500 excess, the firm would be left with $13,400 of the loss if the excess comes off the loss before the sublimit applies, or $15,900 if it comes off the $25,000. Which one applies is a wording question in itself.
  4. Ask the broker three things. What a higher social engineering sublimit, say $100,000, would cost; whether the trigger covers instructions received by phone, video or messaging app, or only email; and how the policy treats an AI agent acting without unauthorised access.
  5. Tighten the control either way. Call-backs extended to every payment over $10,000, not just new payees, which lets the firm answer the payment question with a clean "yes" and lowers the chance of ever using the cover.

The broker's answers decide whether the higher sublimit is worth its price; no general guide can. What the exercise gives the firm is an accurate proposal form, a gap measured in dollars rather than a vague worry, and a stronger control in the meantime. Getting from "we think we're covered" to "we know the gap is up to $15,900 and here's the quote to close it" took about three hours.

If staff use AI agents, limit what they can touch

AI agents, tools that act on your behalf by clicking, sending and editing rather than just drafting text, are the part of AI that insurers are still working out. The discussion in the market is about losses where nobody broke in: the agent had permission and did something harmful anyway. You can't settle that wording question yourself, but you can make sure the question rarely arises, by keeping agents away from the actions that cause large losses. A filled-in permissions record for the same engineering consultancy:

Agent jobAccess givenAccess withheld
Sorting the shared inbox into project foldersRead and label emailSending, forwarding, deleting
Drafting replies to routine enquiriesCreate draftsSending without a person clicking send
Researching suppliers in a browserPublic websitesBanking, payroll and any logged-in admin site
Tidying project filesCopy and rename in one test folderDeleting anything, access to client archives

Two benefits follow. The worst an agent can do shrinks to something annoying rather than expensive, and you can answer the proposal form's agent question precisely: "AI tools can draft and sort, and cannot send email, move money or delete files." Review the record whenever someone connects a new tool, because agent permissions tend to grow one convenient click at a time.

AI mistakes that usually fall outside cyber cover

Cyber insurance is built around security and privacy events. Many AI problems are neither; they're errors in work you deliver, and those belong to other policies.

  • Wrong professional advice. An accountancy practice sends a client a tax-planning note drafted with AI that includes an outdated relief. The client acts on it and loses money. That's a professional negligence claim, for the practice's professional indemnity policy, whether or not AI wrote the first draft.
  • A chatbot's promise. A kitchen fitter's website chatbot tells a customer a 10% discount applies to a full kitchen when it doesn't. That's a customer dispute about what the business said, and it's unlikely to be a cyber event at all.
  • An AI image that infringes someone's work. An architect practice uses an AI-generated illustration in a brochure and receives a copyright complaint. Some cyber policies include media liability for infringement and defamation, so this one may fall inside, which is worth checking.

The broader question of AI errors across all your policies, including professional indemnity, is covered in whether your business insurance covers AI mistakes. The practical defence is the same whichever policy is involved: a person checks AI output before it reaches a client, and you can show that they did.

An email to send your broker this month

Brokers answer specific questions faster and better than general ones. Adapt this:

Subject: AI-related questions on our cyber policy before renewal

Hi [broker's first name],

Before our renewal on [date], could you confirm in writing how our
current cyber policy would respond to these situations:

1. A deepfake phone or video call persuades a staff member to pay a
   fraudulent account. Is social engineering covered, what is the
   sublimit, and does the trigger include phone, video and messaging
   apps as well as email?
2. A staff member pastes client personal data into a free AI tool,
   with no hacking involved. Does that count as a privacy event?
3. An AI tool or agent we authorised deletes or discloses data while
   operating normally. Is that a covered security failure?
4. An AI supplier we depend on has an outage. Does contingent
   business interruption cover software suppliers?
5. Does the renewal wording add any AI-related definitions,
   exclusions or sublimits compared with our current policy?

We've attached our current AI tool list and AI use policy.

Thanks, [your name]

Keep the reply on file with the policy. If the answers reveal a gap, ask for a quote to close it, and weigh that against tightening the control that would prevent the loss in the first place.

An evidence folder that helps at claim time

A claim goes more smoothly when you can show the controls you described actually existed. Keep one folder, updated when things change, with:

  • The signed AI use policy and the list of approved AI tools, with dates.
  • Screenshots showing multi-factor authentication switched on for email and banking.
  • The payment verification procedure, plus a log of call-backs made on bank-detail changes.
  • Backup reports and the date of the last test restore.
  • Training records: who attended what, when, including any deepfake or phishing drills.
  • Your proposal form answers and the broker's written replies about cover.

Twenty minutes a quarter keeps it current. If an incident does happen, the folder also doubles as the starting point for your response; an AI incident response plan shows what to do in the first hours, including when to call the insurer's incident line, which many policies expect you to use before appointing your own experts. And if the inventory step turns up tools nobody approved, an AI tool approval process stops the list growing again before next year's renewal.

Cyber insurance and AI: short answers

Will cyber insurance pay if a staff member pastes client data into a free AI tool?

It depends on how your policy defines a privacy or security event. Some wordings respond to any unauthorised disclosure of personal data, including one caused by an employee; others centre on a hack or security failure, and a voluntary paste may not fit. Ask your broker that exact scenario and get the answer in writing before you need it.

Will using AI tools push up my cyber premium?

Using mainstream AI tools isn't, on its own, a reason insurers give for charging more. What affects terms is the risk picture: weak controls, no policy on what data goes into AI, AI agents with access to email or payments. Good answers on the proposal form, backed by evidence, are what keep terms reasonable. Your broker can tell you how your insurer weighs it.

Is there separate insurance for AI mistakes?

A small specialist market has appeared, with some insurers offering cover for AI models underperforming or producing wrong outputs, mostly aimed at businesses that build or sell AI. For a firm that simply uses AI tools, the first step is checking how your existing professional indemnity and cyber policies respond; a broker can say whether anything standalone is worth pricing.

Further reads

Sources: Coalition's coverage pages and its announcements of the Affirmative AI Endorsement (March 2024) and Deepfake Response Endorsement (December 2025); Hiscox CyberClear proposal form; Fenwick, 'The End of Silent AI?' (June 2026); Insurance Journal, 'As AI Agents Go Rogue, Cyber Insurers Are Adapting Their Policies' (August 2026); Marsh insight on financial lines insurance and AI risk.

Want your AI controls ready before renewal?

On a 1:1 call we'll list the AI tools your team actually uses, spot where client data or payments are exposed, and put together the evidence your broker and insurer will ask for.

Book a 1:1 call with me