Where Cyber Insurance May Respond
Most cyber insurance policies are built around losses linked to cyber events, fraud, or social engineering. Some policies include specific coverage for funds that are transferred because an employee was tricked. That’s where an AI scam can become relevant.
The Policy Wording Matters
• Social engineering coverage is the big one here, especially if an employee was persuaded to send funds.
• A separate crime or funds transfer section may apply instead, depending on how the insurer has structured the policy.
• An exclusion for voluntary transfers can cause trouble, even when the employee acted because of a highly convincing AI-generated instruction.
Why Claims Can Get Complicated
An insurer will usually look closely at what happened before deciding whether a loss is covered. If the employee ignored a required verification process, that could become important. So could a failure to follow the company’s security procedures.
What Should Businesses Check?
Don’t wait for a deepfake incident to discover that social engineering wasn’t included.
• Check whether fraudulent transfer losses are covered at all. This is worth doing before renewal, not after money has disappeared.
• Look at the sublimit because a generous headline policy limit doesn’t mean every fraud loss gets that amount.
• Read the exclusions carefully, particularly around authorized transfers and employee actions.
• Make sure the policy’s security conditions match what employees actually do. A rule nobody follows isn’t much protection.