AI scams have changed the fraud game. A fake voice call can sound exactly like your boss. A video can look like a real person. An email can feel perfectly normal, right up until money leaves the account.
Why AI Scams Are Tricky for Insurance
Cyber insurance usually responds to defined cyber risks rather than every type of fraud that happens online. That distinction matters because an AI scam may involve technology without being treated as a cyber attack under the policy.
Imagine an employee receives a deepfake video call from someone who appears to be a senior executive. They follow the instructions and transfer company money. The fraud used AI, but the insurer may focus on the fact that an employee voluntarily authorised the payment.
Social Engineering Changes the Picture
Many cyber policies have specific coverage for social engineering fraud. Others exclude it unless the business buys an additional endorsement. Some policies also place lower limits on these claims than they do for a standard cyber incident.
• A social engineering section could cover a fraudulent payment, but only if its wording matches the way the scam happened.
• Employee deception is often treated differently from unauthorised access, which can make a huge difference to the claim.
• Deepfake involvement alone doesn’t decide coverage. The policy’s definition of fraud does.
What Happens With Deepfakes and AI-Generated Messages?
Deepfake scams deserve particular attention because they blur the line between cybercrime and traditional fraud. An attacker might use AI to copy someone’s voice, create a convincing video, or produce a message that looks completely legitimate.
Read the Exclusions Before You Need Them
Don’t wait until after a loss to discover that your policy treats authorised transfers differently from stolen credentials. Look closely at the wording around social engineering, fraudulent instructions, impersonation, computer fraud and employee dishonesty.
• Exclusions for voluntary payments can be especially important if someone was tricked into approving the transaction themselves.
• A separate social engineering limit may apply, and it can be much smaller than the policy’s main cyber limit.
• Security requirements buried in the policy can matter too, particularly if the insurer expects payment verification controls to be followed.
So, Are AI Scams Actually Excluded?
Sometimes. But saying that all AI scams are excluded would be wrong.
If an attacker uses AI to obtain credentials and then gains unauthorised access, the event may fit more naturally within traditional cyber coverage. If someone is fooled by a deepfake executive and knowingly sends money, the claim may instead fall under social engineering coverage, assuming that coverage exists.
The Real Question Is Sitting in Your Policy
If your business relies on email approvals or remote payment instructions, AI-enabled impersonation deserves a proper review of your cyber insurance. Ask where social engineering sits in the policy. Check the sub-limit. Then look at the exclusions and security conditions.
Because AI makes scams more convincing, insurers are paying closer attention to how those losses happen. A policy written before deepfakes became this convincing may not say “AI scam” anywhere at all.