Where Cyber Insurance May Respond

Most cyber insurance policies are built around losses linked to cyber events, fraud, or social engineering. Some policies include specific coverage for funds that are transferred because an employee was tricked. That’s where an AI scam can become relevant.

The Policy Wording Matters

Two cyber policies can look almost identical from a distance and still handle AI fraud very differently. One might cover social engineering losses. Another might exclude them unless a separate endorsement has been added.

• Social engineering coverage is the big one here, especially if an employee was persuaded to send funds.

• A separate crime or funds transfer section may apply instead, depending on how the insurer has structured the policy.

• An exclusion for voluntary transfers can cause trouble, even when the employee acted because of a highly convincing AI-generated instruction.

Why Claims Can Get Complicated

An insurer will usually look closely at what happened before deciding whether a loss is covered. If the employee ignored a required verification process, that could become important. So could a failure to follow the company’s security procedures.

What Should Businesses Check?

Don’t wait for a deepfake incident to discover that social engineering wasn’t included.

• Check whether fraudulent transfer losses are covered at all. This is worth doing before renewal, not after money has disappeared.

• Look at the sublimit because a generous headline policy limit doesn’t mean every fraud loss gets that amount.

• Read the exclusions carefully, particularly around authorized transfers and employee actions.

• Make sure the policy’s security conditions match what employees actually do. A rule nobody follows isn’t much protection.

AI scams are moving quickly, and insurance wording won’t automatically keep pace. That’s why the safest approach is pretty simple: treat AI fraud as a coverage question that needs to be answered before the claim happens.