
A few years ago, the cyber insurance conversation in the boardroom was fairly predictable: ransomware, data breach, maybe a nod to third-party vendors for risk. That conversation has changed. Artificial intelligence has rewritten all sides of the story – it is now the attacker’s most efficient tool, the defender’s most promising ally, and, increasingly, a source of risk that nobody’s Insurance policy wording was designed to address. Now it is an enterprise risk conversation, and it needs mainly the three functions of the enterprise IT, Finance and Legal in the room.
AI has changed the maths of an attack
The numbers tell their own story. Ransomware attacks rose sharply through 2025, extortion-style incidents grew even faster, and one payment reportedly touched US$75 million. Business Email Compromise, now supercharged by AI-generated voice and video impersonation, crossed US$3 billion in reported losses in a single year, as per the FBI IC3 report 2025. What used to require a skilled criminal crew – convincing language, a well-timed call, a forged signature – can now be assembled by a single operator using freely available generative tools.
The barrier to entry has collapsed, and the realism of the deception has gone up at the same time. Email remains the most common way attackers get in the door, but what happens after that first click is faster, more targeted, and harder to spot than it was even two years ago.
The AI claims are now a stark reality
This is the part boards sometimes miss – AI-related losses have already moved from theory into live claims. Industry surveys now show roughly one in five insurance professionals have seen an AI-related claim come through, and only about half of those losses were adequately insured when they landed. Cyber liability sits at the centre of this exposure, but Errors & Omissions and Directors’ & Officers’ covers are being pulled in too.
We see this pattern in the claims we help clients navigate. A services firm lost several hundred thousand dollars to a vendor-impersonation fraud where the “CFO” on the approval call was a cloned voice – it settled only because the social-engineering extension had been negotiated in the Crime Policy.
A logistics client hit by a ransomware event tied to a shared cloud vendor found itself negotiating not just its own claim but accumulation risk, since dozens of other firms on the same platform were affected simultaneously. In cases that the claim settles – how fast, and for how much, depends on whether the policy anticipated AI-specific scenarios, and whether the internal legal, IT security and finance teams had already agreed who does what in the first 48 hours.
“Silent AI” is the new silent cyber
A decade ago, insurers discovered that traditional property and liability policies were quietly absorbing cyber losses nobody had priced for – that became known as silent cyber. We are watching the same story repeat with AI. Most existing cyber and liability wordings neither explicitly cover nor explicitly exclude AI-related loss. That ambiguity feels harmless until a claim tests it, at which point it becomes a coverage dispute, and coverage disputes are expensive even when you eventually win them.
Underwriting is catching up, in real time
Insurers are moving away from annual questionnaires and self-certified controls toward continuous attack-surface monitoring and AI-driven risk scoring. New products are emerging for this specific gap – some Reinsurers cover AI performance failures in credit scoring and fraud detection, while some others offer affirmative cover for AI underperformance and hallucination.
Important things to check
Firstly, ask your broker directly whether your current wording addresses AI-enabled fraud, AI system failure, and regulatory penalties arising from AI use – don’t assume silence means cover. Secondly, get the internal Legal, the CISO and Finance teams to jointly walk through one realistic AI-attack scenario and agree, on paper, who owns notifications, forensics, negotiation and evidence-preservation in the first few hours.
AI has not made cyber risk scarier so much as it has made it faster and more interconnected. The organisations that settle their claims quickly and cleanly are, almost without exception, the ones that had this conversation before the incident, not during it.





