Cyber insurance and AI risks: what your policy needs to answer
AI-enabled phishing and deepfake fraud
The classic tells of a phishing email — odd phrasing, broken English, generic greetings — assumed the attacker was human and hurried. Generative AI removes those tells: messages arrive fluent, correctly formatted and personalised from public information about your firm. Voice cloning and deepfake video go further, putting a familiar voice on the phone — or a familiar face on a video call — asking for an urgent payment or a change of supplier bank details.
The endpoint is usually the same: an employee, genuinely deceived, authorises a transfer to a fraudster. Nothing was hacked. No system was breached. And that distinction — deception of a person rather than compromise of a system — is exactly where cyber cover gets complicated.
Does cyber insurance pay for deepfake payment fraud?
Only if the right section is there. Core cyber cover is built around security failure: breach response, system recovery, cyber business interruption, liability for compromised data. A payment authorised by a deceived human may involve no security failure at all, so the loss falls to a distinct section — usually called social engineering, funds-transfer fraud or cyber crime cover — which in many policies is optional, and almost always sub-limited well below the main policy limit.
Three things to check while the sun shines: whether your policy includes social engineering and funds-transfer fraud cover at all; what the sub-limit is, measured against the size of payment your finance team can actually release; and what conditions attach — many wordings require verification callbacks to a known number before payment changes, and an unfollowed procedure can undermine the claim. If you also carry a commercial crime policy, the boundary between the two needs mapping before a loss, not during one.
Staff pasting client data into public AI tools
The most widespread AI risk in most firms involves no attacker. An employee, trying to work faster, pastes client correspondence, financial details or personal data into a free public AI tool. That information has now left your control and sits with a third party on that provider’s terms — and depending on the tool’s settings, it may be retained or used beyond your instruction. If personal data is involved, that can amount to a personal data breach under UK GDPR, with the assessment and possible ICO notification duties that follow.
A cyber policy helps most through its incident-response machinery: legal advice on whether the incident is notifiable, forensic help establishing what went where, notification costs, and liability cover if affected clients claim. What no one should assume is that insurance pays regulatory penalties — ICO fines cannot be relied on to be insurable, so prevention, sensible tool policies and enterprise AI accounts do work a policy never will. Underwriters have started asking about exactly this: whether staff AI use is governed, and whether client data can reach public tools.
The insurance answer, in order
Controls first: payment-verification procedures that assume voices and video can be faked, an AI-use policy that keeps client data out of public tools, and staff who have seen convincing fakes in training. These are increasingly the underwriter’s questions as well as good practice — strong answers buy better terms.
Then the policy: cyber cover with social engineering and funds-transfer fraud sections present, sub-limits sized to your real payment flows, callback conditions your finance team actually follows, and the crime-policy boundary mapped. AI has not made cyber insurance obsolete; it has made the difference between a well-built policy and a cheap one much more expensive to discover at claim time.
Frequently asked questions
Does cyber insurance cover deepfake fraud?
Sometimes — it depends on the sections bought. Losses from staff deceived into making payments typically fall under social engineering or funds-transfer fraud cover, which is often optional and usually sub-limited. A policy without that section may pay nothing for a deepfake payment fraud, however large the headline limit.
An employee put client data into a public AI tool. Is that a data breach?
It can be. If personal data left your control, that may be a personal data breach under UK GDPR, and it needs assessing — some incidents must be reported to the ICO, others recorded internally. A cyber policy’s incident-response cover can fund the legal and forensic help to make that assessment properly.
Will cyber insurance pay an ICO fine?
Do not rely on it. The insurability of regulatory fines is legally doubtful in the UK, and policies commonly limit fines cover to where insurable at law — which may mean not at all. Treat cyber insurance as covering response costs and liability, and treat avoiding the fine as a compliance job, not an insurance one.
What do underwriters ask about AI risks on cyber renewals?
Expect questions on payment controls — particularly verification callbacks for new or changed bank details — alongside multi-factor authentication and staff phishing training, and increasingly on internal AI use: whether staff access to public AI tools is governed, and whether client or personal data can reach them.
Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This page is general information, not advice on a specific policy.
