Cyber insurance premiums are falling, but the coverage gap for AI-related risks is widening faster than most policies can keep up. Deepfake fraud, algorithmic failures, and cloud outages are producing claims that traditional cyber policy language was never drafted to handle.
Ed Chadwick, AVP and professional lines lead broker at Jencap, says most organizations are underinsured against the very threats that are now driving losses. Synthetic voice attacks on insurance companies rose 475% in 2024, according to Pindrop's 2025 Voice Intelligence and Security Report.
Carriers are adapting, but gaps remain
Cyber claims are no longer just system failures and ransomware. AI has moved risk into territory that standard policy forms were not designed to cover.
"AI has shifted claims from traditional IT failures to more algorithmic risks in general," Chadwick said. "Combine that with increasingly convincing deepfake crimes, and losses have begun to increase in both frequency and complexity."
Carriers have responded, though unevenly. "As an industry, we are keeping up overall on a coverage front," Chadwick said. Several reputable carriers now offer affirmative AI coverage, which names AI-related incidents as covered events explicitly rather than leaving that coverage assumed under legacy language.
Chadwick cautions that soft rates should not be mistaken for better coverage. Excess market capacity is keeping premiums down independently of what policies actually cover. "Many carriers are digging deeper into security controls such as phishing-resistant MFA and out-of-band authentication requirements," he said.
The gap most cyber programs miss
AI has made a structural hole in most programs more urgent. Most cyber policies respond to breaches of your own systems, not failures at the third-party providers your operations depend on.
"For me, the biggest issue is the increased 'single point' threat that is inherent to AI and its use," Chadwick said. "This is why contingent business interruption is one of the biggest gaps that I come across in existing risk management portfolios."
That coverage pays for lost income when a third-party system collapses, not just when your own is breached. The July 2024 CrowdStrike outage illustrates the consequences: Fortune 500 companies lost $5.4 billion from the outage, yet cyber insurance covered only 10 to 20 percent of that, according to Parametrix.
"Risk managers would be wise to focus attention here to make sure their cyber policies can respond to a large-scale cloud outage," Chadwick said.
Carriers have tools. Do you?
Carriers are moving beyond reactive underwriting. "Modern cyber insurance and carriers are no longer 'reactive' in nature," Chadwick said. "They're deploying proactive tools to help defend policyholders from AI-driven threats. Key areas here are continuous machine-speed risk monitoring that can detect abnormal behavior and vulnerabilities faster and, critically, more accurately."
Carriers are also deploying AI-driven deepfake detection tools to counter social engineering attacks. The internal work is just as urgent. Organizations with tested incident response plans save an average of $2.66 million per breach, according to IBM's 2025 Cost of a Data Breach Report.
Chadwick says the same discipline applies to policy language as to response plans. "If there's been no language changes to a policy in several years, you're likely falling behind in the marketplace," he said. "A plan that was built and last tested in 2021 will create confusion and frustration if needed today."
All cyber professionals - not just underwriters - should expect AI to degrade the value of old policy forms. For AI for Insurance professionals, the takeaway is to review every policy renewal for three specific gaps: affirmative AI coverage wording, contingent business interruption triggers, and trust in third-party cloud dependencies.
Risk managers in particular should pressure-test their incident response plans against deepfake and algorithmic failure scenarios, not just ransomware. The shortest path to recovering losses after an AI-driven event is a plan that actually covers the event in writing. For deeper technical detail, AI for Cybersecurity Analysts covers defense-in-depth monitoring and detection techniques against these threats.
Your membership also unlocks: