Beazley has introduced an AI Clarifying Endorsement that confirms AI-driven cyber attacks fall within its existing full spectrum cyber cover. The endorsement closes one specific gap - attacker-side AI use - but deliberately leaves unaddressed whether a client's own deployment of AI tools is covered, a question the cyber insurance market continues to answer inconsistently.
Most cyber policies written before this year handled AI-related losses by omission. AI wasn't excluded, and it wasn't explicitly included. Whether a claim involving an AI-driven attack would be paid came down to how a specific incident was argued at the point of loss. That ambiguity has a name in the market: silent AI, a direct echo of the silent cyber problem insurers spent the previous decade trying to eliminate.
The Insurance Services Office introduced three generative-AI exclusion endorsements for commercial general liability policies effective January 1, and cyber carriers have been responding with their own AI-specific language ever since. Some are excluding. Some are capping. Beazley's move is to affirm coverage for one defined category of risk.
The endorsement lands months after discussions of AI sub-limits
The announcement arrives months after Financial Times reporting named Beazley as one of the carriers drafting policy language to cap, not expand, AI-related payouts, specifically for losses tied to regulatory breaches. Sub-limits were reportedly discussed at roughly 10% of overall policy value. A Beazley spokesperson told the FT at the time that the carrier had "not reduced coverage for AI cyber risk and are not planning to." Whether the Clarifying Endorsement supersedes, coexists with, or is unrelated to those earlier discussions is not addressed.
Set against that backdrop, the endorsement's stated purpose is narrower than "AI coverage" as a whole. It addresses AI-driven cyber attacks, meaning incidents where AI is the tool an attacker uses to compromise systems already covered by the policy, such as autonomous phishing or accelerated intrusion attempts. That's a meaningfully different question from whether a client's own use of AI - in a chatbot, an internal model, or an AI vendor's tool - creates liability exposure if that AI causes harm or a data incident. A client asking "are we covered for AI" is usually asking about the second question, while this endorsement answers the first.
What the wording does and doesn't settle
Clarity on attacker-side AI risk is a genuine gap that's existed since large language models became capable enough to run reconnaissance and phishing at scale. Naming that exposure explicitly removes one point of dispute at claims time. It does not, however, settle the broader question the market is currently split on: whether the insured's own AI use is affirmed, excluded, or sub-limited elsewhere in the same policy.
Carriers have been drafting AI wording differently enough over the past year that identical-sounding endorsement names can carry different scope from one policy to the next. Brokers need to read the actual wording rather than relying on the endorsement's name or the carrier's press release. The two categories of AI risk - attacker-side and insured-side - are often conflated in AI insurance conversations, and this endorsement addresses only one.
Why this matters for brokers and underwriters
For brokers, the endorsement removes ambiguity on one front but creates a verification task on another. A client who hears "Beazley affirms AI coverage" may assume their own chatbot or internal model is covered. It falls to the broker to check whether the policy's other terms affirm, exclude, or sub-limit that exposure. For underwriters, the endorsement signals that carrier language is fragmenting faster than standardisation efforts can keep pace. Professionals who need to stay current on how AI risk is being carved into cyber policies can find structured guidance through AI for Insurance Courses, which address exactly this kind of coverage analysis.
Your membership also unlocks: