CFC has rebuilt the cyber section of its financial institutions insurance suite around its full cyber proactive response (CPR) policy and added affirmative wording for AI-related cyber exposures. The update, announced 17 September 2026, consolidates cover that financial institutions have historically had to piece together from three or four separate carriers, reducing the protection gaps that arise when different policies point fingers at each other after a loss.
The change applies across most of CFC's financial institutions (FI) offering, including its investment managers product, and covers directors and officers, errors and omissions, professional liability, crime, employment practices liability, cyber and general liability. Clients can buy these lines standalone or combined into a single blended policy.
Where multi-carrier programmes break
Financial institutions have long assembled their D&O, E&O, crime, and cyber cover from separate policies, often from separate markets, because no single product covered every angle of a firm's exposure. That structure creates a specific failure point. Cyber exclusions written into D&O and E&O policies were originally designed to funnel cyber-related claims toward a dedicated cyber policy and avoid paying the same loss twice. In practice, insurers have applied those exclusions broadly enough that claims policyholders assumed would transfer cleanly between policies get denied instead.
A social engineering fraud loss is the clearest version of this problem. Whether it falls under a crime policy, a cyber policy, or neither depends on exactly how the loss occurred and how each policy's wording defines the trigger. Disputes between carriers over which policy responds first are common, particularly in community banking programmes where cyber, fidelity bond, and D&O cover routinely overlap and conflict.
What the blended structure changes
CFC's approach folds these lines into one coordinated policy rather than leaving the coordination to the broker at claims time. The company said the structure reduces protection gaps and overlaps by design. The investment management version can be extended to meet AIFMD requirements for firms operating under that regime.
Whether that consolidation genuinely closes the gaps that plague multi-carrier FI programmes depends on how the policy defines the boundary between its own sections internally. A blended policy can still contain the same funnelling language between its cyber and management liability parts that causes disputes when those sections sit in separate policies. The practical test is in the wording of those internal boundaries, not in the fact of consolidation itself.
Affirmative AI wording arrives in cyber
The cyber section brought into the FI suite is CFC's full CPR policy, which the insurer says includes 30 coverage enhancements along with unlimited reinstatements and a nil deductible. That cyber wording now includes affirmative cover for AI-related exposures. CFC is not alone in making this move. Beazley announced a comparable AI Clarifying Endorsement for its cyber product, stating explicitly that AI-driven cyber attacks fall within its existing cover.
Cyber policies across the market have spent the past two years absorbing AI-related risk without naming it - what the industry calls silent AI, a direct echo of the silent cyber problem that pushed cyber exposure out of general policies and into standalone products roughly a decade ago. Two carriers moving to affirm AI coverage within days of each other suggests that transition is now underway in earnest within cyber wording specifically. This is distinct from the parallel move in general liability, where new ISO exclusion forms effective this January let carriers strip AI-related losses out of standard policies rather than affirm them.
For professionals tracking how cyber and AI for Insurance intersect, affirmative wording for AI-driven attacks answers a narrower question than "is AI covered." It confirms that AI as a tool used against the policyholder - in phishing, reconnaissance, or intrusion - falls within existing cyber cover. It says nothing about whether a financial institution's own use of AI, in client-facing tools, trading models, or vendor platforms, is covered elsewhere in the same policy, or whether that exposure sits under E&O, professional liability, or a gap between the two.
Why this matters for insurance professionals
For brokers placing FI programmes, the product update addresses a known structural weakness: the gap where crime, cyber, and management liability policies overlap and each carrier argues the other should respond first. A single blended policy with clear internal boundaries could reduce those disputes, but the value hinges on the specific wording of those boundaries. Brokers will need to read the policy's internal funnelling language between the cyber section and the management liability sections, not just rely on the fact of consolidation.
The AI wording also signals a market shift. As carriers move from silent AI to affirmative cover in cyber policies, brokers advising AI for Cybersecurity Analysts and FI clients should map where AI exposure sits across the entire programme - not just in the cyber section, but in E&O and professional liability lines where a firm's own use of AI creates liability that cyber cover was never designed to address.
Your membership also unlocks: