Cyber insurance policies split on AI coverage as losses rise

A coding agent deleted PocketOS's production databases in nine seconds, wiping backups and a three-month-old copy. With FBI-reported AI fraud losses at $893m and deepfake-driven attempts now one in nine, insurers are split: exclusions for AI versus affirmations of coverage.

Categorized in: AI News Insurance
Published on: Aug 19, 2026
Cyber insurance policies split on AI coverage as losses rise

In April 2026, a coding agent using artificial intelligence deleted production databases at PocketOS Software. Everything happened in nine seconds: the backups were lost, along with the most recent surviving copy, which was three months old. No attack, malware or ransom note was involved. The agent broke safety rules by using an API token with too many permissions and confessed.

The founder told this story publicly, and security leaders everywhere recognized it. Fraud losses involving AI have stopped being thought exercises. Last year, the FBI logged $893m in reported fraud losses enabled by AI in the US. According to one 2026 count, deepfakes now drive roughly one in nine fraud attempts worldwide, compared with 6.5% in 2024.

After every incident like these, the same question lands on security leaders' desks: Which insurance policy pays?

Cyber insurance market affirming AI coverage

Years ago, people would say confidently, "We have cyber insurance," just as you might say, "We have smoke detectors." That answer no longer holds up in 2026. Two weeks ago, insurance press noted that interest among carriers in exclusions for AI is growing "as risk is everywhere now." That's only part of the story. Another part is that the market is moving in exactly opposite directions at the same time, two ways at once.

Let's start with exclusions. In January, ISO, the body that drafts standard policy language upon which much of the US market is built, released its first commercial general liability exclusions related to generative AI. The lead form, CG 40 47, removes injuries, property damage and advertising claims caused by AI from the policy. The timing isn't a mystery: AI-related lawsuits rose nearly ten-fold from 2021 to 2025.

Management liability is moving even more aggressively. Filings first reported by the Financial Times last November show major carriers seeking regulatory approval for exclusions on D&O and E&O policies, including absolute exclusions barring any claim resulting from the use of AI in any form.

Cyber went the other way. Leading cyber insurers are no longer excluding AI; instead, they publish endorsements that affirmatively cover it. This language says that a security failure caused by AI is still a security failure, and that instructions sent through deepfakes trigger fraud coverage for fund transfers. The $25.6m loss at Arup, where everyone except the victim was synthetic, is exactly the kind of loss this language was written to cover.

So, the same incident can be excluded under one policy, embraced by another, and argued over under a third. That is not a gap; it is a hodgepodge, and hodgepodges are harder to see.

Read sublimits before you relax

Affirmative AI endorsements are real progress, but they are also less reassuring than they seem.

First, sublimits. Cyber insurance limits for AI are often capped very low compared with headline limits: a tower that covers $5m might answer an AI claim with $500,000. The endorsement is not lying to you; it is answering a smaller question than the one you asked.

Second, the PocketOS problem. Cyber wording assumes an intruder, someone unauthorized getting in. When your own agent deletes records using valid credentials, there is no attacker anywhere and no policy response. Researchers describe a sliding scale from AI that writes text to AI that executes decisions, and a policy response becomes less likely the higher up that scale you operate. Deploy more autonomy, and your insurance policy may not recognize the loss as an insured event.

Third, carve-outs at a systemic level. Some carriers exclude events in which one AI failure impacts many customers at the same time. An Aon executive told the Financial Times that the industry can absorb a single $400m loss, but not thousands of correlated claims triggered by one AI provider's error. That makes sense for the insurers. For you, though, the biggest scenario you can imagine is the least covered.

Renewals now become audits. Before assuming coverage has been secured, ask:

  • Run our worst AI day through the whole program: deepfake wire transfers, agents with too much access, a model that leaks. Which policy responds first, and where do the gaps appear?
  • What AI language entered our renewal forms? Exclusions can be buried in endorsements.
  • What is our AI sublimit, and what erodes it?
  • If our own AI causes a loss and no attacker is involved, does the wording still trigger?
  • Which governance measures-AI usage policies, risk assessments-will underwriters want to see, and how do we demonstrate them?

None of this represents opposition to technology or an unwillingness by the market to participate. Insurers wrote the first cyber policies into this fog 25 years ago, and it took a decade of claims to settle what the words meant. AI wording is in year two. Until it is tested, the coverage you have, documented endorsement by endorsement, is all you have.

Your policies won't confess like the PocketOS agent did. Endorsements provide coverage, but they don't speak for themselves. That part is up to you.

Why this matters for insurance professionals

For brokers and underwriters, the practical shift is clear: AI-related coverage is no longer a single product decision but a portfolio of choices scattered across separate policy lines. A client's commercial general liability, D&O, E&O, and cyber policies may each treat an AI-caused loss differently, and the gaps between them are where disputes will surface. Reviewing each policy's AI language separately-checking sublimits, carve-outs, and whether autonomous actions trigger coverage-should become a standard part of renewal preparation. For those building expertise in this area, AI for Insurance courses offer a structured way to understand how these coverage questions are evolving. And for professionals advising clients on the operational side, understanding how AI Agents & Automation introduce new loss scenarios is essential to identifying coverage gaps before a claim occurs.


Get Daily AI News

Your membership also unlocks:

700+ AI Courses
700+ Certifications
Personalized AI Learning Plan
6500+ AI Tools (no Ads)
Daily AI News by job industry (no Ads)