AI creates two kinds of cyber risk for a company: attacks on its own AI systems, such as prompt injection and data poisoning, and attacks that use AI against it, such as a deepfake of an executive approving a payment. Which policy responds depends on the loss each attack causes rather than on the technique. As a rule, cyber insurance responds to breaches, data loss and damage to systems, crime or social engineering cover to money that staff are tricked into sending, and professional liability (E&O) or directors and officers (D&O) cover to claims that the company's AI failed its customers or that its leaders misled investors.
What Are the Main AI Cybersecurity Risks for a Company?
The main AI cybersecurity risks fall into two groups: attacks on a company's own models, assistants and agents, and attacks that use AI as a weapon, through convincing synthetic content or automated intrusions.
Both groups already appear in breach data: IBM's 2025 Cost of a Data Breach study found that 13% of organizations reported breaches of AI models or applications, that 97% of those lacked proper AI access controls and that 60% of the AI-related incidents led to compromised data.[1] A year later IBM reported that 1 in 4 malicious breaches were AI-enabled and that those breaches cost an average of $6 million, roughly $1 million more than the global average.[2] Attackers also use AI to run intrusions: on November 13th 2025 Anthropic reported that a group it assessed as Chinese state-sponsored had used Claude Code, Anthropic's own coding tool, to perform 80-90% of an espionage campaign against roughly 30 organizations.[3]
Defenses remain limited: NIST's taxonomy of adversarial machine learning, NIST AI 100-2 E2025 (March 2025), notes that the machine learning algorithms in wide use lack information-theoretic security proofs, meaning there is no formal guarantee that they resist attack, and that many mitigations are “empirical and limited in nature.”[4] Since no vendor can promise that its AI is immune to manipulation, it is best to assume some attacks will succeed and to decide in advance which contract, control or policy carries each kind of loss, beginning with the comparison of AI and cyber exposure in the AI risks overview.
Is Prompt Injection Covered by Cyber Insurance?
Cyber insurance is usually the policy that responds to a prompt injection attack that leaks data, but an attack that makes an AI product give a false answer or take an unauthorized action looks more like a failure of the company's service, which is a matter for professional liability (E&O) cover.
Definition
Prompt injection
Prompt injection is an attack in which instructions hidden in user input or in content an AI system reads cause the system to ignore its intended rules. It can lead an AI assistant to disclose data or take actions its operator never authorized.
The OWASP Top 10 for LLM (large language model) Applications ranks prompt injection first (LLM01) in its 2025 edition, listing effects from the “disclosure of sensitive information” to the manipulation of “critical decision-making processes.”[5] Instructions typed in by a user are called direct injection, and instructions hidden in a website, email or file the AI system reads are called indirect injection; NIST observes that in many such indirect attacks “it is the primary user of the model who is harmed.”[4]
In September 2025 researchers disclosed ForcedLeak, a critical flaw in Salesforce's Agentforce in which instructions hidden in an ordinary web-to-lead form could make the AI agent send CRM lead data to a domain the researchers had bought for $5, until Salesforce restricted the agent to trusted URLs.[6] The flaw sat in the vendor's product, but the data at risk belonged to its customers. Such attacks are spreading: Google reported on April 23rd 2026 that malicious indirect prompt injections on the public web rose by 32% in relative terms between November 2025 and February 2026, including attempts at data theft and commands designed to delete files.[7]
Even a data leak can be contested, because a cyber policy that defines a security failure by reference to the insured's own systems leaves room for argument when a vendor hosts the AI tool. An injected agent that gives a customer a false commitment or mishandles a customer's money can instead create a claim that the company's service failed, which is professional liability territory. It is best to treat any AI system that both reads outside content and takes actions as an exposure for both policies.
What Is Data Poisoning, and Which Policy Covers a Poisoned Model?
Data poisoning, which means tampering with the data a model learns from, tends to produce liability claims rather than cyber claims, because a poisoned model gives wrong or biased results that look like ordinary errors, often with no breach to point to.
Definition
Data poisoning
Data poisoning is an attack in which the data used to train, fine-tune or inform an AI model is manipulated so that the model learns hidden vulnerabilities, backdoors or biases. A poisoned model can behave normally until a trigger appears, which makes the damage hard to detect and hard to trace to an attack.
OWASP lists data and model poisoning as LLM04 in its 2025 edition,[8] and recent research suggests the attack needs less data than was once assumed. In a study published on October 9th 2025, Anthropic, the UK AI Security Institute and the Alan Turing Institute found that as few as 250 malicious documents could plant a backdoor in language models from 600 million to 13 billion parameters, regardless of model size.[9] The authors noted that the backdoor they tested only made a model produce gibberish, and that it was not yet clear whether the result holds for larger models or for more complex behaviors, such as backdooring code or bypassing safety guardrails.
The finding matters because most companies build on foundation models (large general-purpose models supplied by vendors) trained on data nobody fully controls; NIST notes that in most cases “no single entity controls all of the data used to train a particular foundation model.”[4] Other links in the AI supply chain are exposed too: in July 2025 a release of Amazon's Q Developer extension for Visual Studio Code shipped with a prompt, added by a hacker, instructing its AI agent to wipe systems and delete cloud resources, although AWS said the code would not run and no customer resources were affected.[10]
Claims that a model approved the wrong applications or screened out candidates unfairly fall to liability policies whether or not anyone can prove an intrusion, and those policies are now acquiring AI exclusions: by May 2025 W. R. Berkley had introduced an “absolute” AI exclusion for D&O, E&O and fiduciary liability that applies to claims “based upon, arising out of, or attributable to” any use, deployment or development of AI.[11] The recommended course of action is to check the AI wording in the E&O, D&O and EPL policies, using the guide to silent AI and AI exclusions, and to require AI vendors to explain where their training data comes from and how they test for tampering.
How Does Deepfake Fraud Target Companies?
Deepfake fraud uses synthetic video, voice or documents to impersonate someone a company trusts, often an executive approving a payment, and its typical loss is money sent to criminals rather than data taken from systems.
The best-documented case is the fraud against the engineering firm Arup. Hong Kong police said in February 2024 that a finance employee of a multinational firm in Hong Kong had made 15 transfers totaling HK$200 million after a video conference in which every participant except the victim, including the company's UK-based chief financial officer, was impersonated.[12] Arup later confirmed that “fake voices and images were used” and that “none of our internal systems were compromised,” and the loss was reported at about US$25.6 million.[13]
Regulators have noted the trend: FinCEN's alert FIN-2024-Alert004 of November 13th 2024 reported a rise since 2023 in suspicious activity reports describing the suspected use of deepfake media in fraud, often in fake identity documents, and noted that criminals have reportedly impersonated “an executive or other trusted employee” to instruct companies to transfer large sums.[14] The FBI's Internet Crime Complaint Center (IC3) recorded more than $3 billion in reported losses in 2025 from business email compromise (criminals posing as an executive or supplier to redirect payments), and businesses linked more than $30 million of that to schemes involving AI.[15]
Does Cyber Insurance Cover Deepfake Fraud?
Cyber insurance generally responds to deepfake payment fraud only if the policy adds social engineering or fraudulent instruction cover, because cyber cover is usually triggered by a security failure, while here an employee authorizes the payment and no system is breached. The loss therefore tends to fall to crime or social engineering cover, where the wording decides the outcome.
Courts have read similar crime wordings differently, particularly the computer fraud provision, which covers money lost through the fraudulent use of a computer. In an unpublished 2016 decision, the federal appeals court for the Fifth Circuit held that the oil producer Apache could not recover under that provision after paying about $7 million, much of it later recovered, to a fraudulent account following a spoofed vendor email; the court found that the email was “merely incidental to the occurrence of the authorized transfer of money.”[16] It also noted that an employee had confirmed the change by calling the telephone number on the fraudulent letterhead.
In a published decision of July 13th 2018, by contrast, the Sixth Circuit held that a Michigan tool and die maker's loss of about $834,000, wired in response to emails impersonating a vendor, was “directly caused” by computer fraud under its crime policy.[17] The result turns on the wording and the governing state law, so it is best not to count on a computer fraud clause to pay for a deepfake payment loss.
Social engineering cover exists to fill that gap, but it is often small: Aon noted in April 2026 that crime and cyber policies “frequently respond to social engineering or fraudulent instruction only via small sublimits that can be out of step with the dollar value of payments routinely processed.”[18] A loss of Arup's size would dwarf a small sublimit, so the sublimit should be tested against the company's largest payments, and changed payment instructions should be confirmed through contact details already on file.
Can an AI Cyber Incident Lead to a D&O Claim?
An AI cyber incident can lead to a D&O claim, because under rules the SEC adopted on July 26th 2023 a public company must disclose a material cybersecurity incident on Form 8-K, generally within 4 business days after determining that it is material.[19] As of this writing the requirement remains in force, although banking trade associations and other groups have asked the SEC to repeal it.[20] Securities plaintiffs are already focused on AI, with Cornerstone Research counting 15 AI-related securities class actions in the first half of 2026,[21] and an AI incident disclosed late or described inaccurately could give them grounds for a claim against directors and officers. The board should therefore confirm that AI incidents go through the same materiality and disclosure process as any other cyber incident.
Which Policy Responds to Each AI Cyber Event?
Each AI cyber event lands on the policy built for the loss it causes. In the table, “Usually” means the policy is built for that loss, subject to its wording and any AI exclusion; “Depends on wording” means it may respond to part of the loss; and “Rarely” means it is not designed for the loss. The table describes general market patterns, not the terms of any particular policy.
| AI cyber event | First-party cyber | Third-party cyber | Crime and social engineering | Technology E&O or AI-E&O | D&O and EPL |
|---|---|---|---|---|---|
| Prompt injection leaks customer or employee data | Usually | Usually | Rarely | Depends on wording | Rarely |
| Prompt injection makes an AI product or agent harm a customer | Depends on wording | Depends on wording | Rarely | Usually | Rarely |
| A poisoned or tampered model gives wrong or biased results | Depends on wording | Rarely | Rarely | Usually | Depends on wording |
| A compromised AI tool damages systems or data | Usually | Depends on wording | Rarely | Depends on wording | Rarely |
| A deepfake of an executive leads staff to send company funds | Depends on wording | Rarely | Usually | Rarely | Rarely |
| Investors sue over an AI incident or its disclosure | Rarely | Rarely | Rarely | Rarely | Usually |
The cyber and crime columns carry the company's own losses, such as forensics, restoration and stolen funds, while the liability columns carry claims by customers, employees and investors. A single attack can trigger both, so the retentions (the share of a loss the company pays itself) and the other-insurance clauses (which decide how two policies share a loss) should be read together. The liability cells marked “Usually” are also the ones exposed to new AI exclusions, which makes them the likeliest place for a gap and the first wordings to check; the guide to AI liability insurance and cyber insurance sets out where the two lines meet.
Where Does AI Liability Coverage Fit?
Affirmative AI liability coverage, which addresses AI risk expressly instead of leaving a policy silent on it, is written for the liability columns of the table above. Mayflower Specialty writes it as three modules and an excess layer:
- AI Professional Liability (AI-E&O) is written for claims that a company's AI-enabled products or services caused a customer or client a loss.
- AI Directors and Officers Liability (AI-D&O) is written for claims over AI oversight and AI-related statements.
- AI Employment Practices Liability (AI-EPL) is written for employment claims involving AI.
- AI DIC Excess is a difference-in-conditions layer over an existing D&O, EPL and E&O program, written to respond to AI claims those policies are silent on or exclude.
Coverage is written on a claims made and reported basis on A- (Excellent) AM Best rated paper backed by global reinsurers, placed through brokers and underwritten on the applicant's AI governance. The modules sit beside cyber and crime insurance rather than replacing them. Whether one responds to a claim that began with a security event depends on the wording, so it is a good idea to have the broker review the liability, cyber and crime wordings side by side.
What Security Controls Do Insurers Ask About for AI?
Underwriters ask about the controls that limit what an attacker can make an AI system do, because those controls decide whether an attack becomes a large claim. They fall into five areas:
- Access limits: AI tools should reach only the data and functions their task requires, given that IBM found 97% of organizations reporting AI breaches lacked proper AI access controls.[1]
- Input and output checks: outside content such as web pages, emails and form submissions should be treated as untrusted, and payments or other consequential actions should need human approval.
- Red-teaming: people should try to break models and agents with prompt injection and tampering before launch and after significant changes, keeping the results as evidence.
- Vendor attestations: AI vendors should state in writing where their training data and model components come from and how quickly they will report a compromise.
- Payment verification: changed payment instructions should be confirmed through details already on file, and FinCEN points to multifactor authentication and live verification checks as practices that may help reduce vulnerability to deepfake identity documents.[14]
Mayflower's application asks about several of these controls in its sections on AI systems, governance, data governance and incident response. The questions include guardrails such as input validation and red-team testing, approval gates for agents that can transact, vendor security attestations, training data provenance and the capability to respond to prompt injection and data poisoning, while payment verification remains a question for the crime or cyber underwriter. It is worth gathering evidence of these controls before applying, and the guide to how underwriters assess AI risk explains what each section looks for.
What Should a Company Do About AI Cyber Risk?
It is best to treat AI cyber risk as a question for the whole insurance program rather than for the cyber policy alone, and to work through it in four steps:
- Inventory every AI system that reads outside content, takes actions or relies on a third-party model, and map each one to the rows of the table above.
- Ask the cyber insurer to confirm in writing how the policy treats a prompt injection attack on an AI tool the company uses, including one a vendor hosts.
- Test the social engineering sublimit against the largest routine payments, and confirm any verification condition the policy imposes.
- Read the E&O, D&O and EPL wordings for AI exclusions, and close any gap with affirmative AI coverage or a DIC layer before the next renewal.
The coverage gap check is a short way to start, after which a company or its broker can begin an application for AI-E&O, AI-D&O or AI DIC Excess, or talk to Mayflower about how the modules would sit beside its cyber and crime cover.
Frequently Asked Questions
Does cyber insurance cover deepfake fraud?
Does crime insurance cover deepfake CEO fraud?
Is prompt injection covered by cyber insurance?
Who is liable if a company's chatbot is manipulated into leaking data?
What is data poisoning in AI?
Does insurance cover losses caused by a poisoned AI model?
Sources
- [1]IBM Report: 13% of Organizations Reported Breaches of AI Models or Applications, 97% of Which Reported Lacking Proper AI Access Controls, IBM, July 30th 2025
- [2]IBM Study: One in Four Malicious Breaches are AI-Enabled, Costing Companies $6 Million on Average, IBM, July 29th 2026
- [3]Disrupting an AI-orchestrated cyber espionage campaign, Anthropic, November 13th 2025
- [4]NIST AI 100-2 E2025, Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (March 2025), National Institute of Standards and Technology
- [5]OWASP Top 10 for LLM Applications 2025: LLM01 Prompt Injection, OWASP Gen AI Security Project
- [6]Salesforce Agentforce tricked into leaking sales leads (ForcedLeak), The Register, September 26th 2025
- [7]AI threats in the wild: The current state of prompt injections on the web, Google, April 23rd 2026
- [8]OWASP Top 10 for LLM Applications 2025: LLM04 Data and Model Poisoning, OWASP Gen AI Security Project
- [9]A small number of samples can poison LLMs, Anthropic, October 9th 2025
- [10]Amazon AI coding agent hacked to inject data wiping commands, BleepingComputer, July 25th 2025
- [11]The Continued Proliferation of AI Exclusions, Hunton Andrews Kurth, May 28th 2025
- [12]Multinational loses HK$200 million to deepfake video scam, Hong Kong Free Press, February 5th 2024
- [13]A deepfake ‘CFO’ tricked British design firm Arup in $25 million fraud, Fortune, May 17th 2024
- [14]FinCEN Alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions (FIN-2024-Alert004), Financial Crimes Enforcement Network, U.S. Department of the Treasury, November 13th 2024
- [15]2025 IC3 Annual Report, Federal Bureau of Investigation, Internet Crime Complaint Center
- [16]Apache Corp. v. Great American Insurance Co., No. 15-20499 (5th Cir.) (unpublished), U.S. Court of Appeals for the Fifth Circuit, October 18th 2016
- [17]American Tooling Center, Inc. v. Travelers Casualty & Surety Co. of America, No. 17-2014 (6th Cir.), U.S. Court of Appeals for the Sixth Circuit, July 13th 2018
- [18]From Phishing to Deepfakes: Social Engineering Risks Are Intensifying for Professional Service Firms (April 2026), Aon
- [19]SEC Adopts Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure by Public Companies, U.S. Securities and Exchange Commission, July 26th 2023
- [20]Cybersecurity Incident Disclosure: Form 8-K Tracker (Two-Year Update), Debevoise & Plimpton, May 21st 2026
- [21]Securities Class Action Filings Surge in the First Half of 2026, Cornerstone Research, July 29th 2026
