Skip to content
MAYFLOWER SPECIALTYMayflower Specialty

Risk

Prompt Injection, Data Poisoning and Deepfake Fraud: Which Policy Responds

Updated 12 minute readBy Mayflower Specialty

AI creates two kinds of cyber risk for a company: attacks on its own AI systems, such as prompt injection and data poisoning, and attacks that use AI against it, such as a deepfake of an executive approving a payment. Which policy responds depends on the loss each attack causes rather than on the technique. As a rule, cyber insurance responds to breaches, data loss and damage to systems, crime or social engineering cover to money that staff are tricked into sending, and professional liability (E&O) or directors and officers (D&O) cover to claims that the company's AI failed its customers or that its leaders misled investors.

What Are the Main AI Cybersecurity Risks for a Company?

The main AI cybersecurity risks fall into two groups: attacks on a company's own models, assistants and agents, and attacks that use AI as a weapon, through convincing synthetic content or automated intrusions.

Both groups already appear in breach data: IBM's 2025 Cost of a Data Breach study found that 13% of organizations reported breaches of AI models or applications, that 97% of those lacked proper AI access controls and that 60% of the AI-related incidents led to compromised data.[1] A year later IBM reported that 1 in 4 malicious breaches were AI-enabled and that those breaches cost an average of $6 million, roughly $1 million more than the global average.[2] Attackers also use AI to run intrusions: on November 13th 2025 Anthropic reported that a group it assessed as Chinese state-sponsored had used Claude Code, Anthropic's own coding tool, to perform 80-90% of an espionage campaign against roughly 30 organizations.[3]

Defenses remain limited: NIST's taxonomy of adversarial machine learning, NIST AI 100-2 E2025 (March 2025), notes that the machine learning algorithms in wide use lack information-theoretic security proofs, meaning there is no formal guarantee that they resist attack, and that many mitigations are “empirical and limited in nature.”[4] Since no vendor can promise that its AI is immune to manipulation, it is best to assume some attacks will succeed and to decide in advance which contract, control or policy carries each kind of loss, beginning with the comparison of AI and cyber exposure in the AI risks overview.

Is Prompt Injection Covered by Cyber Insurance?

Cyber insurance is usually the policy that responds to a prompt injection attack that leaks data, but an attack that makes an AI product give a false answer or take an unauthorized action looks more like a failure of the company's service, which is a matter for professional liability (E&O) cover.

Definition

Prompt injection

Prompt injection is an attack in which instructions hidden in user input or in content an AI system reads cause the system to ignore its intended rules. It can lead an AI assistant to disclose data or take actions its operator never authorized.

The OWASP Top 10 for LLM (large language model) Applications ranks prompt injection first (LLM01) in its 2025 edition, listing effects from the “disclosure of sensitive information” to the manipulation of “critical decision-making processes.”[5] Instructions typed in by a user are called direct injection, and instructions hidden in a website, email or file the AI system reads are called indirect injection; NIST observes that in many such indirect attacks “it is the primary user of the model who is harmed.”[4]

In September 2025 researchers disclosed ForcedLeak, a critical flaw in Salesforce's Agentforce in which instructions hidden in an ordinary web-to-lead form could make the AI agent send CRM lead data to a domain the researchers had bought for $5, until Salesforce restricted the agent to trusted URLs.[6] The flaw sat in the vendor's product, but the data at risk belonged to its customers. Such attacks are spreading: Google reported on April 23rd 2026 that malicious indirect prompt injections on the public web rose by 32% in relative terms between November 2025 and February 2026, including attempts at data theft and commands designed to delete files.[7]

Even a data leak can be contested, because a cyber policy that defines a security failure by reference to the insured's own systems leaves room for argument when a vendor hosts the AI tool. An injected agent that gives a customer a false commitment or mishandles a customer's money can instead create a claim that the company's service failed, which is professional liability territory. It is best to treat any AI system that both reads outside content and takes actions as an exposure for both policies.

What Is Data Poisoning, and Which Policy Covers a Poisoned Model?

Data poisoning, which means tampering with the data a model learns from, tends to produce liability claims rather than cyber claims, because a poisoned model gives wrong or biased results that look like ordinary errors, often with no breach to point to.

Definition

Data poisoning

Data poisoning is an attack in which the data used to train, fine-tune or inform an AI model is manipulated so that the model learns hidden vulnerabilities, backdoors or biases. A poisoned model can behave normally until a trigger appears, which makes the damage hard to detect and hard to trace to an attack.

OWASP lists data and model poisoning as LLM04 in its 2025 edition,[8] and recent research suggests the attack needs less data than was once assumed. In a study published on October 9th 2025, Anthropic, the UK AI Security Institute and the Alan Turing Institute found that as few as 250 malicious documents could plant a backdoor in language models from 600 million to 13 billion parameters, regardless of model size.[9] The authors noted that the backdoor they tested only made a model produce gibberish, and that it was not yet clear whether the result holds for larger models or for more complex behaviors, such as backdooring code or bypassing safety guardrails.

The finding matters because most companies build on foundation models (large general-purpose models supplied by vendors) trained on data nobody fully controls; NIST notes that in most cases “no single entity controls all of the data used to train a particular foundation model.”[4] Other links in the AI supply chain are exposed too: in July 2025 a release of Amazon's Q Developer extension for Visual Studio Code shipped with a prompt, added by a hacker, instructing its AI agent to wipe systems and delete cloud resources, although AWS said the code would not run and no customer resources were affected.[10]

Claims that a model approved the wrong applications or screened out candidates unfairly fall to liability policies whether or not anyone can prove an intrusion, and those policies are now acquiring AI exclusions: by May 2025 W. R. Berkley had introduced an “absolute” AI exclusion for D&O, E&O and fiduciary liability that applies to claims “based upon, arising out of, or attributable to” any use, deployment or development of AI.[11] The recommended course of action is to check the AI wording in the E&O, D&O and EPL policies, using the guide to silent AI and AI exclusions, and to require AI vendors to explain where their training data comes from and how they test for tampering.

How Does Deepfake Fraud Target Companies?

Deepfake fraud uses synthetic video, voice or documents to impersonate someone a company trusts, often an executive approving a payment, and its typical loss is money sent to criminals rather than data taken from systems.

The best-documented case is the fraud against the engineering firm Arup. Hong Kong police said in February 2024 that a finance employee of a multinational firm in Hong Kong had made 15 transfers totaling HK$200 million after a video conference in which every participant except the victim, including the company's UK-based chief financial officer, was impersonated.[12] Arup later confirmed that “fake voices and images were used” and that “none of our internal systems were compromised,” and the loss was reported at about US$25.6 million.[13]

Regulators have noted the trend: FinCEN's alert FIN-2024-Alert004 of November 13th 2024 reported a rise since 2023 in suspicious activity reports describing the suspected use of deepfake media in fraud, often in fake identity documents, and noted that criminals have reportedly impersonated “an executive or other trusted employee” to instruct companies to transfer large sums.[14] The FBI's Internet Crime Complaint Center (IC3) recorded more than $3 billion in reported losses in 2025 from business email compromise (criminals posing as an executive or supplier to redirect payments), and businesses linked more than $30 million of that to schemes involving AI.[15]

Does Cyber Insurance Cover Deepfake Fraud?

Cyber insurance generally responds to deepfake payment fraud only if the policy adds social engineering or fraudulent instruction cover, because cyber cover is usually triggered by a security failure, while here an employee authorizes the payment and no system is breached. The loss therefore tends to fall to crime or social engineering cover, where the wording decides the outcome.

Courts have read similar crime wordings differently, particularly the computer fraud provision, which covers money lost through the fraudulent use of a computer. In an unpublished 2016 decision, the federal appeals court for the Fifth Circuit held that the oil producer Apache could not recover under that provision after paying about $7 million, much of it later recovered, to a fraudulent account following a spoofed vendor email; the court found that the email was “merely incidental to the occurrence of the authorized transfer of money.”[16] It also noted that an employee had confirmed the change by calling the telephone number on the fraudulent letterhead.

In a published decision of July 13th 2018, by contrast, the Sixth Circuit held that a Michigan tool and die maker's loss of about $834,000, wired in response to emails impersonating a vendor, was “directly caused” by computer fraud under its crime policy.[17] The result turns on the wording and the governing state law, so it is best not to count on a computer fraud clause to pay for a deepfake payment loss.

Social engineering cover exists to fill that gap, but it is often small: Aon noted in April 2026 that crime and cyber policies “frequently respond to social engineering or fraudulent instruction only via small sublimits that can be out of step with the dollar value of payments routinely processed.”[18] A loss of Arup's size would dwarf a small sublimit, so the sublimit should be tested against the company's largest payments, and changed payment instructions should be confirmed through contact details already on file.

Can an AI Cyber Incident Lead to a D&O Claim?

An AI cyber incident can lead to a D&O claim, because under rules the SEC adopted on July 26th 2023 a public company must disclose a material cybersecurity incident on Form 8-K, generally within 4 business days after determining that it is material.[19] As of this writing the requirement remains in force, although banking trade associations and other groups have asked the SEC to repeal it.[20] Securities plaintiffs are already focused on AI, with Cornerstone Research counting 15 AI-related securities class actions in the first half of 2026,[21] and an AI incident disclosed late or described inaccurately could give them grounds for a claim against directors and officers. The board should therefore confirm that AI incidents go through the same materiality and disclosure process as any other cyber incident.

Which Policy Responds to Each AI Cyber Event?

Each AI cyber event lands on the policy built for the loss it causes. In the table, “Usually” means the policy is built for that loss, subject to its wording and any AI exclusion; “Depends on wording” means it may respond to part of the loss; and “Rarely” means it is not designed for the loss. The table describes general market patterns, not the terms of any particular policy.

AI cyber eventFirst-party cyberThird-party cyberCrime and social engineeringTechnology E&O or AI-E&OD&O and EPL
Prompt injection leaks customer or employee dataUsuallyUsuallyRarelyDepends on wordingRarely
Prompt injection makes an AI product or agent harm a customerDepends on wordingDepends on wordingRarelyUsuallyRarely
A poisoned or tampered model gives wrong or biased resultsDepends on wordingRarelyRarelyUsuallyDepends on wording
A compromised AI tool damages systems or dataUsuallyDepends on wordingRarelyDepends on wordingRarely
A deepfake of an executive leads staff to send company fundsDepends on wordingRarelyUsuallyRarelyRarely
Investors sue over an AI incident or its disclosureRarelyRarelyRarelyRarelyUsually

The cyber and crime columns carry the company's own losses, such as forensics, restoration and stolen funds, while the liability columns carry claims by customers, employees and investors. A single attack can trigger both, so the retentions (the share of a loss the company pays itself) and the other-insurance clauses (which decide how two policies share a loss) should be read together. The liability cells marked “Usually” are also the ones exposed to new AI exclusions, which makes them the likeliest place for a gap and the first wordings to check; the guide to AI liability insurance and cyber insurance sets out where the two lines meet.

Where Does AI Liability Coverage Fit?

Affirmative AI liability coverage, which addresses AI risk expressly instead of leaving a policy silent on it, is written for the liability columns of the table above. Mayflower Specialty writes it as three modules and an excess layer:

Coverage is written on a claims made and reported basis on A- (Excellent) AM Best rated paper backed by global reinsurers, placed through brokers and underwritten on the applicant's AI governance. The modules sit beside cyber and crime insurance rather than replacing them. Whether one responds to a claim that began with a security event depends on the wording, so it is a good idea to have the broker review the liability, cyber and crime wordings side by side.

What Security Controls Do Insurers Ask About for AI?

Underwriters ask about the controls that limit what an attacker can make an AI system do, because those controls decide whether an attack becomes a large claim. They fall into five areas:

  1. Access limits: AI tools should reach only the data and functions their task requires, given that IBM found 97% of organizations reporting AI breaches lacked proper AI access controls.[1]
  2. Input and output checks: outside content such as web pages, emails and form submissions should be treated as untrusted, and payments or other consequential actions should need human approval.
  3. Red-teaming: people should try to break models and agents with prompt injection and tampering before launch and after significant changes, keeping the results as evidence.
  4. Vendor attestations: AI vendors should state in writing where their training data and model components come from and how quickly they will report a compromise.
  5. Payment verification: changed payment instructions should be confirmed through details already on file, and FinCEN points to multifactor authentication and live verification checks as practices that may help reduce vulnerability to deepfake identity documents.[14]

Mayflower's application asks about several of these controls in its sections on AI systems, governance, data governance and incident response. The questions include guardrails such as input validation and red-team testing, approval gates for agents that can transact, vendor security attestations, training data provenance and the capability to respond to prompt injection and data poisoning, while payment verification remains a question for the crime or cyber underwriter. It is worth gathering evidence of these controls before applying, and the guide to how underwriters assess AI risk explains what each section looks for.

What Should a Company Do About AI Cyber Risk?

It is best to treat AI cyber risk as a question for the whole insurance program rather than for the cyber policy alone, and to work through it in four steps:

  1. Inventory every AI system that reads outside content, takes actions or relies on a third-party model, and map each one to the rows of the table above.
  2. Ask the cyber insurer to confirm in writing how the policy treats a prompt injection attack on an AI tool the company uses, including one a vendor hosts.
  3. Test the social engineering sublimit against the largest routine payments, and confirm any verification condition the policy imposes.
  4. Read the E&O, D&O and EPL wordings for AI exclusions, and close any gap with affirmative AI coverage or a DIC layer before the next renewal.

The coverage gap check is a short way to start, after which a company or its broker can begin an application for AI-E&O, AI-D&O or AI DIC Excess, or talk to Mayflower about how the modules would sit beside its cyber and crime cover.

Frequently Asked Questions

Does cyber insurance cover deepfake fraud?

Cyber insurance generally covers deepfake payment fraud only if the policy adds social engineering or fraudulent instruction cover, because an employee is deceived into authorizing the payment and no system is breached, so the loss more often falls to crime insurance. Both policies often limit this cover to a small sublimit, and some add conditions on verifying payment instructions, so each should be checked against the largest payments the company routinely makes.

Does crime insurance cover deepfake CEO fraud?

Crime insurance is the usual home for deepfake CEO fraud, but the result depends on the wording. Federal appeals courts have reached different results on whether a computer fraud clause covers payments an employee made after being deceived by impersonation, so the clearer route is social engineering or fraudulent instruction cover. That cover often carries a small sublimit, which should be tested against the largest payments the company routinely makes.

Is prompt injection covered by cyber insurance?

Cyber insurance usually responds when a prompt injection attack exposes personal or confidential data, because that is a privacy event of the kind the policy is built for. An attack that makes a company's AI product or agent give a customer a false commitment or take an unauthorized action produces a claim that the service failed, which falls to professional liability (E&O) cover, subject to its wording and any AI exclusion.

Who is liable if a company's chatbot is manipulated into leaking data?

The company that deployed the chatbot is usually the party customers and regulators look to, because it chose the tool and controls the data the chatbot can reach. It may be able to recover some of the loss from the vendor, depending on the warranties and indemnities in their contract. The company's own response costs and privacy claims typically fall to cyber insurance, while claims that its service failed customers fall to E&O.

What is data poisoning in AI?

Data poisoning is an attack in which the data used to train, fine-tune or inform an AI model is manipulated so that the model learns hidden backdoors, errors or biases. A 2025 study by Anthropic, the UK AI Security Institute and the Alan Turing Institute found that as few as 250 malicious documents could plant a simple backdoor in models of up to 13 billion parameters, which makes the source of training data a practical concern.

Does insurance cover losses caused by a poisoned AI model?

Claims caused by a poisoned model usually look like ordinary AI errors, such as wrong advice, a bad decision or a biased result, so they tend to fall to E&O, EPL or D&O cover rather than to cyber insurance, which needs a security event. Those liability policies may be silent on AI or carry new AI exclusions, so it is worth reading their AI wording and adding affirmative AI coverage where it is missing.

Sources

  1. [1]IBM Report: 13% of Organizations Reported Breaches of AI Models or Applications, 97% of Which Reported Lacking Proper AI Access Controls, IBM, July 30th 2025
  2. [2]IBM Study: One in Four Malicious Breaches are AI-Enabled, Costing Companies $6 Million on Average, IBM, July 29th 2026
  3. [3]Disrupting an AI-orchestrated cyber espionage campaign, Anthropic, November 13th 2025
  4. [4]NIST AI 100-2 E2025, Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (March 2025), National Institute of Standards and Technology
  5. [5]OWASP Top 10 for LLM Applications 2025: LLM01 Prompt Injection, OWASP Gen AI Security Project
  6. [6]Salesforce Agentforce tricked into leaking sales leads (ForcedLeak), The Register, September 26th 2025
  7. [7]AI threats in the wild: The current state of prompt injections on the web, Google, April 23rd 2026
  8. [8]OWASP Top 10 for LLM Applications 2025: LLM04 Data and Model Poisoning, OWASP Gen AI Security Project
  9. [9]A small number of samples can poison LLMs, Anthropic, October 9th 2025
  10. [10]Amazon AI coding agent hacked to inject data wiping commands, BleepingComputer, July 25th 2025
  11. [11]The Continued Proliferation of AI Exclusions, Hunton Andrews Kurth, May 28th 2025
  12. [12]Multinational loses HK$200 million to deepfake video scam, Hong Kong Free Press, February 5th 2024
  13. [13]A deepfake ‘CFO’ tricked British design firm Arup in $25 million fraud, Fortune, May 17th 2024
  14. [14]FinCEN Alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions (FIN-2024-Alert004), Financial Crimes Enforcement Network, U.S. Department of the Treasury, November 13th 2024
  15. [15]2025 IC3 Annual Report, Federal Bureau of Investigation, Internet Crime Complaint Center
  16. [16]Apache Corp. v. Great American Insurance Co., No. 15-20499 (5th Cir.) (unpublished), U.S. Court of Appeals for the Fifth Circuit, October 18th 2016
  17. [17]American Tooling Center, Inc. v. Travelers Casualty & Surety Co. of America, No. 17-2014 (6th Cir.), U.S. Court of Appeals for the Sixth Circuit, July 13th 2018
  18. [18]From Phishing to Deepfakes: Social Engineering Risks Are Intensifying for Professional Service Firms (April 2026), Aon
  19. [19]SEC Adopts Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure by Public Companies, U.S. Securities and Exchange Commission, July 26th 2023
  20. [20]Cybersecurity Incident Disclosure: Form 8-K Tracker (Two-Year Update), Debevoise & Plimpton, May 21st 2026
  21. [21]Securities Class Action Filings Surge in the First Half of 2026, Cornerstone Research, July 29th 2026

Next step

Put Affirmative AI Coverage in Front of Your Board

Apply online and underwriting will respond within 48 hours, or send a short note if you would rather talk first.