Cyber insurance responds to security and privacy events, such as a data breach, a ransomware attack or a network outage, including those in which AI plays a part. Many AI claims involve no security event at all, for instance a chatbot that gives a customer wrong advice or a screening tool that rejects older job applicants, so they fall to errors and omissions (E&O), employment practices liability (EPL) and directors and officers (D&O) policies, which may say nothing about AI or exclude it outright. A company that uses AI in its products or in decisions about people therefore needs both kinds of cover, with wordings that meet without a gap.
Does Cyber Insurance Cover AI?
Cyber insurance covers AI-related losses mainly when they arise from a security or privacy event, such as a breach, a data leak or a ransomware attack. An AI system can cause a loss while working exactly as it was built to, and a claim that it was wrong, biased or misdescribed then gives the cyber policy nothing to respond to, so the claim falls to the company's liability policies instead.
| Topic | Cyber insurance | AI liability insurance (E&O, EPL, D&O) |
|---|---|---|
| Trigger | A security failure, data breach, privacy event, extortion demand or network outage | A claim alleging a wrongful act, such as negligent advice, discrimination or a misleading statement |
| Typical claimant | The company itself; customers, employees and regulators affected by the incident | Customers, clients, job applicants, employees, shareholders and regulators |
| Typical loss | Forensics, notification, data recovery, extortion payments, lost income and claims over exposed data | Defense costs, damages, settlements and judgments |
| AI examples | A prompt injection attack that leaks customer records; a breach in which attackers used AI | A chatbot gives wrong fare advice; a screening tool rejects older applicants; a company overstates its AI to investors |
| Where the gap is | AI losses with no security event | Policies that are silent on AI or exclude it |
The practical test for any use of AI is therefore to ask what would go wrong: a leak points to cyber, while a wrong, unfair or misleading result points to E&O, EPL or D&O.
What Does Cyber Insurance Cover?
Cyber insurance covers the costs and claims that follow a security failure or privacy event, through first-party cover for the company's own losses and third-party cover for claims by others, and both parts assume that such an event has occurred.
Definition
First-party and third-party cover
First-party cover pays the policyholder's own costs after an incident, such as forensic investigation, data recovery and lost income. Third-party cover pays for claims that others bring against the policyholder, such as claims by customers whose data was exposed.
According to guidance for businesses from the Federal Trade Commission (FTC), first-party cover typically includes notification and legal advice, data recovery, business interruption, crisis management, cyber extortion and forensic investigation. Third-party cover typically includes payments to consumers affected by a breach, lawsuits and regulatory inquiries, and losses related to defamation and copyright or trademark infringement.[1] Almost every item on that list is tied to the incident itself, so a loss that arises from what an AI system says or decides, while every system works as intended, falls outside what the policy was designed for.
The defamation and infringement items are the partial exception, since they may reach content an AI system produces for the company, depending on how the policy defines the media it covers. It is a good idea to read the definitions of “security failure,” “privacy event” and “computer system” in the current cyber policy, because they settle most of the questions that follow.
Which AI Claims Fall Outside Cyber Insurance?
The AI claims that fall outside cyber insurance are those in which nothing was breached, such as wrong answers, discriminatory decisions, misleading statements about AI and mistaken actions by AI agents. Each is a claim about the quality, fairness or honesty of what the company did, so it looks to E&O, EPL or D&O cover instead.
Wrong Output With No Breach
The clearest example is Moffatt v. Air Canada, in which British Columbia's Civil Resolution Tribunal held Air Canada liable for negligent misrepresentation on February 14th 2024 after the chatbot on its website gave a customer wrong information about bereavement fares. The tribunal ordered the airline to pay C$812.02 in damages, interest and fees and rejected Air Canada's argument that the chatbot was responsible for its own actions, finding that the chatbot “is still just a part of Air Canada's website.”[2][3] The sum was small and the tribunal hears small claims, but its reasoning matters more than the award, because it treated the chatbot's answer as the company's own statement.
Nothing in the case involved a hack or a leak, so a typical cyber policy would have had nothing to respond to, even though security specialists treat this kind of error as an AI risk. The OWASP Top 10 for large language model (LLM) applications, a ranking of the main security risks in AI systems, lists misinformation as LLM09 in its 2025 edition and cites the Air Canada case among its examples.[4] For a company whose chatbot or AI-generated work reaches customers, the policy that matters is professional liability, and it is worth confirming that the E&O wording does not restrict claims over AI output, which is the exposure AI Professional Liability (AI-E&O) is written for.
Discriminatory Decisions
AI used in hiring creates discrimination claims, which are employment claims rather than security events. In Mobley v. Workday, a federal court in California allowed a job applicant's claims against the HR software vendor to proceed. On May 16th 2025 the court preliminarily certified a collective of applicants aged 40 and over under the Age Discrimination in Employment Act, a step that lets other applicants in that age group join a case that was still being litigated in 2026.[5] Earlier, iTutorGroup paid $365,000 to settle a suit by the Equal Employment Opportunity Commission (EEOC) alleging that its application software automatically rejected female applicants aged 55 or older and male applicants aged 60 or older.[6]
No data was stolen and no system failed in either case, so for an employer using such a tool these claims fall to EPL, subject to its wording, and that is the exposure AI Employment Practices Liability (AI-EPL) is written for. An employer that screens applicants with AI should check before renewal that its EPL policy does not exclude AI-driven decisions.
Misleading Statements About AI
Statements about AI create securities and regulatory exposure for directors and officers. On March 18th 2024 the SEC settled charges against two investment advisers, Delphia and Global Predictions, for false and misleading statements about their use of AI, with penalties of $225,000 and $175,000.[7] Private plaintiffs have followed, and Cornerstone Research counted 15 AI-related securities class actions in the first half of 2026, putting such filings “on pace to nearly double the 2025 total.”[8]
These suits allege that the company misdescribed its AI or, in a newer line of cases, that it failed to disclose how AI was disrupting its business.[19] Because they turn on what the company and its leaders told investors, they are a D&O matter and the exposure AI Directors and Officers Liability (AI-D&O) is written for. A company that describes its AI in filings or on investor calls should check its D&O wording for an AI exclusion before the next renewal.
Mistaken Actions by AI Agents
AI agents, meaning systems that carry out tasks in other software on a user's behalf, can cause losses through authorized actions that go wrong. In July 2025 an AI coding agent on the Replit platform deleted a live production database holding records on more than 1,200 executives during a code freeze, before the user restored the data himself.[9] The agent had been given access, so nothing was breached in the usual sense, and a claim by a client who lost money because of such an action would usually be a professional liability claim. A company that lets agents change live systems should be ready to explain to underwriters how their permissions are limited.
Which AI-Related Events Can Cyber Insurance Cover?
Cyber insurance can cover AI-related events that are, at bottom, security or privacy incidents, such as breaches in which attackers used AI and prompt injection attacks that expose data. Whether a given policy responds depends on its definitions and on any AI exclusion or endorsement (a written amendment to the policy) it carries, and the AI risks overview shows how AI is changing cyber exposure more broadly.
AI-Assisted Breaches
A breach in which the attacker used AI is still a breach, so the question for buyers is less whether cyber responds than whether its limit is large enough. IBM's 2026 Cost of a Data Breach Report found that one in four malicious breaches were AI-enabled and that these cost an average of $6 million, roughly $1 million more than the global average of $4.99 million, while more than 20% of organizations reported a breach that targeted AI models or applications.[10] A cyber limit chosen several years ago is worth testing against those costs at the next renewal.
Prompt Injection That Leads to a Data Leak
Definition
Prompt injection
Prompt injection is an attack in which instructions hidden in user input or in content an AI system reads cause the system to ignore its intended rules. It can lead an AI assistant to disclose data or take actions its operator never authorized.
Prompt injection is the first entry, LLM01, in the OWASP 2025 Top 10 for LLM applications, which lists the “disclosure of sensitive information” among its possible effects.[11] In June 2025 researchers disclosed EchoLeak, a critical zero-click flaw in Microsoft 365 Copilot (CVE-2025-32711) that could let an attacker extract sensitive information without any action by the user; Microsoft fixed it that month, with no evidence that it had been exploited.[12] In September 2025 a similar critical flaw, ForcedLeak, was disclosed in Salesforce's Agentforce, where it could have leaked customer relationship management (CRM) data until it was fixed.[13]
When an attack of this kind exposes personal or confidential data, the result looks like a classic privacy event, which is the loss cyber insurance is built for. The uncertainty lies in the definitions, because a prompt injection works through an AI tool the company is authorized to use, often one a vendor hosts, and involves no break-in. It is best to ask the cyber insurer to confirm in writing that such an attack counts as a security failure or privacy event under the policy.
Why Deepfake Payment Fraud Turns on Social Engineering Cover
Deepfake payment fraud, in which criminals use AI-generated video or audio to impersonate an executive, tests social engineering cover rather than the security-event cover at the core of a cyber policy, because the loss comes from an employee who is deceived into sending money while every system works normally. Social engineering cover, which pays for losses caused by that kind of deception, can sit in a crime policy or form part of a cyber policy. In a fraud reported in 2024, an employee in the Hong Kong office of the engineering firm Arup made 15 transfers totaling HK$200 million, about US$25.6 million, after a video call in which fraudsters impersonated the company's CFO, and Arup said that “none of our internal systems were compromised.”[14]
Aon noted in April 2026 that “there is potential coverage in both crime and cyber policies,” depending on the attack and the terms, but that social engineering is “often subject to low sublimits,” meaning caps well below the policy's overall limit.[15] Some cyber insurers have moved to cover these schemes, according to Gallagher's John Farley, who told Business Insurance that “a number of cyber insurance carriers” had come out and said they would cover “those AI-driven attacks for deepfake technology schemes.”[16] The guide to prompt injection, data poisoning and deepfake fraud sets out which policy responds to each of these attacks. For a finance team, the priority is to confirm which policy carries the social engineering cover and whether its sublimit matches the largest payments the company routinely makes.
How Do Cyber and AI Liability Policies Work Together?
Cyber and AI liability policies work together by dividing AI losses at the security event: cyber takes the incident and its privacy consequences, while E&O, EPL and D&O take claims that the company's AI was wrong, unfair or misdescribed. The risk lies where the policies meet, in overlaps where both respond to one event and in gaps where each points to the other or both exclude AI.
Overlaps are the smaller problem, because when a single event triggers both policies, for instance a prompt injection that leaks a client's data and causes it a financial loss, the other-insurance clauses largely decide which pays first. Such a clause sets out how a policy shares a loss with other insurance that also applies, and if both clauses say their policy applies only in excess of the other, the dispute can delay payment. The FTC's guidance suggests asking a cyber insurer whether it will provide cover “in excess of any other applicable insurance you have,”[1] and the same question belongs in the review of each liability policy.
Gaps are the larger problem, and they are growing on the liability side. By May 2025 W. R. Berkley had introduced an AI exclusion for its D&O, E&O and fiduciary liability products that removes cover for any claim “based upon, arising out of, or attributable to” any actual or alleged use, deployment or development of AI.[17] Verisk's ISO generative AI exclusions for commercial general liability (CG 40 47, CG 40 48 and CG 35 08), standard forms that carriers have started to adopt, took effect in January 2026.[16] A company whose cyber policy needs a security event and whose liability policies exclude AI can find that an AI claim falls between them, a problem the guide to silent AI and AI exclusions examines in detail.
Underwriters themselves rank the AI exposure in professional liability above that in cyber. In a Lloyd's Market Association (LMA) survey that drew 144 responses in the second and third quarters of 2025, 94% of them from underwriters, professional indemnity (the UK term for professional liability) was rated the class with the highest potential impact from AI loss scenarios, followed by cyber, although the LMA noted that the actual risk depends on the wording and the circumstances.[18]
Affirmative AI liability coverage, which names AI claims expressly rather than leaving them to argument, is designed for the claims that remain. Mayflower Specialty writes it in four modules: AI Directors and Officers Liability (AI-D&O), AI Employment Practices Liability (AI-EPL), AI Professional Liability (AI-E&O) and AI DIC Excess, a difference-in-conditions layer over an existing D&O, EPL and E&O program, written for AI claims those policies are silent on or exclude. Coverage is written on a claims made and reported basis, on A- (Excellent) AM Best rated paper backed by global reinsurers, placed through brokers and underwritten on the applicant's AI governance. Because the modules are liability coverage, they sit beside a cyber policy and do not replace it, and since the treatment of a claim that also involves a security event depends on the wording, the two programs are best reviewed together.
What Should You Ask Your Broker at Renewal?
The most useful renewal questions test where each policy stops, and five are worth putting to the broker in writing:
- Does our cyber policy treat a prompt injection attack on an AI tool we use, including one a vendor hosts, as a security failure or privacy event?
- Has any policy in our program, cyber included, added an AI exclusion or an AI endorsement since the last renewal, and how does it define AI?
- Which policy carries our social engineering cover, what is its sublimit, and does a payment made after a deepfake call meet its verification conditions?
- Which policies respond if our chatbot misinforms a customer or an AI screening tool is said to discriminate, and do their wordings restrict AI claims?
- How do the other-insurance clauses in our cyber and liability policies interact when a single AI event triggers both?
The recommended course of action is to start from an inventory of the company's AI systems, which Mayflower's application asks for in any case, and to map each system to the policy that should respond if it leaks data, gives a wrong answer, treats someone unfairly or is misdescribed to investors. Where the liability side is silent on AI or excludes it, the gap is best closed before the next renewal rather than after a claim. The coverage gap check is a short way to start, after which a company or its broker can apply for AI-E&O or AI DIC Excess over an existing program.
Frequently Asked Questions
Does cyber insurance cover AI hallucinations?
Does cyber insurance cover deepfake fraud?
Do I need both cyber and AI liability insurance?
Is a prompt injection attack covered by cyber insurance?
Can cyber insurance policies exclude AI?
Sources
- [1]Cyber Insurance (Cybersecurity for Small Business), Federal Trade Commission
- [2]Moffatt v. Air Canada, 2024 BCCRT 149, Civil Resolution Tribunal of British Columbia (via CanLII), February 14th 2024
- [3]BC Tribunal Finds Air Canada Liable for Inaccurate Advice Given by Website Chatbot, Deeth Williams Wall
- [4]OWASP Top 10 for LLM Applications 2025: LLM09 Misinformation, OWASP Gen AI Security Project, November 17th 2024
- [5]Mobley v. Workday, Inc., 3:23-cv-00770 (N.D. Cal.), case summary, Civil Rights Litigation Clearinghouse
- [6]iTutorGroup to Pay $365,000 to Settle EEOC Discriminatory Hiring Suit, U.S. Equal Employment Opportunity Commission, September 11th 2023
- [7]SEC Charges Two Investment Advisers with Making False and Misleading Statements About Their Use of Artificial Intelligence, U.S. Securities and Exchange Commission, March 18th 2024
- [8]Securities Class Action Filings Surge in the First Half of 2026, Cornerstone Research, July 29th 2026
- [9]An AI-powered coding tool wiped out a software company's database, then apologized for a 'catastrophic failure on my part', Fortune, July 23rd 2025
- [10]IBM Study: One in Four Malicious Breaches are AI-Enabled, Costing Companies $6 Million on Average, IBM, July 29th 2026
- [11]OWASP Top 10 for LLM Applications 2025: LLM01 Prompt Injection, OWASP Gen AI Security Project, November 17th 2024
- [12]Zero-Click AI Vulnerability Exposes Microsoft 365 Copilot Data Without User Interaction, The Hacker News, June 12th 2025
- [13]Prompt injection and a $5 domain trick Salesforce Agentforce into leaking sales (ForcedLeak), The Register, September 26th 2025
- [14]A deepfake 'CFO' tricked the British design firm behind the Sydney Opera House in $25 million scam, Fortune, May 17th 2024
- [15]From Phishing to Deepfakes: Social Engineering Risks Are Intensifying for Professional Service Firms (April 2026), Aon
- [16]Insurers, brokers adjust as AI exclusions emerge, Business Insurance, April 7th 2026
- [17]The Continued Proliferation of AI Exclusions, Hunton Andrews Kurth, May 28th 2025
- [18]Understanding AI Exposures: AI Loss Scenarios Survey Results, Lloyd's Market Association
- [19]AI-Related Securities Litigation Continues to Evolve, The D&O Diary, July 13th 2026
