Will your cyber insurance pay out if the attacker used AI? For years, the honest answer was "nobody had said." That is changing. Beazley, a leading specialist in the cyber insurance sector, confirmed it would provide "AI-affirmative cover" — meaning it covers losses from an incident even if the attacker used artificial intelligence, according to Cybersecurity Dive.
That matters because the industry had been mostly silent on AI-based attacks, leaving businesses unsure whether losses would be covered at all. If you run a business with a cyber policy — or you're shopping for one — this is the moment to read the fine print on AI. Not every insurer has taken the same position, and the differences now visible between them are exactly what you should ask about at renewal. This connects to our earlier piece, How the SEC's four-business-day cyber incident rule actually works.
This guide explains what AI-affirmative cover actually is, where the major named insurers stand, and what to check in your own policy. If you need the fundamentals first, our cyber insurance explainer covers what standard policies cover, demand, and exclude. Readers following this should also see Cyber insurance explained: what policies cover, what they demand, and what they exclude.
Why did AI create an insurance gap in the first place?
Cyber insurance was already under pressure from a rising wave of cyber risk. Then AI arrived fast, and insurers had to work out whether the sector could afford to cover potentially billions in losses from a catastrophic event, per the Cybersecurity Dive report. For years, the industry was largely noncommittal on how it would handle AI-based cyberattacks.
The result was uncertainty across multiple industries, including cyber itself, about whether losses would be covered. That's according to a report released Wednesday from Rand. "There is an emerging story about whether this just adds to existing risks in insurance lines or whether it creates new risks," said Sasha Romanosky, a senior policy researcher at Rand and co-author of the report.
There's also a legal layer: a wide range of AI-related disputes are currently winding through the court system in the U.S. and other parts of the world. Until those cases settle out, insurers' written positions are doing the work courts haven't yet.
What exactly is "AI-affirmative cover"?
It's a commitment, not a product feature you can assume you have. Beazley's version, confirmed on a Thursday after months of uncertainty, means the insurer covers losses stemming from an incident even if the attacker utilized artificial intelligence. In other words: the method of attack doesn't void the policy.
That distinction matters because the alternative — silence, or an exclusion buried in renewal paperwork — could leave a business eating the full cost of an AI-driven breach. The Financial Times reported in April that some insurance firms, including Beazley, were looking to cap payouts for certain AI-related losses. So even where coverage exists, watch for limits.
Where do the major insurers stand?
The named positions come from insurers speaking to Cybersecurity Dive, and they don't all match. Here's the comparison:
| Insurer | Stated position on AI-related claims |
|---|---|
| Beazley | Confirmed "AI-affirmative cover" — losses covered even when the attacker used AI |
| QBE | "Continuing to support coverage for cyber risks and claims arising out of AI, not retreating from them," per Serene Davis, global head of cyber. AI is "treated as a risk amplifier, not a fundamentally new cyber risk." Core policies cover losses from system compromise or data breaches the same way whether or not AI was involved |
| AIG | No immediate plans to limit coverage for AI-related claims. It told Cybersecurity Dive that although an Insurance Services Offices (ISO) General Liability policy update includes GenAI exclusions, it is "not specifically seeking to use or implement any of these exclusions at this time." One of its subsidiaries filed a response to ISO |
| Boxx (a Zurich Insurance subsidiary) | Cyber policies have consistently covered losses from social-engineering attacks and failures to secure an insured's computer network; as concerns around AI-related attacks grew, it added coverage for AI-driven social-engineering attacks and security failures, per Erik Tifft, global head of underwriting |
ISO, for context, is an industry office that interacts with state insurance policy regulators across the U.S. Its GenAI exclusions exist in a policy update — but an exclusion existing in a form is not the same as an insurer using it. AIG's statement is the clearest current example of that gap.
Why should a policyholder care about this now?
Because the security-side picture is moving at the same time. Criminal and state-linked hackers are increasingly using AI to accelerate and scale attacks beyond the ability of current technologies to track them, per the report. If you can't confirm whether you'd have full insurance coverage, the practical consequence is that you may have to take additional measures to protect your systems from disruption and future liability.
"As organizations accelerate AI adoption and threat actors use AI to increase the speed and scale of their attacks, organizations are looking for greater clarity around how these risks are assessed and managed," says Kevin Kiser, senior director of strategy for insurance solutions at Arctic Wolf.
There's also competitive pressure reshaping the market. So-called InsureTechs — mostly Silicon Valley–backed startup firms using AI, machine learning and low overhead expenses — are bypassing traditional insurance firms in much the way fintechs bypass traditional banks. More options can mean more tailored coverage, but also more variation between policies.
What should I check in my own policy?
Based on what these insurers have actually said, here's a practical checklist for your next renewal conversation:
- Ask directly whether AI-involved attacks are covered. Beazley's affirmative cover shows the question is answerable. If your insurer won't give a written answer, that is itself information.
- Look for AI-specific exclusions. The ISO General Liability update includes GenAI exclusions. Check whether your policy documents reference them or anything similar — and ask whether the insurer intends to adopt them.
- Check for payout caps on AI-related losses. Some firms, including Beazley, were reported in April to be looking at capping certain AI-related payouts. A covered loss with a low cap is a partial answer only.
- Confirm social-engineering coverage. AI makes phishing and impersonation cheaper and better. Boxx's approach — covering social-engineering attacks and network-security failures, then explicitly adding AI-driven versions — is the pattern to look for.
- Get positions in writing, dated. The industry's position has shifted within a single year. A statement from your insurer that isn't dated and written down won't help much at claim time.
What to do now
The evidence so far points one direction: insurers are moving from silence to stated positions, and the stated positions so far favor coverage — Beazley affirmatively, QBE and AIG explicitly not retreating. But the Rand report frames the open question that hasn't been settled: whether AI adds to existing risks in insurance lines or creates new ones. Until that's resolved, and until the AI-related disputes in courts are decided, treat your policy's AI language as something to verify, not assume.
Meanwhile, the defense side hasn't changed: coverage is a backstop, not a control. Attackers using AI to scale attacks is exactly the kind of risk you want layered defenses against — and our threats coverage tracks how those attacks are evolving. If your exposure is mainly people rather than systems, our piece on AI voice-clone robocalls covers what works against the consumer-facing version of the same problem.
The next development to watch is whether other major insurers follow Beazley with explicit affirmative cover, and how the ISO GenAI exclusions get used — or don't — across the U.S. market.

