BOXX Insurance, a global cyber insurtech and part of Zurich Insurance Group, has announced affirmative coverage for AI and deepfake related events tied to social engineering and security failures within its commercial policy offering, Cyberboxx Business.
The company said the new endorsement is designed to eliminate ambiguity around AI-driven incidents for customers and broker partners, addressing what it called the "grey zone" that has existed in cyber policy language around AI and deepfake losses.
BOXX's move places it on one side of a divide that has opened across the cyber insurance market since the start of 2026. A number of carriers began explicitly excluding AI-generated deepfake fraud from standard social engineering coverage from January 1, 2026, narrowing or removing protection for policies renewed after that date. Others moved the opposite way, updating their social engineering insuring agreements to affirmatively include losses from AI-generated impersonation, including voice cloning and video deepfakes. BOXX's endorsement follows that second path.
BOXX pointed to recent survey data showing how quickly AI-driven threats have moved from theoretical risk to common experience. Citing Cisco's 2025 Cybersecurity Readiness Index, the company said 86% of US business leaders with cybersecurity responsibilities have reported at least one AI-related incident in the past 12 months. In Canada, KPMG research published in March 2026 found that 81% of Canadian businesses that experienced fraud in the past year also faced an AI-enabled attack.
Erik Tifft, global head of underwriting at BOXX Insurance, said the sophistication of AI tools is changing how social engineering attacks unfold. "Threat actors are exploiting trusted relationships amongst employee and executive networks which can result in handing over credentials or misdirecting payments without an actual breach," Tifft said. "That's why we've updated our policy language to address the real risks that businesses, executives and their employees face in the age of AI."
BOXX said the new AI and deepfake coverage works alongside its existing First Party Each and Every Loss feature, which reinstates the policy's aggregate limit of liability after each cyber incident, keeping coverage available for the remainder of the policy term. "Our underwriting is keeping up with the higher frequency and the changing nature of emerging cyber and AI-driven threats," Tifft said. "As a result, we're continuously enhancing our cyber insurance products with broadened, affirmative coverages to capture emerging cyber threats and new forms of cybercrime, whether they occur via systems breaches or through advanced social engineering."
BOXX is headquartered in Toronto, and the announcement lands inside a Canadian market where fraud losses have intensified sharply. The Canadian Anti-Fraud Centre reported that Canadians lost approximately $643 million to fraud in 2024, an increase of nearly 300% since 2020, and cautioned that only a small fraction of incidents are believed to be reported at all. A separate RBC poll released in March 2026 found that 81% of Canadians feel a new scam emerges almost weekly, while 87% said it is getting harder to tell whether an online ad is genuine.
That climbing loss trend is drawing a formal regulatory response. The Office of the Superintendent of Financial Institutions has said its 2026-2027 supervisory priorities include thematic monitoring of cyber insurance underwriting and the use of artificial intelligence in underwriting at selected federally regulated P&C companies, a sign that AI's role in both the threats being insured and the underwriting process itself is now a live regulatory concern. Separately, Bill C-8, introduced in 2025 to reintroduce the earlier Bill C-26, would establish mandatory cybersecurity standards and incident reporting requirements for critical infrastructure operators, a framework that could eventually shape how insurers underwrite AI-related cyber exposure for larger commercial clients.
The average cost of resolving a data breach in Canada reached $6.9 million in 2023, according to Mordor Intelligence research, a figure that has pushed organizations toward higher-limit first-party coverage for ransom payments, forensic costs and business interruption.
The Canadian cyber insurance market remains fairly concentrated, with the top five carriers accounting for nearly half of total premiums written. As more Canadian businesses report AI-enabled fraud and regulators sharpen their focus on how insurers underwrite it, product decisions by that small group of dominant carriers, including affirmative endorsements like BOXX's, will disproportionately determine how much of this fast-growing exposure the market actually ends up covering.