Silent or affirmative - the AI coverage debate reshaping Canadian cyber placements
In January 2024, a finance worker at Arup's Hong Kong office transferred US$25.6 million to fraudsters after a video call in which every participant - including his CFO - was an AI-generated deepfake. Whether that loss would be covered under a typical Canadian cyber policy is not a settled question
Silent or affirmative - the AI coverage debate reshaping Canadian cyber placements
CYBER
By Paul Lucas
02 Oct 2026

In January 2024, a finance employee at engineering firm Arup's Hong Kong office joined a video conference call with what appeared to be the company's CFO and several colleagues. Every participant on the call was a deepfake, generated from publicly available video and audio of Arup executives. The employee authorized 15 wire transfers totalling US$25.6 million before contacting Arup's UK head office and realizing what had happened. Arup confirmed the incident publicly in May 2024. No perpetrator has been publicly identified, and the funds remain unrecovered.

Whether a loss of that nature - AI-generated impersonation used to facilitate a social engineering fraud - would be covered under a typical Canadian commercial cyber policy is not a settled question. The answer depends on policy language that was written before deepfakes existed as a claims category, and on a debate that the Canadian market has not yet resolved.

Derek May, VP cyber & technology and Canadian cyber product co-leader at Hub, described both sides of that debate at a recent Insurance Business Canada cyber power panel.

"We're seeing clients really push for affirmative AI coverage. They want to have that peace of mind that the policy is there and it's protecting them. But there's two schools of thought. One is: 'Okay, let's give the clients what they're looking for. Let's script some coverage to make sure that AI is specifically mentioned, that deepfakes are specifically mentioned.' However, there's another school of thought that says: 'Let's try to keep it silent,' because if we keep it silent, we're not specifically defining those risks. And in the event of a claim, we're not then potentially narrowing inadvertently coverage where it could have been broader if we had left it alone."

Both positions have coherent logic. Neither resolves the client's exposure.

Why silence is not the same as coverage

The case for keeping policies silent on AI rests on a genuine principle: undefined terms cannot be argued against, and a policy that does not name AI exclusions has not excluded AI. In a market where carrier approaches are fragmented and claim law on AI is still developing, silence preserves flexibility.

But silence has a cost that a Canadian court case has recently made concrete.

In July 2025, the Ontario Superior Court ruled in Panasonic Canada Inc. v XL Specialty Insurance Company that Panasonic could claim under the base policy's US$1.5 million retention following a malware attack, rather than the higher US$3 million retention in a ransomware endorsement. The victory was short-lived. In September 2026, the Ontario Court of Appeal overturned that ruling, finding that Endorsement #023 governed all claims for cyber extortion and ransomware events under the policy - and that Panasonic's loss, valued at approximately US$2 million, fell entirely within that retention. The claim was wholly self-insured.

The case did not involve AI. But its lesson is directly applicable to the silent-versus-affirmative debate: when a claim arrives, the question of which policy terms govern it - base form or endorsement, broad definition or narrow one - is decided by the court against language that the broker and client may have read very differently at placement. The carrier controls that argument at claims time. Silence does not guarantee breadth; it guarantees ambiguity.

A 2026 RAND Corporation report, The Insurability of Artificial Intelligence, mapped the same risk across the broader market. It found that when a policy says nothing about AI, coverage depends entirely on how the claim is characterized at the time of loss. The deepfake BEC scenario illustrates this precisely: a loss driven by AI-generated impersonation could be framed as social engineering, a fraud event, a reputational harm claim, or a technology failure. Each framing triggers a different policy response. The carrier - not the broker or the client - controls that characterization when the claim lands.

Joe Hines, AVP commercial sales - Nova Scotia and national practice leader - cyber at Gallagher, acknowledged the market's current posture: "We're not really seeing a complete retreat from AI risk, but we're just seeing insurers looking to more precisely define the exposures that they're actually willing to insure."

Precisely defined, as Panasonic found, can mean precisely limited.

The affirmative coverage counterargument

The case for affirmative AI coverage is that explicit language removes the ambiguity that silence creates - and that clients who understand what they are buying are better protected than clients relying on undefined terms.

May noted that the market is already moving in both directions. Some carriers are scripting coverage to specifically include AI-related losses and deepfake scenarios. Others are moving toward exclusions that explicitly remove AI risk from the base form. Fenwick's June 2026 analysis found that coverage is fragmenting across cyber, tech E&O, D&O, and employment practices liability as carriers independently narrow AI protections within each line - a process the firm described as "gap risk," where no single policy in a programme provides comprehensive protection.

That fragmentation is arriving quietly. It does not typically appear as a single conspicuous AI exclusion. It arrives through revised base forms, tightening definitions, and restrictive carve-backs that a broker examining only headline policy language will miss until a claim tests them.

May's assessment of where the market stands is honest about its uncertainty: "I think it's going to take some claim activity to really hash this out. But we're in a really interesting world right now as the threats are evolving and so is the terminology that goes along with it."

The regulatory dimension

Two regulatory developments are reshaping the context in which these coverage conversations happen, operating on different timelines that matter to different client segments.

Quebec's Law 25, with all provisions in force since September 2024, has introduced breach-reporting obligations backed by significant penalties: administrative fines of up to CAD$10 million or 2% of worldwide turnover, and penal fines of up to CAD$25 million or 4% for the most serious violations. The Commission d'acces a l'information has published enforcement decisions and issued class-action pathways that Canadian privacy law has historically constrained. Any business handling personal data belonging to Quebec residents - not only Quebec-based businesses - carries this exposure.

Hynes identified Law 25 as the dominant regulatory driver shaping placement conversations today. "Law 25 is certainly leading today's conversation," he said, "and then the federal legislation is shaping tomorrow's conversations as that progresses down the road."

That federal legislation - Bill C-8, Canada's Critical Cyber Systems Protection Act - received Royal Assent on June 15, 2026. It imposes enhanced incident-reporting obligations on designated operators of federally regulated critical infrastructure across energy, utilities, transport, and financial services. Brokers with clients in those sectors who are not yet familiar with C-8's scope are already behind.

The connection between both regulatory frameworks and the AI coverage debate is direct. A deepfake-facilitated breach that triggers Law 25 reporting obligations creates a claim that spans social engineering coverage, potential regulatory defence costs, and third-party liability exposure. Whether each of those sits affirmatively within the cyber policy, silently covered by existing language, or excluded by a revised endorsement added at the last renewal - that is the question brokers need to be able to answer before the incident, not after.

What the wording review needs to cover

Marsh's Canadian Market Index has recorded carriers broadening terms even as prices continue to fall: fewer co-insurance requirements, more frequent cybercrime sublimit enhancements, lower retentions for insureds with strong security controls.

May was direct about the pace of change that creates. "It's definitely moving faster. The coverages are evolving so quickly that we're having to revisit our wording reviews on a quarterly or every six month basis now."

The Panasonic case is a reminder that a coverage enhancement granted in a soft market is only as useful as its interaction with every other term in the policy. A broadened social engineering sublimit that has not been tested against the policy's definition of a covered event - and against any AI-related endorsement language added at the same renewal - is not a confirmed protection. It is an expectation that may or may not survive contact with a claim.

The broker's discipline in this market is to understand what the evolving language actually covers, and what it does not, before a client relies on it. That applies whether the policy takes an affirmative or silent approach to AI. The Arup loss and the Panasonic case, taken together, make the same point from different directions: the coverage that matters is the coverage that holds at claim time, not the coverage that looked adequate on the day the policy was bound.

Related Stories
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB CA.