CFC has rebuilt the cyber section of its financial institutions insurance suite around its full cyber proactive response (CPR) policy and added affirmative wording for AI-related cyber exposures, the specialist insurer announced. The update applies across most of CFC's financial institutions (FI) offering, including its investment managers product, and covers directors and officers, errors and omissions, professional liability, crime, employment practices liability, cyber and general liability, sold either standalone or combined into a single blended policy.
Financial institutions have historically had to piece together their D&O, E&O, crime, and cyber cover from separate policies, often from separate markets, because no single product covered every angle of a firm's exposure.
That structure creates a specific failure point. Cyber exclusions written into D&O and E&O policies were originally designed to funnel cyber-related claims toward a dedicated cyber policy and avoid paying the same loss twice. In practice, insurers have applied those exclusions broadly enough that claims policyholders assumed would transfer cleanly between policies get denied instead, leaving the institution holding a loss no single policy was written to pay.
A social engineering fraud loss is the clearest version of this problem in the FI space. Whether it falls under a crime policy, a cyber policy, or neither depends on exactly how the loss occurred and how each policy's wording defines the trigger. Disputes between carriers over which policy responds first are common enough that they've become a recognized weak point in cross-policy placement, particularly in community banking programs where cyber, fidelity bond, and D&O cover routinely overlap and conflict.
CFC's approach folds these lines into one coordinated policy rather than leaving the coordination to the broker at claims time. The company describes the structure as reducing protection gaps and overlaps by design. It lets a client pick standalone coverages or combine them, with the investment management version extendable to meet AIFMD requirements for firms operating under that regime.
Whether that consolidation genuinely closes the gaps that plague multi-carrier FI programs depends on how the policy defines the boundary between its own sections internally. A blended policy can still contain the same funnelling language between its cyber and management liability parts that causes disputes when those sections sit in separate policies. The practical test is in the wording of those internal boundaries, rather than in the fact of consolidation itself.
The cyber section being brought into the FI suite is CFC's full CPR policy, which the insurer says includes 30 coverage enhancements along with unlimited reinstatements and a nil deductible, features that are checkable within the policy itself rather than characterizations to take on faith. That cyber wording now includes affirmative cover for AI-related exposures.
CFC is not alone in making that move recently. Beazley announced a comparable AI Clarifying Endorsement for its cyber product, stating explicitly that AI-driven cyber attacks fall within its existing cover.
Cyber policies across the market have spent the past two years absorbing AI-related risk without naming it. That gap the industry has taken to calling silent AI is a direct echo of the silent cyber problem that pushed cyber exposure out of general policies and into standalone products roughly a decade ago.
Two carriers moving to affirm AI coverage within days of each other suggests that transition is now underway in earnest within cyber wording specifically, distinct from the parallel move happening in general liability, where new ISO exclusion forms effective this January let carriers strip AI-related losses out of standard policies rather than affirm them.
Affirmative wording for AI-driven attacks answers a narrower question than "is AI covered." It confirms that AI as a tool used against the policyholder, in phishing, reconnaissance, or intrusion, falls within existing cyber cover. However, it says nothing about whether a financial institution's own use of AI, in client-facing tools, trading models, or vendor platforms, is covered elsewhere in the same policy, or whether that exposure sits under E&O, professional liability, or a gap between the two.
For firms buying the blended FI product specifically because of interconnected exposure across cyber, E&O, and professional liability, that's the boundary worth reading closely.