Cyber insurance rates are falling. But cheaper premiums do not mean better coverage, and AI is widening that gap. Deepfake fraud and algorithmic risks are reshaping claims in ways the market is still catching up to. Ed Chadwick, AVP and professional lines lead broker, at Jencap, says AI cyber liability risk is outpacing the coverage risk managers think they have.
Cyber claims are no longer just about system failures and ransomware. AI has moved the risk into territory that traditional policy language was not designed to cover.
"AI has shifted claims from traditional IT failures to more algorithmic risks in general," Chadwick said. "Combine that with increasingly convincing deepfake crimes, and losses have begun to increase in both frequency and complexity."
The insurance industry has already felt that shift. Synthetic voice attacks at insurance companies rose 475% in 2024, according to Pindrop's 2025 Voice Intelligence and Security Report. Carriers have responded, though unevenly.
"As an industry, we are keeping up overall on a coverage front," Chadwick said. "Several reputable carriers now offer affirmative AI coverage to policyholders." Affirmative AI coverage means policies explicitly name AI-related incidents as covered events, rather than leaving that coverage assumed under legacy language.
Chadwick adds that soft rates should not be read as a sign of better coverage. Excess market capacity is keeping premiums down independently of what the policy actually covers. "Many carriers are digging deeper into security controls such as phishing-resistant MFA and out-of-band authentication requirements," he said.
AI has made a specific structural gap more urgent. Most cyber policies are built to respond to breaches of your own systems, not failures at the third-party providers your operations depend on.
"For me, the biggest issue is the increased 'single point' threat that is inherent to AI and its use," Chadwick said. "This is why contingent business interruption is one of the biggest gaps that I come across in existing risk management portfolios."
Contingent business interruption coverage pays for income lost when a third-party system fails, not just when your own is breached. The July 2024 CrowdStrike outage is the clearest recent illustration. Fortune 500 companies lost $5.4 billion from the outage, yet cyber insurance covered only 10 to 20% of that, according to Parametrix.
"Risk managers would be wise to focus attention here to make sure their cyber policies can effectively respond to a large-scale cloud outage," Chadwick said. The question for every renewal: does your policy pay if a cloud provider fails and your own systems are never breached?
Carriers are getting ahead of AI threats. Most internal risk programs, however, are still behind them.
"Modern cyber insurance and carriers are no longer 'reactive' in nature," Chadwick said. "They're deploying proactive tools to help defend policyholders from AI-driven threats. Key areas here are continuous machine-speed risk monitoring that can detect abnormal behavior and vulnerabilities faster and, critically, more accurately."
Carriers are also deploying AI-driven deepfake detection tools to help policyholders counter social engineering. The internal work is just as urgent. Organizations with tested incident response plans save an average of $2.66 million per breach, according to IBM's 2025 Cost of a Data Breach Report.
Chadwick notes that the same discipline applies to policy language and breach response plans. "If there's been no language changes to a policy in several years, you're likely falling behind in the marketplace," he says. "A plan that was built and last tested in 2021 is likely to create confusion and frustration if needed in 2026 and beyond."