
Your Cyber Insurance Policy Was Written Before AI. Here’s the Gap That Creates.
A few years ago, a fake email from your CEO had tells. The grammar was off. The logo looked wrong. You could train your team to spot it. That era is ending. Today an attacker can clone a voice from a public clip. They can write a flawless phishing email that names a real project. They can even join a video call wearing the face of someone you trust. The attack no longer looks suspicious. That shift changes what your business needs from its insurance.
At Western Pacific Insurance, we help business owners think through this kind of risk all the time. This guide covers the three ways AI is reshaping cyber risk for small and mid-sized businesses. Then it covers the coverage gap almost nobody checks for until a claim is in motion. Want the basics on what cyber insurance covers first? Our earlier explainer on cyber insurance for business still holds up and pairs well with this one.
How AI Has Shifted the Threat
The shift breaks into three distinct categories. Each one defeats a defense that used to work. Here is how each one lands on a business like yours.
1. Deepfake Voice and Video Fraud
The scenario is simple. Your finance person gets a call. The voice sounds like the owner, the CFO, or a long-standing vendor. A wire needs to go out today. It is a little urgent. There is a plausible reason it came through a different channel than usual. The voice is right. The request is fake.
AI generated that audio from something public. A webinar, a podcast, a conference talk all work as source material. The advanced version is not even a phone call. In one widely reported case, an employee joined a video conference with several apparent company leaders. Every one of them was an AI-generated deepfake. The employee transferred the equivalent of millions of dollars. Reuters covers how insurers are responding in this analysis of AI deepfake coverage.
The old defense was to train people to spot the fake. That no longer works, because a good fake leaves almost nothing to spot. The defense now is procedural. Call back a known number, not the number that contacted you. Require two people to approve any change to payment instructions. Never let an urgent wire skip verification just because it sounds legitimate.
2. AI-Generated Phishing
Phishing used to carry tells. Now an attacker can use AI to write a flawless message in seconds. It matches your industry’s tone and references real details. One attacker can produce hundreds of personalized variations, each aimed at a different person in your company. The clumsy mass email is fading. What replaces it reads like a note from a coworker or a vendor.
The risk grows as AI tools start to act like assistants. They can browse the web and click on a user’s behalf, not just write text. That opens a newer trick. An attacker hides instructions inside a website or document. The AI tool reads them and can be manipulated into following them instead of your employee’s. The person never sees it happen. FBI data shows business email compromise drove roughly $2.77 billion in reported losses in 2024 alone. These AI-enhanced lures feed that category directly. The full picture is in the FBI’s 2024 Internet Crime Report.
3. Your Own Team and AI Tools
The third risk is not an attack at all. Your employees use AI tools to work faster. They paste things in to get help: a customer email, a contract, a chunk of source code, a spreadsheet of client information. The research here is startling. A large share of employees who use AI tools at work paste data into them. Much of that data includes company information. Often it goes through personal accounts the business cannot see. The security firm LayerX documents this pattern in detail.
Picture a software company. A developer pastes proprietary product code into a public tool to debug it. That code now sits in a third-party system the company does not control. The same risk hits a medical office pasting patient information or a law firm pasting client detail. The fix is a written policy on what can and cannot go into these tools. Use approved business accounts, not personal ones. Train the team that a prompt is not automatically private just because it feels like a private chat. Many business and enterprise AI products do offer stronger protection. OpenAI, for example, says its business products are not used to train models by default.
The Coverage Gap Nobody Is Checking
Here is the part most owners miss. Many assume a cyber policy covers any AI-driven fraud automatically. It is not that simple. The gap shows up in two places.
The Sublimit Trap
First, the sublimit. Many standalone cyber policies include some form of social engineering, funds transfer fraud, or fraudulent instruction coverage. That is where these deepfake scams often get analyzed. But that coverage may be sublimited, endorsed separately, or missing altogether. You might carry a one million dollar cyber policy. The social engineering piece might be capped at, say, two hundred fifty thousand. Suppose a deepfake voice call costs you six hundred thousand in a fraudulent wire. Even if coverage applies, the payable amount can land well below your actual loss.
Cyber or Crime?
Second, the classification problem. Sometimes an employee is deceived and sends a wire on purpose. Some forms may not treat that as a cyber loss at all. They treat it as a crime loss. That runs through a separate commercial crime policy you may or may not carry. The loss is real either way. Which policy responds, or whether either one does, comes down to how your forms are written. Coalition, a cyber carrier, explains how funds transfer fraud coverage responds in more depth.
The AI wrinkle sits on top of all this. Carriers have reacted in two opposite directions over the last couple of years. Some added language that specifically addresses AI impersonation, including voice cloning and video deepfakes. Others tightened definitions or added exclusions that may narrow a covered event when AI is involved. Two businesses with what looks like the same policy can see different outcomes on the same claim. It depends on whose form they are on and when it was last written.
Many of these coverage agreements also carry conditions. A policy may expect a verification process for wire transfers and a second channel of confirmation. Skip it, and the carrier may have a basis to deny or limit the claim even where coverage looked solid. Those internal controls are not just good practice. Depending on the policy language, they can decide whether a claim pays at all.
What To Actually Do
None of this is a reason to avoid coverage. For many small businesses, standalone cyber coverage stays relatively affordable. It can start around the low thousands a year, depending on industry, revenue, limits, and controls. The market has generally favored buyers lately. The point is to carry the right form and know what is in it. Have a real conversation with your agent and ask four things:
- What is my social engineering sublimit, and is it anywhere close to what one bad wire could cost?
- Has my carrier added any AI-specific language, coverage or exclusion, in the last couple of renewals?
- Do I carry both cyber and commercial crime, and do those two forms line up, or is there a gap between them?
- Is there a verification procedure my policy expects me to follow, so we make sure we are following it?
If you do not know the answers, you do not fully know what you are covered for. A policy written even two or three years ago may not have caught up to the way these attacks actually happen now.
Where Western Pacific Insurance Comes In
Western Pacific Insurance is an independent agency based in Nevada. We also help business owners in Arizona, Utah, and California. Want someone to read your cyber policy with you, explain what the form appears to do, and point out the gaps worth asking about? That is the kind of thing we do every day. Understanding your insurance before you need it, not after, is the whole idea.
Get a quote and we will help you review your business coverage. We serve business owners across Nevada, Arizona, Utah, and California.
This article is educational and general in nature. Coverage varies by policy, carrier, and state, and nothing here is a guarantee of coverage. Talk with a licensed agent about your specific situation.