Most cyber insurance policies were written for attacks that don’t happen anymore. Attackers targeted your perimeter. They tried to breach your data. They deployed ransomware against your infrastructure. Cyber policies were built to respond to those scenarios. But the threat landscape has fundamentally shifted. Attackers now exploit AI vulnerabilities, compromise your vendors, and use social engineering to trigger voluntary transfers. The policies haven’t kept pace.

AI Is Rarely Named Explicitly In Policy Language

AI has become a primary attack vector. Model manipulation, prompt injection, data poisoning, deepfake fraud. These are real threats that organizations face today.

But most cyber policies don’t explicitly reference AI. Cover for these threats is inferred, not guaranteed. The NIST AI Risk Management Framework provides a comprehensive approach to managing AI risks, but most cyber policies predate this framework and don’t incorporate its recommendations.

A policy might cover “fraud” or “unauthorized access,” but it doesn’t explicitly state whether that covers AI-generated deepfakes or model poisoning attacks. The OWASP Top 10 for Large Language Model Applications identifies specific LLM vulnerabilities that organizations should protect against, yet standard cyber policies remain silent on these threats.

This creates ambiguity. When an organization experiences an AI-enabled attack and files a claim, the insurance company can argue: this threat wasn’t contemplated in the policy language. Cover is disputed. The organization absorbs the gap.

Explicit coverage for AI-specific threats is beginning to appear in new policy wordings. But most organizations are still operating under older language that treats AI threats as variations of traditional fraud or system compromise, rather than as distinct attack vectors.

Supply Chain Risk Sits In Contingent BI—And It’s Sub-Limited

The most common attack path today isn’t through the insured’s own perimeter. It’s through a vendor or SaaS provider. Attackers compromise a less-secure supplier. The insured’s operations stall because they depend on that supplier’s service.

The CISA Securing the Software Supply Chain guidance outlines best practices for managing supply chain risk, but most cyber policies don’t adequately cover the financial impact when a vendor is compromised.

This is contingent business interruption exposure. It’s covered under most cyber policies—but typically as a sub-limit well below the main aggregate. An organization with $10 million in cyber coverage might have only $1 million in contingent BI sub-limits.

For an organization losing $500,000 daily when a critical vendor goes offline, a $1 million sub-limit covers two days of losses. The remaining exposure is uninsured.

Additionally, contingent BI coverage often requires proof that the vendor’s outage directly caused a demonstrable loss. Establishing that causal chain takes time. By the time the claim is approved, the organization has already absorbed months of recovery costs.

Social Engineering Cover Is Scattered Across Cyber And Crime Wordings

Social engineering attacks result in voluntary transfers. An employee believes they’re following legitimate instructions from an executive. The money moves to an attacker. The system worked correctly. But the loss is real.

This loss sits between cyber insurance and crime insurance. Neither policy owns it cleanly. Cyber insurance covers system breaches, not voluntary transfers. Crime insurance covers theft, but often excludes “voluntary parting”—situations where the victim willingly transferred money because they were deceived.

Social engineering fraud (SEF) coverage attempts to bridge this gap. But SEF is placed inconsistently across cyber and crime wordings. Some organizations have it under cyber. Some under crime. Some under both, but with different sub-limits and exclusions.

When a social engineering attack occurs, the claim gets disputed. Is this cyber? Is this crime? Does the voluntary parting exclusion apply? By the time the coverage question is resolved, the organization has already spent months without recovery.

Regulators Are Expanding AI Enforcement

Regulators in the UK, EU, and APAC are expanding enforcement around AI governance, model integrity, and data security. When an organization experiences an AI-enabled attack or discovers model poisoning in their systems, regulators open investigations.

The HKMA Supervisory Approach on Cyber Risk Management and HKMA Technology Risk Management Guidelines set expectations for Hong Kong institutions. In Singapore, the MAS Cyber and Technology Resilience Experts Panel and the MAS AI-Driven Cyber and Technology Risk Taskforce are actively working to strengthen defenses against AI-enabled threats.

The EU AI Act and AI Act Explorer set a comprehensive regulatory framework. The FCA’s AI governance expectations in the UK emphasize governance and operational resilience.

These investigations trigger notification requirements, defense costs, and compliance obligations. Traditional cyber policies address notification costs for data breaches. They don’t explicitly address notification for AI governance failures or model compromise incidents.

As regulatory enforcement expands, organizations are facing investigation costs that their cyber insurance doesn’t contemplate. The gap between actual exposure and insured exposure widens.

The Three Gaps Show Up In Almost Every Mid-Market Programme

When Continuum reviews cyber insurance programmes for mid-market and fintech organizations, three gaps consistently appear:

First, AI threats are inferred, not explicit. Cover for model manipulation, prompt injection, or deepfake fraud depends on how broadly the policy interprets “fraud” or “cyber attack.” That ambiguity creates claims disputes.

Second, supply chain risk is sub-limited. Contingent BI coverage exists but is capped well below the organization’s actual exposure to vendor outages. The most likely attack path is under-insured.

Third, social engineering sits in a grey zone. Whether the claim is covered depends on how cyber and crime policies interact, how SEF sub-limits are structured, and whether voluntary parting exclusions apply. The coverage landscape is unclear.

A Defensible Cyber Programme Aligns Wordings Across Cyber, Crime, And PI

Organizations need cyber insurance that explicitly addresses AI threats. They need contingent BI sub-limits that reflect their actual vendor dependencies. They need clear coverage for social engineering fraud without voluntary parting exclusions.

Most importantly, they need alignment. Cyber, crime, and professional indemnity policies should work together to close gaps, not create them. When a loss occurs, the organization should know which policy responds—not spend months disputing coverage.

This requires reviewing wordings against the current threat environment, not the environment they were drafted for. Most cyber programmes were built three to five years ago. The threat landscape has evolved. The policies haven’t.

Understanding Your Coverage Against Today’s Threats

Before renewing cyber insurance, organizations should ask:

Does the policy explicitly cover AI-specific threats? Or does cover depend on broad interpretations of “fraud” and “system compromise”?

What are the contingent BI sub-limits? Are they adequate for a multi-day vendor outage? Or do they cover only a fraction of your actual exposure?

How is social engineering covered? Is it under cyber, crime, or SEF? Are there voluntary parting exclusions? What are the sub-limits?

How do your cyber, crime, and PI policies interact? Do they work together to close coverage gaps, or do they create overlaps and exclusions?

Most organizations can’t answer these questions. They renew based on premium, not on whether the coverage aligns with their actual threat environment.

Continuum Helps Close The Gaps

Cyber policies need to evolve. The Insurance Information Institute’s latest cyber insurance market analysis shows the market is growing, but coverage gaps persist. Until policies evolve, organizations need to understand where their coverage falls short and what gaps exist between their actual cyber risk and their insured exposure.

Continuum reviews cyber, crime, and PI policies against the threat environment organizations actually face today. We identify where AI threats are under-covered, where supply chain risk is sub-limited, and where social engineering sits in a grey zone. We help organizations align their wordings to close those gaps before a loss occurs.

Before renewing cyber insurance, understand what your policies actually cover—and what they don’t. Contact Continuum to review your coverage against the current threat landscape.