Editor's note.
One insurer's wording is described in this article, and only because its announcement was read on the insurer's own site on 14 September 2026. Every other description of crime, cyber and AI liability policies is a general market description: no clause is quoted, no form number is asserted, and no other carrier's position is characterised. Where this desk has not read a wording it does not describe one.
- An impersonation fraud that moves money is a first-party loss procured by deception. The wordings with a claim to it are commercial crime, through a social engineering or funds transfer fraud extension, and the cyber crime section of a cyber policy. Not professional indemnity, and not AI liability.
- The trigger differs. Crime historically asks who was dishonest and had to write back the voluntary parting with money that a social engineering loss involves. Cyber asks what the instruction was and whether it was verified. AI liability asks whose AI failed, and here the answer is nobody's.
- The verification condition decides more of these claims than any exclusion. A wording that requires out-of-band confirmation before a new payee or a changed bank detail is paid will apply that requirement whether the voice was real or synthetic.
- One wording names the peril expressly: a funds transfer fraud trigger extended to a fraudulent instruction transmitted by deepfake or other AI, on a North American cyber product, read at source on 14 September 2026. It is the language to ask a European broker for.
- The hard case is an insured's own AI agent executing a payment on a forged instruction. It is inbound and outbound at once, and it should be placed at renewal in writing rather than argued at claim.
Section 1. Name the loss before naming the policy
Coverage disputes in this area begin with a category error, and the error is understandable. The cause of the loss was an AI tool, so the loss is filed under AI. But insurance does not classify by cause. It classifies by trigger, and the trigger in every affirmative AI and AI liability wording this desk has read is a failure of an AI system that the insured operates, provides or relies on. In an impersonation fraud, no system of the insured's did anything. A human, or in the hard case an agent, acted in good faith on an instruction that a criminal manufactured with somebody else's tool.
Strip the technology away and the shape is familiar: the insured was deceived into transferring its own money. That is a first-party loss. Nobody is claiming against the insured, which removes professional indemnity. No system of the insured's failed, which removes AI liability in the ordinary case. What is left is the family of covers built for deception, which in a typical European programme means a commercial crime policy, the cyber crime section of a cyber policy, or both. The general division between inbound and outbound AI risk, of which this is the clearest inbound example, is set out at the professional indemnity and cyber decision guide.
Section 2. Three wordings, three triggers
Crime. A commercial crime policy was built around employee dishonesty, with third-party perils such as forgery and computer fraud added over time. The historical difficulty for a social engineering loss is that older crime wordings excluded loss where the insured voluntarily parted with money or property, and a deceived employee who authorises a payment has, in the policy's terms, parted with it voluntarily. The social engineering or funds transfer fraud extension exists precisely to write that back, and because it is a write-back it is usually optional, separately rated and sublimited. Whether it is in the programme at all is a schedule question.
Cyber. A cyber policy's funds transfer fraud or fraudulent instruction section approaches the same loss from the other direction. Its trigger is typically an instruction, received electronically, that purports to come from a person authorised to give it, acted upon in good faith, and later found to be fraudulent. The arguments that arise under this trigger are definitional: whether a telephone call, a voice message or a video call is an electronic instruction within the wording; whether an instruction that was partly genuine and partly forged qualifies; and, above all, whether the verification the policy required actually took place. Sublimits are again common and often well below the headline limit, a mechanism set out at sublimits and aggregate caps explained.
AI liability and affirmative AI. These wordings answer a different question. Their trigger is the insured's own AI: a wrong output, a biased decision, a performance shortfall, a regulatory violation arising from a system the insured deploys or provides. An impersonation fraud committed with a third party's tool does not engage that trigger, and a claim presented under one of these wordings for a forged-instruction loss should be expected to be declined on the trigger rather than on any exclusion. The current map of what these wordings do respond to is at the European AI agent insurance market tracker.
The practical consequence is uncomfortable but clarifying. The same loss can be covered under one policy, sublimited under two, and declined under either on a condition. Which of those outcomes applies is decided by wording read before the event, not by the sophistication of the fraud.
Section 3. The verification condition
More funds transfer fraud claims turn on verification than on any exclusion, and the point deserves to be stated as a rule rather than an observation.
Wordings that cover a fraudulent instruction commonly make cover conditional on the insured having verified the instruction through a channel independent of the one it arrived on, before the payment was made. The archetype is a call back to a telephone number already held on file for the requester, never to a number supplied in the request, before any new payee is created or any bank detail is changed. Some wordings require this for every transfer above a stated value; some require that a documented procedure existed and was followed; some require dual authorisation.
A synthetic voice does not change the condition. It changes only the probability that a human will skip the step, because the whole point of the clone is that the recipient believes they have just spoken to the person. The condition, however, is about the insured's process, not about the quality of the deception. A payment made on the strength of a convincing voice, without the call back the wording required, is a payment made in breach of the condition, and the claim may fail on that fact alone.
For a buyer this converts into a single question that should be answered before renewal rather than after a loss: does our actual payment procedure, as practised by the people who make payments, satisfy the verification condition in the wording we hold, in the form the wording requires. If the answer is no, the exposure is not a coverage gap. It is a control gap wearing a coverage gap's clothes, and it is cheaper to close.
Section 4. The one verified wording that names the peril
The market has begun to write this peril into insuring clauses in plain words, and one example has been read at source.
Coalition, a cyber insurer, added an affirmative artificial intelligence endorsement to its US surplus and Canada cyber policies, dated 26 March 2024. The endorsement does two things. It extends the security failure and data breach definitions to an AI security event, where AI technology caused a failure of the security of computer systems. And it extends the funds transfer fraud trigger to a fraudulent instruction transmitted through the use of deepfakes or any other artificial intelligence technology. The announcement names no reinsurer, no limit and no amount, and none is stated here. Both extensions were read at the insurer's own site on 14 September 2026.
The second limb is the peril in this article, written into a policy. Its relevance to a European buyer is not that it can be bought here; on the insurer's own description it sits on North American products, and the wider European reading of that insurer's position is at Coalition's affirmative AI coverage and its European relevance. Its relevance is that it settles what the language can look like. A buyer who wants certainty that a synthetic-voice instruction is within the funds transfer fraud definition now has a published example to put in front of a broker as the drafting to ask for, rather than asking in the abstract whether the wording would probably respond.
The same insurer separately announced a deepfake response endorsement, providing technical analysis by a deepfake forensics firm with a written report, legal work to have the content taken down, and crisis communications support, which its own announcement lists as available in the United Kingdom, Germany, Denmark, Sweden and France as well as the United States, Canada and Australia. That is a different loss from the money: it is the cost of establishing that the clip of an executive was synthetic and of containing the consequences. A programme can cover the money and not the response, or the reverse, and the two should be placed separately in the renewal conversation.
Section 5. The hard case: the insured's own agent made the payment
Everything above assumes a human received the forged instruction and acted on it. Increasingly that is not the architecture. An AI agent with authority to raise or approve payments receives the instruction, through email, through a transcribed call, through a document it was asked to process, and executes it. Now the analysis moves.
An attacker forged the instruction, so it looks like cyber crime. The insured's own AI system acted on it without human review, so it looks like a failure of an AI system the insured deployed, which is the trigger for an affirmative AI or AI liability wording. It is inbound and outbound at once. Each carrier has an argument that the other should respond, and the argument is a real one rather than a posture: the cyber carrier can say the proximate cause was the agent's decision, the AI carrier can say the proximate cause was a third-party fraud. The wider version of that overlap, where the manipulation is a hostile instruction hidden in content the agent reads, is at whether AI insurance covers losses from agent-to-agent transactions.
Two consequences follow, one for placement and one for controls. On placement, the scenario should be put to both carriers in writing before inception, with a request for confirmation of which policy is primary and whether either treats an agent-executed payment on a forged instruction as excluded. A written answer at placement is worth more than an argument at claim, and the absence of one is itself information. On controls, note that a verification condition applies to the agent's process exactly as it would to a human's. An agent that can pay a new payee without a system-enforced, out-of-band confirmation step is an agent whose payments are made in breach of the condition by design. What that control looks like when it is assessed, and the evidence that demonstrates it, is set out at agentcertified.eu, on certifying an AI agent that can move money.
Section 6. What the AI Act does and does not do here
Because the cause is an AI tool, the question arises whether Regulation (EU) 2024/1689 helps the victim. It does not, and the reason is structural rather than a gap.
Article 50 places a transparency duty on deployers of AI systems that generate or manipulate deepfake content, requiring disclosure that the content has been artificially generated or manipulated, with exceptions. That duty has applied since 2 August 2026. It regulates legitimate deployers and is enforced against them by national authorities. It creates no civil right of action for a person deceived by undisclosed synthetic content, and the person who cloned an executive's voice to commit fraud is not a deployer who will comply with it. The deployer-side reading of the obligation is at agentliability.eu, on the Article 50 transparency and labelling obligations.
The AI Omnibus, Regulation (EU) 2026/1744, added new prohibitions that apply from 2 December 2026, but they concern systems generating child sexual abuse material and non-consensual intimate imagery. They are not about financial fraud and should not be cited as if they were. For the victim of a forged-instruction loss the recovery routes are the ordinary ones: the bank's recall process, criminal reporting, and the insured's own policy, notified promptly under its conditions.
Section 7. A note on frequency
This desk does not report loss statistics it has not read at source, and none are reported here. One structural observation is defensible without them. The cost of producing a convincing synthetic voice has fallen to the point where the constraint on this fraud is no longer technical skill but the availability of a target with weak payment controls. Where the constraint on a peril is the victim's control environment rather than the attacker's capability, underwriters respond by making the control a condition, which is exactly the pattern visible in the verification requirements described above. A buyer should expect those conditions to become more specific rather than less, and should expect the underwriting questions on payment controls to be asked with more precision than they were two renewals ago. The general set of those questions is at what underwriters ask before writing a policy.
Section 8. Seven things to settle at renewal
- Which policy in the programme carries funds transfer fraud or social engineering cover, identified by section and by name, and whether it is in the programme at all.
- The sublimit, whether it is per loss or aggregate, and the excess that applies to it.
- Whether a voice call, a voice message and a video call are each within the wording's definition of a fraudulent instruction, in terms.
- What verification the wording requires as a condition, in what form, and whether the payment procedure the finance team actually follows satisfies it.
- Whether the same loss is covered under both a crime and a cyber policy and, if so, which is primary and how the other-insurance clauses interact.
- Whether a payment executed by the insured's own AI agent on a forged instruction is treated as cyber crime, as an AI system failure, or as excluded under both, confirmed in writing by each carrier.
- Whether deepfake response costs, meaning forensics, takedown and communications, are covered anywhere in the programme, since they are a separate loss from the money.
The fourth question is the one most often skipped and most often decisive. The disclosure side of the same conversation, and why an answer of we do not use AI leaves this exposure undescribed, is at disclosing AI agents when applying for insurance. The plain-language version of this article for smaller operators is at insureyouragent.com, on a cloned voice authorising a payment.
Section 9. The point in one sentence
A forged-instruction loss is placed by its trigger and decided by its verification condition, so the buyer who settles both at renewal has done more for recovery than any amount of AI cover bought afterwards.
Questions
Which policy responds when a deepfake instruction causes a payment to a fraudster?
In most programmes the candidates are a commercial crime policy, through a social engineering or funds transfer fraud extension, and the cyber crime section of a cyber policy, through its funds transfer fraud or fraudulent instruction insuring clause. Professional indemnity does not respond because no third party is claiming against the insured. AI liability and affirmative AI wordings do not respond in the ordinary case because they are triggered by a failure of an AI system the insured deploys, and in an impersonation fraud the insured's systems did nothing. The loss is the insured's own money, procured by deception, and that is a crime or cyber crime peril.
What is the trigger difference between crime and cyber wordings for this loss?
A crime policy is historically built around dishonesty of an employee, with third-party fraud added by extension, and older crime wordings excluded loss where the insured voluntarily parted with money, which is exactly what happens in a social engineering fraud. The extension exists to write that back. A cyber policy's funds transfer fraud section is built around a fraudulent instruction received electronically and acted upon in good faith, and the argument there tends to be about whether a voice call or a video call is an instruction within the definition and whether the required verification took place. The practical consequence is that the same loss can be covered under one policy, sublimited under both, and declined under either on a verification condition.
Is there any wording that names deepfake payment fraud expressly?
Yes. Coalition's affirmative artificial intelligence endorsement, dated 26 March 2024 and applying to its US surplus and Canada cyber policies, extends the funds transfer fraud trigger to a fraudulent instruction transmitted through the use of deepfakes or any other artificial intelligence technology. That is the peril written into an insuring clause in plain words, and it was read at the insurer's own site on 14 September 2026. It is a North American product on the insurer's own description. Its European relevance is as a marker of what a wording can say, which a buyer can put in front of a broker as the language they want to see in their own programme.
What changes if the insured's own AI agent executed the payment?
The loss moves into the overlap between inbound and outbound risk, and it is the case most likely to produce a dispute between insurers. An attacker forged the instruction, which looks like cyber crime. The insured's own agent acted on it without a human, which looks like a failure of an AI system the insured deployed, which is the trigger for an affirmative AI or AI liability wording. Each carrier has an argument that the other should respond. The protection is to raise that exact scenario at placement, in writing, and to ensure the agent's payment authority is subject to a system-enforced verification step, since a policy that requires verification will apply that requirement to the agent's process exactly as it would to a human's.
Does the EU AI Act give the victim of a deepfake fraud any remedy?
No. Article 50 of Regulation (EU) 2024/1689 places a transparency duty on deployers of AI systems that generate or manipulate deepfake content, requiring disclosure that the content is artificial, and that duty has applied since 2 August 2026. It regulates legitimate use and is enforced by national authorities against deployers. It creates no civil claim for a person defrauded by undisclosed synthetic content, and a fraudster is not a party who will comply with it. The victim's recovery routes remain the bank recall process, criminal reporting, and the insured's own policy. Separately, the AI Omnibus added new prohibitions applying from 2 December 2026, but those concern intimate imagery and child sexual abuse material, not financial fraud.
What should a European buyer settle at renewal for this exposure?
Seven things. Which policy in the programme carries funds transfer fraud or social engineering cover, by section and by name. The sublimit, and whether it is per loss or aggregate. Whether a voice call, a video call and a voice message are each within the definition of a fraudulent instruction. What verification the wording requires as a condition, in what form, and whether the insured's actual payment procedure satisfies it. Whether the same loss is covered under two policies and, if so, which is primary. Whether an AI-executed payment on a forged instruction is treated as cyber crime, as an AI system failure, or as excluded under both. And whether deepfake response costs, meaning forensics, takedown and communications, are covered anywhere, since they are a separate loss from the money.