Beazley, a specialist insurer with a large global cyber insurance business, has confirmed AI-affirmative coverage for cyber losses, giving policyholders greater clarity when artificial intelligence contributes to an attack.
The decision comes as cyber insurers examine whether existing policy structures remain suitable for AI-enabled attacks with the potential to produce large aggregated losses.
Rapid adoption of generative and agentic AI has increased pressure on carriers to state how their policies respond when attackers use AI during intrusion, social engineering or other malicious activity.
Under Beazley’s approach, cyber losses remain covered when artificial intelligence contributes to an insured incident, subject to the policy’s existing terms. The company said its affirmative wording expressly addresses AI-related risks already included within its cyber coverage rather than leaving policyholders dependent on interpretation after a loss.
The announcement addresses a longstanding source of uncertainty for businesses buying cyber insurance.
Insurers have spent years assessing how established policy language applies to AI-related events, while disputes involving artificial intelligence have started reaching courts in the US and other markets.
RAND researchers examined the issue in a recent report and found considerable uncertainty around insurance treatment of AI exposures. One question is whether artificial intelligence primarily increases the frequency or severity of risks insurers already understand, or introduces exposures requiring separate insurance structures.
RAND described an emerging debate over whether AI adds intensity to existing insurance risks or produces genuinely different forms of loss. That distinction matters for underwriting because insurers price established cyber events differently from exposures without substantial claims histories.
Silent AI coverage has therefore become an important issue across cyber insurance.
A policy written without an explicit AI exclusion might respond to a covered data breach or system compromise even when an attacker used AI, leaving insurers exposed to losses they didn’t separately price as artificial-intelligence risk.
Insurers are beginning to state their positions more directly. Beazley’s affirmative approach marks one response, while several other large cyber carriers have also said AI involvement doesn’t automatically change how they treat an otherwise covered cyber event.
QBE, one of the major international cyber insurers, said it continues supporting cyber claims involving artificial intelligence. Serene Davis, QBE’s global head of cyber, described AI as an amplifier of existing cyber exposure rather than an entirely separate class of risk.
Under QBE’s main cyber policies, a system compromise or data breach receives the same coverage treatment regardless of whether artificial intelligence contributed to the attack. The insurer has pushed back against suggestions that it is withdrawing from AI-related exposure.
AIG has taken a similar position regarding current coverage intentions. The insurer said it has no immediate plans to introduce restrictions specifically targeting AI-related claims, despite broader insurance-industry work on policy language addressing generative AI.
One AIG subsidiary responded to Insurance Services Office filings involving updates to general liability forms. Those ISO changes include generative AI exclusions, though AIG said it isn’t currently seeking to adopt those exclusions within its own business.
The distinction between general liability and cyber insurance matters. AI-related losses span several insurance classes, and an exclusion developed for one policy type doesn’t automatically determine how another responds to a cyberattack involving artificial intelligence.
Boxx Insurance has also extended its wording around AI-related attacks. Its policies have historically covered social-engineering losses and failures involving the security of an insured computer network.
As AI-enabled fraud became more prominent, Boxx added wording addressing AI-driven social engineering and security failures. Erik Tifft, the company’s global head of underwriting, said the insurer’s cyber products were developed to respond to those forms of loss rather than exclude them because artificial intelligence played a part.
These positions arrive as attackers use generative AI to increase the speed and volume of cyber operations. Criminal groups and state-linked actors have incorporated AI into reconnaissance, social engineering and other stages of intrusion activity, raising concerns about the number of attacks security teams need to process.
For insurers, scale presents a different problem from a single AI-assisted incident. A tool that lowers the cost of attacking thousands of companies at once creates aggregation concerns because many insured businesses might suffer losses during the same event.
Frontier models and autonomous agents add another layer. Agentic systems execute sequences of actions with less direct human involvement, increasing the possibility of faster attacks or unexpected behaviour across interconnected services.
The resulting insurance question isn’t limited to whether AI appears somewhere in an incident. Carriers also need to understand how AI changes loss frequency, severity and correlation across multiple insured companies before setting prices or deciding how much risk to retain.
Earlier reports suggested some insurers were considering limits for certain AI-related losses. The Financial Times reported in April that carriers including Beazley had examined potential payout caps as the market assessed the possibility of unusually large losses linked to advanced AI.
Beazley’s latest announcement gives policyholders a clearer position on its cyber product. AI involvement alone doesn’t remove coverage for a cyber event that otherwise falls within the policy terms.
The company has also been developing AI-specific wording across other insurance products. Beazley has said it is revising cyber, technology and professional-services coverages to address AI use more explicitly, alongside underwriting questions intended to identify how clients deploy the technology.
Competition is also influencing insurer responses. Cyber-focused InsurTech companies have entered the market with lower operating costs and technology-driven underwriting models, putting additional pressure on established carriers to make coverage language easier for brokers and customers to interpret.
For corporate insurance buyers, affirmative wording reduces uncertainty before a claim occurs. Security teams increasingly deal with attacks where AI forms one element of a familiar cyber event, rather than a separate event with an obvious artificial-intelligence label.
Beazley’s move doesn’t remove the wider accumulation problem facing cyber insurers.
A large AI-enabled event affecting many insured organisations at once still presents difficult questions around pricing, reinsurance capacity and the amount of loss the private insurance market is prepared to absorb.
It does provide a clearer answer at the individual-policy level. Where a covered cyber incident involves an attacker using AI, Beazley intends its affirmative wording to state directly that artificial intelligence doesn’t by itself take the loss outside cyber coverage.









