- BOXX Insurance added affirmative AI and deepfake coverage to Cyberboxx Business, covering social engineering losses and security failures tied to AI-driven impersonation.
- The move contrasts with insurers excluding AI-generated deepfake fraud from standard social engineering cover, as the cyber market splits over how to treat AI-enabled losses.
- Rising fraud and breach costs in Canada are pushing demand for broader cyber cover, while regulators increase scrutiny of cyber underwriting and AI use by P&C insurers.
BOXX Insurance, a global cyber insurtech owned by Zurich Insurance Group, has added affirmative cover for AI and deepfake events inside Cyberboxx Business, its commercial cyber policy.
The endorsement applies to AI-linked social engineering losses and security failures. BOXX said the wording removes uncertainty for customers and brokers, especially where cyber policies have left AI and deepfake losses in a grey zone.
The update puts BOXX on one side of a widening cyber insurance split. Since Jan. 1, 2026, some carriers have started excluding AI-generated deepfake fraud from standard social engineering cover, especially on renewed policies.
Insurers are running into a harder version of insider risk. Security researchers have started calling this profile a synthetic insider.
The label refers to fraudsters who use AI-generated photos, video or voice to impersonate employees, contractors or job candidates, then work their way inside a company network through normal onboarding.
The North Korean remote IT-worker scheme still the clearest example. In that case, operatives used stolen American identities to secure technical jobs at more than 100 US companies. The scheme generated more than $5 mn for the sanctioned regime before the US Justice Department moved against it last year.
Others have moved the other way, rewriting social engineering agreements to include AI-generated impersonation, voice cloning and video deepfakes. BOXX chose the second route.
Coalition adds deepfake response cover to global cyber insurance policies too. Coalition has expanded its cyber insurance offering with a new Deepfake Response Endorsement, now available across its policies worldwide. The move reflects how quickly AI-driven impersonation has shifted from fringe risk to board-level concern.
The endorsement lets brokers offer broader protection as AI tools spread and misuse accelerates. Coalition positions the coverage as a response layer, not a preventative promise, aimed at helping firms recover when trust erodes in public view.
AI-enabled fraud has moved out of theory and into daily loss activity.
BOXX cited Cisco’s Cybersecurity Readiness Index, which found that 86% of US business leaders with cybersecurity duties reported at least one AI-related incident in the previous 12 months.
In Canada, KPMG research found that 81% of Canadian businesses hit by fraud during the past year also faced an AI-enabled attack.
Erik Tifft, global head of underwriting at BOXX Insurance, said AI tools are changing how social engineering attacks work. Threat actors now exploit trusted relationships between employees and executives, he said, leading people to hand over credentials or misdirect payments without a systems breach.
BOXX said the AI and deepfake endorsement works alongside its First Party Each and Every Loss feature. That provision restores the policy’s aggregate limit of liability after each cyber incident, leaving cover available for the rest of the policy term.
Tifft said BOXX’s underwriting is tracking higher claim frequency and the changing nature of cyber and AI-driven threats. He said the company continues to broaden affirmative cover for newer cybercrime methods, whether attackers use systems breaches or advanced social engineering.
The announcement lands in Canada, where BOXX is headquartered and fraud losses have risen fast. The Canadian Anti-Fraud Centre said Canadians lost about $643 mn to fraud in 2024, up nearly 300% since 2020. The agency also warned that only a small share of fraud incidents get reported.
A separate RBC poll found that 81% of Canadians feel a new scam appears almost every week. Another 87% said it is getting harder to tell whether an online ad is genuine.
Regulators are watching the same risk shift. The Office of the Superintendent of Financial Institutions said its 2026-2027 supervisory priorities include thematic monitoring of cyber insurance underwriting and the use of artificial intelligence in underwriting at selected federally regulated P&C insurers. We think that signals a sharper supervisory focus on AI as both an insured threat and an underwriting tool.
Bill C-8, introduced in 2025 to reintroduce the earlier Bill C-26, would also create mandatory cybersecurity standards and incident reporting rules for critical infrastructure operators. For larger commercial buyers, that framework might shape how insurers assess AI-linked cyber exposure and data controls.
See Beinsure Infographics:









