Is Your Business Ready for the AI Cyber Risk No One Is Talking About?
- Toby Hartman

- Jun 21
- 6 min read
Artificial intelligence is changing how businesses operate, and how criminals attack them. For business owners who already carry a cyber liability policy, the good news is that most modern policies are built to respond to a wide range of cyber events, including AI-related ones. But coverage alone is not a plan, and the pace of AI-driven threats is outrunning the pace at which most businesses are updating their internal practices.
Whether you currently carry a cyber policy or are on the fence about purchasing one, this post breaks down the real risks, real claims scenarios, and the practical steps you can take to protect your business.
The Four AI-Driven Cyber Risks Every Business Should Understand
1. AI-Enhanced Phishing and Social Engineering
Criminals are now using AI to craft phishing emails that are nearly indistinguishable from legitimate communications. We are not talking about the broken-English scam emails of ten years ago. Today, an employee can receive what looks like a perfectly written message from the CEO directing them to wire funds to a vendor, complete with the right tone, context, and urgency. By the time someone realizes the request was fraudulent, the money is gone.
Claims scenario: An accounts payable employee receives an email that appears to be from the company's owner, referencing a real ongoing project, and instructs them to wire $47,000 to a new vendor account. The employee complies. The wire cannot be reversed. The business files a claim under their cyber policy's Funds Transfer Fraud coverage, only to discover that coverage requires a callback verification procedure that was never followed.
The lesson: Funds Transfer Fraud coverage typically requires a documented, secondary verification step before any wire is executed. If your team does not have that protocol in writing and in practice, you may not be covered when you need it most.
2. AI-Driven Malware and Ransomware
Threat actors are using AI to build faster, more adaptive malware. Ransomware attacks that previously took months to develop and deploy can now be engineered and launched in a fraction of the time. The financial impact extends well beyond the ransom itself. It includes data restoration costs, forensic investigation, legal counsel, breach notification, and business interruption losses while systems are offline.
Claims scenario: A regional manufacturing company has its systems encrypted by ransomware on a Thursday morning. By Friday, it cannot access production schedules, customer orders, or payroll. The ransom demand is $200,000 in cryptocurrency. Even after paying, full recovery takes 18 days. Total costs including forensics, ransom, lost revenue, and notification exceeded $400,000.
What a cyber policy typically covers: Network security, data restoration, business interruption, and breach response costs are commonly covered under a well-structured cyber policy, subject to your specific terms and deductibles.
What it may not cover: Government-imposed fines and penalties from regulatory bodies are generally excluded. The coverage protects your business losses, not the regulatory consequences.
3. AI-Generated Content and Privacy or Intellectual Property Claims
Employees are increasingly using AI tools to draft marketing copy, summarize documents, and generate operational content. What many businesses have not considered is the liability exposure when that content inadvertently includes someone else's personal data or infringes on intellectual property.
Claims scenario: A marketing team member uses an AI tool to draft website copy. The tool produces text that closely mirrors a competitor's copyrighted material. A claim is filed alleging intellectual property infringement. The business faces legal defense costs regardless of whether the claim has merit.
Coverage note: Depending on the policy form and coverages purchased, media liability and privacy liability endorsements may respond to these types of claims. This is worth reviewing with your agent, especially if your team is actively using AI for content creation.
4. Employees Entering Sensitive Data Into Consumer AI Platforms
This is the scenario we are seeing most frequently right now, and it is the one that catches businesses off guard because it does not look like a cyberattack. It looks like a productive employee getting work done faster.
When an employee pastes customer information, financial records, or any other sensitive data into a consumer-grade AI tool like ChatGPT or Claude, that data is being transmitted to a third-party system. For businesses in regulated industries like healthcare, financial services, and legal, this can create significant regulatory exposure independent of any external hack.
Claims scenario (healthcare): A billing coordinator uses a free ChatGPT account to help summarize patient records for an insurance appeal. The AI vendor's standard consumer terms do not include a Business Associate Agreement. Months later, during a routine compliance review, this practice is identified. The organization faces a potential HIPAA violation, not because of a hacker, but because of an employee trying to be efficient.
For all businesses: Even outside regulated industries, pasting customer lists, employee data, financial projections, or proprietary processes into unapproved AI tools creates data exposure that most businesses have not accounted for in their risk management planning.
Coverage challenge: Cyber insurance responds to covered events. A self-inflicted data exposure caused by an employee's use of an unauthorized tool may face coverage challenges depending on how the claim is presented. More importantly, the regulatory exposure from these incidents is often excluded from coverage entirely.
If You Have a Cyber Policy: Six Steps to Strengthen Your Position
Having a cyber policy is the right foundation. The following steps help ensure that coverage actually responds when you need it and that you are not creating gaps through internal practices.
1. Establish a Written AI Acceptable Use Policy: Define which AI tools are approved, by whom, and for what purposes. Explicitly prohibit the entry of sensitive business, customer, or employee data into non-approved platforms. This document matters both for internal accountability and in the event of a claim.
2. Verify Data Agreements for Any AI Tools in Use: For businesses in regulated industries, confirm whether your AI vendors have executed the required data agreements (such as a Business Associate Agreement under HIPAA). If not, either obtain one or restrict the use of that platform for work involving sensitive data.
3. Implement a Wire Transfer Verification Protocol: Require a secondary callback to a known, verified number before any wire transfer or significant payment is authorized, regardless of how convincing the request appears. This is not just good practice; for many cyber policies, it is a coverage condition.
4. Require MFA for All Business Systems: Multi-factor authentication is consistently the single most effective control for preventing unauthorized access. Many cyber carriers now require it as a condition of coverage. If it is not already in place, it should be.
5. Conduct AI-Specific Employee Training: General cybersecurity awareness is no longer sufficient. Employees need explicit, practical guidance on the risks of AI tools, particularly around sensitive data handling, AI-generated phishing, and deepfake voice and video scams. The threat has evolved; the training needs to as well.
6. Review Your Social Engineering and Funds Transfer Fraud Sublimits: These coverages are often purchased as endorsements with limits that are separate from, and lower than, your primary cyber limit. Given the increasing sophistication of AI-driven fraud, now is a good time to evaluate whether those sublimits are adequate for your business.
If You Do Not Have a Cyber Policy: How to Manage Your Risk
Purchasing a cyber policy is the most efficient way to transfer financial risk associated with cyber events. But if coverage is not currently in your budget or you are still evaluating it, the following controls will meaningfully reduce your exposure.
Control what enters your systems and what leaves them. Implement clear policies around data classification and approved tools. Not every employee needs access to every system, and not every AI tool is appropriate for every use case.
Make verification a reflex, not an afterthought. Require a second set of eyes, or a phone call to a known contact, before any significant financial transaction is executed via email instruction alone.
Back up everything, and test those backups. Ransomware is far less catastrophic when you can restore from a clean, recent backup. Off-site, air-gapped backups are the standard recommendation. Test them regularly.
Know your regulatory obligations before an incident forces you to learn them. Depending on your industry and the type of data you handle, you may have notification obligations in the event of a breach. Understanding these obligations in advance puts you in a far better position than discovering them during a crisis.
Document your controls. If a claim does arise, demonstrating that you had reasonable safeguards in place matters, both for any coverage discussion and for any regulatory review.
The Bottom Line
AI is not going away, and neither is the liability it creates. The businesses that navigate this landscape well are not necessarily the ones with the most sophisticated technology. They are the ones that have taken the time to understand their exposure, put reasonable controls in place, and made sure their insurance coverage actually matches the risks they face.
If you have questions about how your current cyber policy responds to AI-related incidents, or if you are considering whether cyber coverage makes sense for your business, we are happy to walk through it with you. This is exactly the kind of conversation we are built for.
Toby Hartman, MM Insurance Associates




Comments