A finance employee receives an urgent video call from a familiar executive. The face, voice and mannerisms appear genuine. The payment instructions are not. AI-generated impersonation can make an old social-engineering scheme dramatically more convincing—and insurance coverage should never be assumed.

The important warning

Some cyber and commercial crime policies may cover a qualifying loss involving fraudulent instructions, impersonation or funds-transfer fraud. Others may restrict the loss through definitions, exclusions, authentication conditions or a small social-engineering sublimit. A policy can also respond to certain incident-response expenses while providing little or no reimbursement for the transferred money itself.

There is no single standard cyber form and no universal market rule that all policies renewed after January 1, 2026 exclude deepfake fraud. Carrier forms and endorsements are changing at different times. The practical lesson is still urgent: a renewal should be reviewed for AI and deepfake language before a loss—not after one.

Why the coverage question is complicated

A deepfake is the method used to deceive the employee, but the resulting loss might be analyzed under several different insuring agreements. Depending on the facts and wording, the relevant section could be social engineering, fraudulent instruction, funds-transfer fraud, computer fraud, cybercrime, incident response or commercial crime.

The details matter. Was a computer system compromised, or was an authorized employee persuaded to send money? Did the instruction arrive by email, voice, video or a combination? Did the employee follow the required call-back or dual-authorization procedure? Did the policy define a covered communication broadly enough to include synthetic audio or video?

Policy language to examine

  • AI and deepfake exclusions: Look for exclusions or limitations referring to artificial intelligence, synthetic media, manipulated content, impersonation or fraudulent instructions.
  • Trigger definitions: Confirm whether “social engineering,” “fraudulent instruction” and “funds-transfer fraud” extend beyond email and written communications.
  • Voluntary transfer exclusions: Determine whether an employee-authorized payment is excluded or restored through an endorsement.
  • Sublimits and deductibles: Social-engineering protection may be far below the policy’s headline cyber limit and may carry a separate retention.
  • Verification conditions: Coverage may depend on dual approval, call-back procedures, multifactor authentication or other controls represented in the application.
  • Other insurance: Review how the cyber policy coordinates with commercial crime, fidelity and financial-institution coverage.

Ask direct questions at renewal

Do not rely only on a coverage summary. Ask the underwriter to identify the exact form and endorsement that would address an employee transferring funds after receiving a convincing AI-generated voice or video instruction. Request the applicable limit, retention, conditions and exclusions in writing, then compare the response with the issued wording.

Some insurers are introducing affirmative AI or deepfake endorsements, which shows why policy comparison matters. Affirmative language can clarify selected protections, but it does not automatically mean every kind of deepfake-related financial loss is covered.

Controls remain part of the insurance strategy

  • Require independent call-back verification using a trusted number for every unusual payment request.
  • Use dual authorization and transaction limits for wire and ACH transfers.
  • Create an internal code word or verification process for urgent executive instructions.
  • Train employees to treat voice and video as potentially spoofable.
  • Document the controls accurately on insurance applications and retain evidence that they are followed.

The broker takeaway

Deepfake fraud is not simply a new label for an automatically covered cyber loss. It can sit at the intersection of cyber, crime, social-engineering and control-based conditions. Peloton recommends a form-level review that tests the policy against a realistic deepfake payment scenario and identifies any gap before renewal.

Further reading

Reuters: Real insurance coverage for increasing AI deepfake risks

Coalition: AI and deepfake-related cyber coverage information

Insurance note

This article is for general informational purposes only and is not a promise of coverage or legal advice. Coverage depends on the policy language, facts, exclusions, conditions and carrier underwriting. The issued policy controls.