CFC folds affirmative AI cyber wording into its financial-institutions suite
CFC consolidated cyber, D&O, errors and omissions, professional liability, crime, employment practices liability and general liability into blended financial-institutions and investment-manager policies, adding wording confirming that “AI as a tool used against the policyholder, in phishing, reconnaissance, or intrusion, falls within existing cyber cover.” As with Beazley's endorsement the same day, the wording does not address whether the institution's own use of AI — in client-facing tools or trading models — is covered elsewhere.
Beazley adds an endorsement affirming that AI-driven cyber attacks are covered — and is silent on the insured's own AI
Beazley issued an AI Clarifying Endorsement stating that AI-driven cyber attacks fall within the existing full-spectrum cyber cover on its cyber and tech errors-and-omissions policies, addressing attacker-side AI such as autonomous phishing and accelerated intrusion. Insurance Business reports the endorsement “says nothing about whether a client's own use of AI, in a chatbot, an internal model, or a vendor's tool, is covered elsewhere in the same policy,” and that the market remains split on whether an insured's own AI use is affirmed, excluded or sub-limited.
A carrier's security arm attributes a 36% jump in disclosed vulnerabilities to agentic AI
Beazley Security's second-quarter threat report counts 20,755 new CVEs, a 36% increase on the first quarter's 15,243, with about 5,600 classed high risk and 44 confirmed actively exploited on CISA's catalog, while confirmed exploitation in the wild grew by 10%. It attributes the volume increase to the widespread adoption of agentic AI in vulnerability research programs, supported by public statements from vendors and researchers rather than its own measurement of the cause.