Beazley

3 items · Markets 3 · all entities

CFC folds affirmative AI cyber wording into its financial-institutions suite

CFC consolidated cyber, D&O, errors and omissions, professional liability, crime, employment practices liability and general liability into blended financial-institutions and investment-manager policies, adding wording confirming that “AI as a tool used against the policyholder, in phishing, reconnaissance, or intrusion, falls within existing cyber cover.” As with Beazley's endorsement the same day, the wording does not address whether the institution's own use of AI — in client-facing tools or trading models — is covered elsewhere.

Self-reported, untestedInsurance Business (reporting CFC) ↗ ·

Beazley adds an endorsement affirming that AI-driven cyber attacks are covered — and is silent on the insured's own AI

Beazley issued an AI Clarifying Endorsement stating that AI-driven cyber attacks fall within the existing full-spectrum cyber cover on its cyber and tech errors-and-omissions policies, addressing attacker-side AI such as autonomous phishing and accelerated intrusion. Insurance Business reports the endorsement “says nothing about whether a client's own use of AI, in a chatbot, an internal model, or a vendor's tool, is covered elsewhere in the same policy,” and that the market remains split on whether an insured's own AI use is affirmed, excluded or sub-limited.

Self-reported, untestedInsurance Business (reporting Beazley) ↗ ·

A carrier's security arm attributes a 36% jump in disclosed vulnerabilities to agentic AI

Beazley Security's second-quarter threat report counts 20,755 new CVEs, a 36% increase on the first quarter's 15,243, with about 5,600 classed high risk and 44 confirmed actively exploited on CISA's catalog, while confirmed exploitation in the wild grew by 10%. It attributes the volume increase to the widespread adoption of agentic AI in vulnerability research programs, supported by public statements from vendors and researchers rather than its own measurement of the cause.

Self-reported, untestedBeazley Security ↗ ·