Commercial cyber policies have historically drawn a hard line around social engineering losses: if a human was deceived rather than a system breached, coverage was sublimited or absent. AI-generated deepfakes make that line harder to hold. A synthetic audio clip of a CFO authorizing a wire transfer is a social engineering attack, but it is also, arguably, a technical fraud. BOXX Insurance, a global cyber insurtech within Zurich Insurance Group, has announced affirmative coverage for AI and deepfake-related events, covering both social engineering and security failures, inside its commercial policy, Cyberboxx Business.

The coverage problem deepfakes created

The mechanism behind social engineering losses is identity impersonation: an attacker convinces an authorized person to take an action, usually a payment or credential handover, by appearing to be someone trusted. Policy language written a decade ago tied coverage triggers to unauthorized system access. An employee voluntarily wiring funds to a fraudster does not meet that trigger. Carriers have patched this with endorsements and sublimits, but consistent, affirmative first-party coverage for the category has remained uneven across the market.

Deepfakes sharpen the problem. Voice and video synthesis now allows attackers to manufacture the appearance of a trusted authority at low cost. The loss mechanism is the same as older social engineering fraud; the persuasion tooling is not.

What affirmative coverage means in practice

In insurance, "affirmative" is a technical term. It means the policy explicitly names the peril as covered, rather than leaving the insured to argue that the loss was not excluded. The distinction matters at claims time: exclusion-based ambiguity is where disputed social engineering losses have historically stalled. BOXX's decision to add affirmative language to Cyberboxx Business removes that ambiguity for commercial policyholders on the named categories.

Where this sits in the stack

BOXX operates as a cyber-specialist insurtech inside a large incumbent carrier group, Zurich Insurance Group. That backing matters for the capacity and reinsurance depth behind any new peril class the policy takes on.

The specific unit that drives the economics here will be claims frequency on AI-enabled social engineering events. That number does not exist yet in any public loss study. Carriers that define the policy language before loss data matures set their own terms on the category; those that wait negotiate against that language later.

Related reading