Beazley's AI Clarifying Endorsement states that AI-driven cyber attacks fall within its existing cyber and tech E&O cover, with no separate limit or premium disclosed, on a Cyber Risks book whose written premium fell 15.4 percent to $524.9 million in the first half of 2026 (Beazley plc, H1 2026 results; Reinsurance News, September 18, 2026). CFC added the same affirmative wording across its financial institutions suite the same week.

"This endorsement makes it clear to our clients that in the event of a cyber attack, AI-driven or otherwise, they are protected," said Alessandro Lezzi, Beazley's Group Head of Cyber Risks (Insurance Times, September 2026). Everywhere else in the commercial program the direction runs the other way: more than 60 property and casualty carriers have filed AI exclusions and regulators have approved over 80 percent of them.

Key Takeaways

  • $318.6 million of net cyber premium is what Beazley kept in H1 2026, down 34.9 percent from $489.7 million, against a 15.4 percent gross decline; the ceded share rose from 21 to 39 percent (Beazley plc, H1 2026 results, computed).
  • 91.7 percent is the Cyber Risks undiscounted combined ratio for the half, from 79.7 percent a year earlier, with renewal rates down 4.3 percent (Beazley plc, H1 2026 results).
  • One in four malicious breaches in IBM's March 2025 to February 2026 sample was AI-enabled, up 56 percent, at an average $6.0 million against a $4.99 million global mean across 602 organisations (IBM, July 29, 2026).
  • 30 percent of aggregate breach cost in that sample therefore sits in the AI-enabled quarter, and an AI-enabled breach runs 29 percent above the $4.65 million implied average for the rest (computed from IBM, July 2026).
  • Zero is what the endorsement says about the insured's own AI, in a chatbot, an internal model or a vendor tool; it addresses AI as the attacker's tool only (Insurance Business, September 17, 2026).

What the Endorsement Affirms and What It Leaves Silent

Beazley's wording answers one question. AI used by an attacker, in deepfake impersonation, generated malware or automated phishing, is a cyber event and the existing full-spectrum cover responds. Insurance Business's reading of the endorsement is that it "addresses one specific gap: attacker-side AI use," and that "cyber policies have spent the past two years quietly absorbing AI risk without ever naming it" (Insurance Business, September 17, 2026). No sublimit, additional premium or effective date was reported.

CFC drew the line in the same place. Its refreshed financial institutions suite, from investment managers to D&O, E&O, crime and cyber, now confirms that "AI as a tool used against the policyholder, in phishing, reconnaissance, or intrusion" sits inside the cyber section, and says nothing about the institution's own use of AI under its professional liability sections (Insurance Business, September 17, 2026).

Lloyd's ran this exercise once before. Market Bulletin Y5258 in July 2019 required every policy to "either exclude or provide affirmative coverage" for cyber, starting with first-party property incepting from January 1, 2020, and Y5277 phased the remaining classes through July 2021 (Lloyd's, January 29, 2020). Silent cyber became a wording decision by mandate. Silent AI is becoming one by carrier choice, and only on the attacker side.

A Clarification Priced at Zero on a Book Cut by a Third

An affirmation with no sublimit does not change the expected loss on a policy that was already paying AI-enabled claims; it removes the option to argue about them. An exposure that sat in the wording as ambiguity is now contracted, and the rate has to carry it explicitly.

IBM's 2026 study gives the size. One in four malicious breaches was AI-enabled, at $6.0 million each against a $4.99 million global average (IBM, July 29, 2026). Solving for the other three-quarters gives $4.65 million, so the affirmed peril costs about 29 percent more per event and accounts for 30 percent of breach cost in the sample.

The book taking that on is being shrunk for inadequate rate. Beazley cut cyber gross premium 15.4 percent in the half and lifted its cession so that net premium fell 34.9 percent; management said "excess competition in some cyber markets" is "driving rates down to where they no longer reflect the escalating risk environment created by AI and geopolitical volatility," and that it "will not follow the market down" (Beazley plc, H1 2026 results). Renewal rates still fell 4.3 percent.

Beazley Cyber RisksH1 2025H1 2026Change
Insurance written premiums$620.3m$524.9m-15.4%
Net insurance written premiums$489.7m$318.6m-34.9%
Ceded share (computed)21%39%+18 pts
Undiscounted combined ratio79.7%91.7%+12.0 pts
Renewal rate change-6.5%-4.3%

Put the two together and the endorsement is a pricing statement as much as a coverage one. Beazley is telling brokers the peril is inside the limit and telling shareholders the market rate does not pay for it, then ceding 39 cents of every premium dollar to reinsurers who now hold an explicitly worded AI exposure too. The company's own results narrative frames the product promise as being "insured whether a cyber breach is human or AI generated" (Beazley plc, H1 2026 results).

The Half of the Risk That Nobody Has Priced

The insured's own AI is the exposure the endorsement does not reach, and it is the one the rest of the market has already rejected. CSIS counts more than 60 P&C carriers filing AI exclusions, including Berkshire Hathaway, Chubb, Travelers and AIG, with more than 80 percent of the filings approved by April 23, 2026; ISO's generative AI exclusion for commercial general liability took effect January 1, 2026, and ISO confirmed on July 10 that it is drafting agentic AI exclusions (CSIS, September 4, 2026). W. R. Berkley has added exclusions to its D&O, E&O and fiduciary forms (The Register, September 18, 2026).

For a policyholder the program now reads three ways. AI used against it is affirmed in cyber. AI used by it is silent in cyber and excluded in general liability. The dedicated products that would fill the middle cap at $25 million to $50 million per insured, as the site set out in its piece on the frontier labs' captives, which leaves the cyber policy as the residual home for whatever AI loss a court declines to call excluded.

That residual is what the affirmation invites. A deepfake that induces a wire transfer is an attack; a chatbot that hallucinates a refund policy is the insured's own model; an agent that is prompt-injected into exfiltrating data is both at once, and the endorsement names only the first. The ISO agentic exclusion being drafted will move the CGL boundary again within the policy year, and each move pushes more of the unnamed middle toward a cyber wording that has just promised, in writing, not to add to the uncertainty.

Further Reading

Sources

  1. Reinsurance News, "Beazley adds affirmative AI cover in cyber and tech E&O policies," September 18, 2026
  2. Insurance Times, "Beazley launches new AI proposition for cyber product," September 2026
  3. Mark Rosanes, "What Beazley's AI cyber endorsement does and doesn't cover," Insurance Business, September 17, 2026
  4. Mark Rosanes, "CFC folds cyber, AI wording into financial institutions suite," Insurance Business, September 17, 2026
  5. Beazley plc, "Results for period ended 30 June 2026," RNS via Investegate
  6. IBM, "IBM Study: One in Four Malicious Breaches are AI-Enabled, Costing Companies $6 Million on Average," July 29, 2026
  7. Gregory C. Allen, "The Insurance Industry's Retreat from AI Threatens to Slow Innovation and Adoption," CSIS, September 4, 2026
  8. The Register, "AI risks make some insurers wary of corporate liability," September 18, 2026
  9. Lloyd's, Market Bulletin Y5277, "Update: Providing clarity for Lloyd's customers on coverage for cyber exposures," January 29, 2020 (referencing Y5258)