BOXX Insurance Adds Affirmative AI and Deepfake Coverage to Cyberboxx Business Policy

Home Opinion CISO Perspective BOXX Insurance Adds Affirmative AI and Deepfake Coverage to Cyberboxx Business Policy
BOXX Insurance Adds Affirmative AI and Deepfake Coverage to Cyberboxx Business Policy, Infosec Federation

BOXX Insurance has added affirmative coverage for AI driven and deepfake related losses to its commercial Cyberboxx Business cyber insurance policy, the company announced on July 22, 2026, confirming that social engineering scams built on voice cloning or synthetic video impersonation are explicitly covered rather than left to claims interpretation. The change matters to risk and security leaders because it removes a gray area that has dogged cyber policies as deepfake fraud shifts from novelty to routine attack technique against finance teams and executives.

What Did BOXX Insurance Change in Its Cyberboxx Business Policy?

According to BOXX Insurance’s announcement, carried by The AI Journal, the insurer added an affirmative endorsement to Cyberboxx Business covering losses tied to AI and deepfake related events, including social engineering and security failures stemming from exploitation of AI tools. Erik Tifft, BOXX’s Global Head of Underwriting, said the update responds to a shift in how criminals now operate: threat actors are exploiting trusted relationships among employee and executive networks, he said, which can result in handing over credentials or misdirecting payments without an actual breach ever occurring.

The endorsement is paired with a feature BOXX calls First Party Each and Every Loss, discussed further below, and BOXX said it reflects a broader push to keep underwriting language current as AI reshapes both attacks and defenses, a theme our 2026 CISO perspective on AI has tracked across the security leadership community.

Why Is Affirmative AI and Deepfake Coverage Necessary Now?

The move follows a wave of deepfake fraud cases in which voice cloning and synthetic video were used to impersonate executives and push through fraudulent payments, a pattern our earlier coverage of SEBI’s advisory on the deepfake \”boss scam\” also documented among listed companies in India. BOXX said in its announcement that 86% of US business leaders with cybersecurity responsibilities reported at least one AI related incident in the past 12 months, and that 81% of Canadian businesses that experienced fraud also faced AI enabled attacks.

Separately, in comments to Insurance Business, Neal Jardine, BOXX’s Chief Cyber Intelligence and Claims Officer, said AI is becoming the new search engine, the new analyst and the new threat actor, and warned that deepfake scams are no longer confined to text. The scariest part of AI driven scams, he said, is that they are not limited to messages, they can sound exactly like someone you know. Jardine pointed to Viking Cloud data showing that 98% of cyberattacks now involve some form of social engineering, and to a Goldman Sachs 2024 survey finding that 29% of insurance companies globally already use AI in their own operations, according to Insurance Business.

Neither outlet disclosed how many claims BOXX has already paid under the previous, non affirmative language, so it is not possible to say how large the coverage gap actually was in dollar terms before this update.

How Does the First Party Each and Every Loss Feature Work?

BOXX said the new AI and deepfake endorsement is coupled with a policy mechanic it calls First Party Each and Every Loss, which reinstates the policy’s Aggregate Limit of Liability after each cyber incident during the policy period rather than letting a single large claim exhaust the available cover for the rest of the term. BOXX framed this as a direct response to the fact that AI driven social engineering and deepfake losses tend to recur, meaning a policyholder hit twice in one year needs the second incident to be covered on the same terms as the first, not paid out of a diminished remaining limit.

This is the kind of structural change that shows up on a renewal quote long before it shows up in a headline, and it is worth board level attention because it affects how much residual risk a company is actually carrying between incidents, not just whether a single loss is covered.

What Should CISOs and Risk Leaders Do With This News?

  • Ask your current cyber insurer, in writing, whether deepfake voice or video impersonation resulting in fraudulent payment or credential disclosure is affirmatively covered, or whether it falls under a broader social engineering sublimit that may cap payouts well below the policy’s headline limit.
  • Check whether your policy’s aggregate limit resets after each incident or is shared across all claims in the term, since a business facing repeat AI enabled fraud attempts could otherwise exhaust cover after the first successful scam.
  • Pair any policy review with the operational controls this class of fraud actually defeats: callback verification on payment changes, out of band confirmation for executive requests, and staff training on the specific tells of voice cloning, an area our analysis of deepfake threats and enterprise readiness covers in more depth.
  • Treat this as one data point in a wider pattern rather than an isolated insurer move. AI enabled social engineering is now showing up across the kill chain, not just at the initial contact stage, a trend we mapped in our review of AI’s reach across the cyberattack kill chain.

Does This Reflect a Wider Industry Shift in Cyber Insurance?

BOXX Insurance, headquartered in Toronto with offices worldwide, is now part of Zurich Insurance Group following an acquisition announced in mid 2025, according to Insurance Business and Zurich’s own newsroom. An insurer of Zurich’s scale backing affirmative AI language in a commercial cyber product is a signal that underwriters increasingly see AI enabled fraud as a defined, quantifiable risk category rather than an edge case to be argued over at claims time. Expect competitors to follow with their own affirmative language or explicit exclusions over the coming quarters, which means the coverage question will not stay static even for companies satisfied with their current policy today.

The shift also lands alongside a broader rethink of how organizations manage AI as an insider style risk, not just an external attack vector, a dynamic explored in our coverage of agentic AI security risk and the insider threat nobody trained for.

What happenedBOXX Insurance added affirmative AI and deepfake coverage to its Cyberboxx Business commercial cyber policy
WhenAnnounced July 22, 2026
Who is affectedCommercial policyholders and broker partners using BOXX’s Cyberboxx Business cyber insurance product
ScaleApplies across BOXX’s cyber book, paired with a First Party Each and Every Loss feature that resets the Aggregate Limit of Liability after each incident
Fix or deadlineNo customer action required; the endorsement applies to current and renewing Cyberboxx Business policies

The Numbers Behind the Rising AI Fraud Risk

The statistics cited by BOXX and Insurance Business, drawn from BOXX’s own data, Viking Cloud and Goldman Sachs, sketch a fast moving risk picture even though they come from different surveys and are not directly comparable in methodology.

Cyberattacks involving social engineering
98%
US leaders reporting an AI related incident
86%
Canadian fraud victims also hit by AI enabled attacks
81%
Global insurers already using AI (2024)
29%

Read together, the numbers describe an industry where social engineering is already the dominant attack path, AI has made it more convincing, and insurers are only beginning to build products that match the frequency of the problem rather than treating each incident as a one off exception.

Frequently asked questions

What did BOXX Insurance change in its cyber policy?

BOXX Insurance added an affirmative endorsement to its Cyberboxx Business commercial cyber policy that explicitly covers losses from AI driven and deepfake related events, including social engineering and security failures caused by exploitation of AI tools, rather than leaving such claims open to interpretation.

Who is Erik Tifft and what did he say about the change?

Erik Tifft is BOXX Insurance’s Global Head of Underwriting. He said threat actors are exploiting trusted relationships among employees and executives, which can result in handing over credentials or misdirecting payments without any actual system breach occurring, according to BOXX’s announcement.

How big is the AI enabled fraud problem according to BOXX?

BOXX Insurance said 86% of US business leaders with cybersecurity responsibilities reported at least one AI related incident in the past 12 months, and 81% of Canadian businesses that experienced fraud also faced AI enabled attacks, according to the company’s announcement.

Leave a Reply

Your email address will not be published.