In February 2024, a finance employee at Arup, the engineering firm behind the Sydney Opera House and London’s Shard, joined a video call with the company’s UK-based chief financial officer and several colleagues to authorise a confidential transaction. Everyone on the call looked and sounded right. Nobody on the call was real. The “CFO” and every other participant were AI-generated recreations, built from publicly available footage, and by the time the employee grew suspicious and rang headquarters to confirm, HK$200 million (roughly $25.6 million) had already left the building across fifteen transfers. Arup told investigators it never got the money back.

Most coverage of that case treated it as a cybersecurity cautionary tale. It is more usefully read as a governance problem, and the part that should worry a chief executive isn’t the fraud itself. It’s the question that follows: would this have been covered, and by whom would that decision actually have been made? Increasingly, the answer to corporate security decisions of this kind is being made not by boards, not by regulators, and not even by chief information security officers, but by underwriters at Chubb, Beazley, and a handful of Lloyd’s syndicates, working from actuarial models that AI is now breaking in two different directions at once.
The quiet transfer of authority
Ask any CISO what actually determines the shape of their security architecture and, off the record, many will tell you it isn’t the national cybersecurity framework, or the board’s stated risk appetite. It’s the cyber insurance renewal questionnaire. Multi-factor authentication everywhere, endpoint detection and response on every device, segmented and immutable backups, privileged-access management: these have become underwriting prerequisites long before they were universal regulatory requirements. Fail to tick the boxes and a company either can’t buy coverage or pays a punitive premium. That is a form of regulation, exercised by private capital, with no public rulemaking process, no appeal mechanism, and terms that can be rewritten at every annual renewal based on the insurer’s claims experience rather than the client’s actual risk profile.
This would be a defensible, even efficient, arrangement if the pricing behind it reflected reality. It increasingly doesn’t. Lockton’s underwriting data shows global average cyber premiums fell by roughly 11 percent in 2025, even as claim frequency and severity both climbed over the same period, according to Moody’s analysis of the market. That is not a signal of improving risk. It’s a signal of an oversupplied, intensely competitive insurance market chasing premium volume in a specialty line that still represents under 1 percent of global property and casualty premium, even as the global cyber insurance market itself is projected to roughly double from $15.3 billion in 2024 to over $30 billion by 2030. Underwriters are pricing for a threat environment that is, structurally, already out of date the moment the policy is signed, because generative and agentic AI have compressed attack timelines from weeks to hours and made deepfake-enabled social engineering, like the Arup call, cheap and repeatable at a scale actuarial tables built on historical loss data were never designed to capture.
Why the war exclusion is the wrong argument to be having
For a decade, the industry’s answer to catastrophic, state-linked cyberattacks has been the war exclusion: language borrowed from marine and property insurance that lets an insurer deny a claim if the loss stemmed from an “act of war.” Insurers tried this on Merck after the 2017 NotPetya attack, a Russian-linked worm that spilled out of Ukraine and cost the pharmaceutical giant roughly $700 million in disrupted manufacturing and lost sales. Merck’s insurers argued the malware’s presumed state origin made it warlike and therefore excluded. A New Jersey court disagreed in 2022, an appellate panel upheld that view, and the parties settled confidentially in early 2024, with Merck effectively winning the principle that “state-linked” does not automatically mean “excluded.”
That case forced Lloyd’s to rewrite the rulebook. The market’s newer LMA5567A and 5567B clauses, refined again through a market bulletin during 2026, abandon the attempt to police attribution and instead ask a narrower, more mechanical question: did the attack cause “major detrimental impact” to a sovereign state’s essential services, and were the insured’s own systems physically located inside that state? Under this framing, a company in Mumbai or Chicago hit by collateral damage from a Russia-linked worm targeting Ukrainian infrastructure stays covered, even though the operation is unambiguously state-backed.

That should reassure executives, but it exposes the real fragility underneath. The entire exclusion architecture, old and new, assumes insurers can meaningfully sort attacks into “criminal” and “state” buckets. AI is dissolving that distinction from the inside. Leaked and commercially available offensive AI tooling now lets financially motivated ransomware crews operate with the reconnaissance speed and social-engineering sophistication that used to be the signature of state intelligence services. When a criminal syndicate’s AI-orchestrated intrusion is functionally indistinguishable from a nation-state one, attribution stops being a meaningful underwriting variable, and insurers know it. Expect the next round of policy language to move even further from “who did this” toward “what happened,” which sounds like progress for policyholders until you notice it also gives underwriters a cleaner, more defensible basis to dispute claims on impact grounds instead.
India’s version of the same mismatch
India illustrates a distinct version of this problem, because its regulatory stick is tightening faster than its insurance safety net is growing. The Data Protection Board became operational in late 2025, and the Digital Personal Data Protection Act’s penalties, up to ₹250 crore for security failures that lead to a personal data breach, are no longer theoretical. CERT-In’s six-hour incident reporting mandate, and SEBI’s equivalent requirement for regulated financial entities under its 2024 cyber resilience framework, mean Indian companies now face some of the shortest disclosure windows anywhere in the world. Deepfake-enabled fraud targeting Indian businesses and financial institutions has reportedly grown more than fivefold since 2019, with projected losses in the tens of thousands of crores annually.
Set against that is a domestic cyber insurance market worth an estimated $752 million in 2025, tiny relative to the exposure it is meant to absorb, even with projected annual growth above 25 percent through the next decade. Global insurers largely underwrite Indian corporate risk out of London and Singapore, applying war and state-attribution exclusions calibrated to European and American loss experience, with limited sensitivity to India’s specific threat landscape, from state-linked activity in the region to the sheer scale of deepfake-driven financial fraud. An Indian conglomerate with global operations can find itself simultaneously facing among the world’s toughest breach-penalty regimes and among the world’s thinnest, most externally priced insurance backstops for the AI-driven fraud most likely to trigger those penalties.
What this means for the people who sign off on renewals
The practical implication isn’t “buy more coverage,” it’s that the insurance renewal conversation has stopped being a procurement exercise and become a governance one. Boards that treat the cyber policy as a line item, rubber-stamped by the CFO once premium and limits look reasonable, are outsourcing a meaningful share of their security architecture and their claims-dispute exposure to an underwriter whose incentives shift with the market cycle, not with the company’s actual threat model. The better discipline is to have the CISO and general counsel walk the board through the exclusion language itself, particularly how “impact” and “essential services” are now defined, and to stress-test whether a plausible AI-enabled fraud or intrusion scenario would fall inside or outside that language before it happens, not after.
The Arup fraud succeeded not because anyone lacked a firewall, but because a human being trusted a video call more than a verification protocol. No insurance policy, however well written, fixes that. What a well-understood policy does is tell a board, in advance, exactly which version of the next AI-enabled attack it is actually financially prepared for, and which version it has silently, unknowingly, agreed to absorb itself.



