In April 2026, an artificial intelligence coding agent wiped out production databases at PocketOS Software in nine seconds, erasing backups and leaving only a three-month-old copy—with no attack, malware, or ransom demand involved. A report published by Infosecurity Magazine examines how insurance markets are responding to AI-driven losses with contradictory coverage decisions that leave organizations uncertain which policy will pay when AI causes harm. The analysis warns that the same incident can be excluded under one policy, embraced by another, and disputed under a third, creating what the author calls a "hodgepodge" rather than a simple gap.

The FBI recorded $893 million in reported fraud losses enabled by artificial intelligence in the United States last year, according to the report. Deepfakes now account for roughly one in nine fraud attempts globally in 2026, up from 6.5% in 2024. AI-related lawsuits climbed nearly tenfold between 2021 and 2025. In January, ISO—the organization that drafts standard policy language for much of the US insurance market—released its first commercial general liability exclusions tied to generative AI, removing injuries, property damage, and advertising claims caused by AI from coverage. Major carriers are seeking regulatory approval for absolute exclusions on directors and officers and errors and omissions policies that would bar any claim resulting from AI use in any form.

The report notes that leading cyber insurers are moving in the opposite direction, publishing endorsements that affirmatively cover AI-related security failures and clarifying that instructions sent through deepfakes trigger fraud coverage for fund transfers. The $25.6 million loss at Arup, where everyone except the victim was synthetic, is exactly the type of loss this language was designed to cover, the analysis states. However, the report warns that cyber insurance limits for AI are often capped far below headline limits—a tower covering $5 million might answer an AI claim with just $500,000. Some carriers exclude events where one AI failure impacts many customers simultaneously, with an Aon executive quoted as saying the industry can absorb a single $400 million loss but not 10,000 correlated claims from one AI provider error.

The divergence stems from how different insurance lines interpret the same risk, the report explains. Cyber policies assume an unauthorized intruder, but when an organization's own agent deletes records using valid credentials—as happened at PocketOS—there may be no attacker and possibly no coverage trigger. Researchers describe a sliding scale from AI that writes text to AI that executes changes, and policy response becomes less likely the higher up that scale an organization operates. Management liability carriers see litigation risk climbing faster than their ability to price it, while cyber insurers view AI-driven fraud as an evolution of existing social engineering threats they already cover. The timing of ISO's exclusion rollout reflects this urgency—AI-related lawsuits surged as generative tools became widely accessible, and carriers needed language to draw boundaries before claims volume overwhelmed underwriting models.

Organizations should run their worst AI scenario—deepfake wire transfers, poisoned models, agents with excessive access—through their entire insurance program to identify which policy responds first and where two carriers might point at each other, the report recommends. Renewal processes now function as audits focused on AI governance, with sublimits, exclusions, and carve-outs often buried in endorsements that enter quietly. The analysis concludes that AI wording is in year two of development, and until it's tested through claims, the coverage documented endorsement by endorsement is all an organization has. The report closes with a stark reminder: the PocketOS agent left a confession, but insurance policies won't speak for themselves. Coverage exists on paper, but understanding exactly what triggers it remains the policyholder's responsibility—a burden that grows heavier as autonomous systems gain more permissions and the gap between cyber's embrace and management liability's retreat widens.