Most small business owners think about cyber insurance the same way they did five years ago: as protection against a data breach or ransomware attack. Something that could happen, but probably to a bigger target.
But today’s biggest threats don’t always look like cyberattacks. They can look like a phone call from your bank, an email from your CEO, or a video meeting with a trusted vendor.
The person may sound and look real, but the entire interaction could be fake. And many small businesses lack insurance that covers the resulting loss. A cyber policy focused only on data breaches and ransomware may not cover losses when an employee is tricked into sending money to a fraudster.
Keep reading to learn how AI-driven fraud can create gaps between cyber and crime policies and what Maryland business owners should review before their next renewal.

AI-driven fraud is no longer a future concern or a threat limited to large corporations. According to the FBI 2025 Internet Crime Report, AI-attributed fraud crossed into formal crime reporting for the first time last year, with nearly $900 million in documented losses, a figure the FBI itself calls a significant undercount.
One reason these losses are so high is that AI fraud operates differently from the cyberattacks most businesses have prepared for, and it’s much harder to detect. There’s no malware, no system to breach, no network intrusion to trigger an alert.
Instead, fraudsters use convincing emails, cloned voices, and deepfake videos to make a fraudulent request appear legitimate.

AI-driven fraud can take several forms, but each relies on the same strategy: impersonating someone an employee trusts and convincing them to take an action they normally would not.
Phishing is a type of fraud in which someone sends a deceptive email or message to steal information, gain access to an account, or convince the recipient to send money.
Traditional phishing emails were often easier to recognize because they contained poor grammar, unusual formatting, or generic greetings. AI-generated phishing messages can be much more convincing. They may be personalized, grammatically correct, and written to match the tone of a real colleague, executive, or vendor.
These messages can also reference real projects, employees, and business relationships gathered from websites, social media, and other public sources. Phishing attempts increased 202% in the second half of 2024 alone, with credential phishing up 703%.
Deepfake voice fraud, also known as vishing (“voice phishing”), uses a cloned voice to impersonate someone over the phone. A fraudster needs as little as three seconds of audio to copy the voice of a business owner, executive, vendor, or financial contact and use it to request an urgent wire transfer, payment, or account change.
Because the caller sounds familiar, an employee may follow the request without realizing the person on the other end is fake. Vishing attacks with AI voice cloning surged 442% in 2025, and the average enterprise loss per voice fraud attack was approximately $680,000.
The most sophisticated attack, deepfake video fraud, uses AI-generated video to make it appear as if a real person is on camera. And as the technology grows, real-time deepfake videos are being used to target businesses as well.
In 2024, an employee at global engineering firm Arup transferred $25 million after attending a video conference in which every other participant, including the company’s CFO, was a deepfake.
While that case involved a multinational company, small businesses can be especially attractive targets. They often have fewer payment controls, less cybersecurity training, and smaller teams responsible for verifying financial requests. A convincing video call may be enough to bypass the safeguards they have in place.

For Maryland small business owners, the insurance implications of AI fraud can be difficult to spot.
AI-generated impersonation is a relatively new threat, and many cyber and crime policies written before 2024 were created before deepfake voice, video, and email AI fraud became widespread. If you aren’t familiar with how cyber liability coverage is structured, our cyber insurance explainer covers the basics.
The key point here is that the coverage language was built around human social engineering, which can create several gaps in coverage where AI fraud is concerned:
Most social engineering and fraud coverage requires that a loss result directly from the fraudulent act. When a human deceives an employee into wiring money, the chain of causation is clear.
When an AI-generated deepfake is the mechanism of deception, some carriers argue the AI creates an intervening agency between the fraudster and the loss, which, under strict policy interpretation, can break the chain required for coverage.
Courts in multiple jurisdictions are actively litigating this question. According to a cyber policy coverage analysis published in May 2026, policies issued before 2024 fall into one of three categories: covered under existing social engineering language, excluded under a direct loss interpretation, or genuinely ambiguous.
The ambiguity resolves at claim time, which is the worst possible moment to find out where you stand.
Social engineering and funds transfer fraud coverage is almost always sublimited within a cyber policy, often at $250,000 within a $1 million policy.
Given that documented deepfake fraud losses average well above that threshold per incident, the sublimit is frequently the binding constraint rather than the overall policy limit. A business that believes it has adequate cyber coverage may find, after a loss, that the relevant sublimit covers a fraction of the actual damage.
Throughout late 2024 and 2025, a significant portion of the cyber insurance market began adding explicit AI and deepfake exclusions to policy language. ISO exclusions affecting commercial general liability policies took effect in January 2026.
According to Business Insurance reporting, the industry is now moving in two directions simultaneously: some carriers are adding affirmative coverage, others are adding exclusions. The policy you renewed in December 2025 may cover deepfake fraud. The same policy renewed in February 2026 may not.
The only way to know is to read the definitions section of your current policy, looking specifically for language around algorithmic content, AI-generated material, or intervening agency exclusions.
We also know that reviewing policy language can be time-consuming and difficult to interpret. We can help you review your coverage, clarify the wording, and identify any gaps to address before renewal.

As AI-driven fraud has become more common, some insurers have updated their cyber and crime policies to address deepfake impersonation, AI-enabled social engineering, and fraudulent funds transfers more directly.
Coverage still varies widely by carrier, policy form, and endorsement, so newer language does not always mean broader protection.
In 2024, several major cyber insurers introduced AI endorsements that explicitly clarify coverage for AI-driven fraud events, including deepfake-enabled wire transfer fraud and social engineering conducted through AI-generated voice or video.
Coalition incorporated this endorsement into its base active cyber policy in 2025 and later added a deepfake response endorsement covering reputational harm and incident response.
An IAPP's January 2026 analysis shows multiple carriers have now affirmatively stated they will cover AI-driven deepfake attacks under their cyber policies, though policy language varies enough that carrier-by-carrier review matters.
Commercial crime policies, which cover fraud and theft by external parties, have also been updated to address social engineering losses more broadly. The stronger crime policies now include explicit language covering funds transfer fraud initiated through electronic deception, regardless of the mechanism involved.
For small businesses, a well-structured crime policy that addresses both internal and external fraud is an important complement to cyber coverage, not a substitute for it.
A cyber and crime program structured for 2026 risk exposure addresses these specific elements:

The gap between what small business owners assume their cyber policy covers and what it actually covers has never been wider. These three steps will help you identify and start closing any gaps you have, and none of them require buying a new policy:
If those reviews uncover gaps—or you would rather have someone walk through the policies with you—the next step is to speak with an agent who understands how cyber and crime coverage work together.
Gerety Insurance has helped Maryland businesses navigate commercial insurance for more than 30 years. As an independent agency, we compare options from multiple carriers and help clients find coverage that reflects the risks their businesses actually face.
Our team can review your current cyber and crime policies, explain how they may respond to AI-driven fraud, identify potential gaps, and recommend changes before your next renewal.
AI fraud has changed the risks businesses face. Your coverage should reflect those changes before a claim reveals what your policy does not cover.
Have questions about your current cyber or crime coverage? Contact Gerety Insurance to review your policies before your next renewal.