- A payment made because a cloned voice impersonated somebody you trust is a funds transfer fraud or social engineering loss. Your AI did nothing. Somebody else's did. That puts it in crime or cyber crime cover, not in professional indemnity and not in AI liability cover.
- Funds transfer fraud cover is usually an optional extension with its own sublimit, which can be a small fraction of the headline limit. The schedule tells you whether you bought it. The brochure does not.
- The condition that decides most of these claims is verification. If the wording requires the instruction to have been confirmed through a separate channel and it was not, the policy may not respond however convincing the voice was.
- The EU AI Act obliges whoever deploys AI to make a deepfake to disclose that it is artificial, and has since 2 August 2026. A fraudster will not comply, and the Act gives the victim no claim. Bank recall, police and your policy are the routes to the money.
- The control that costs nothing is a written call-back rule: every new payee, changed bank detail or urgent transfer is confirmed on a number the business already holds. A voice is not an identity.
First, what actually happened in insurance terms
Strip the technology out and look at the shape of the loss. A person in your business, acting in good faith, was deceived into sending your money to a criminal. That shape is old. It used to be a forged letter, then a spoofed email from the managing director, then a phone call from somebody claiming to be the bank. The voice clone is a new and much better disguise for the same trick, and insurance has a name for the trick: social engineering, or funds transfer fraud, depending on which wording you are reading.
This matters because the word AI in the story pulls people toward the wrong policy. AI liability cover, and the affirmative AI wordings that have appeared in the last two years, are built for the outbound case: your AI system does something wrong and somebody suffers. We set out that distinction at there are two AI risks and your insurance is probably only about one. A voice clone fraud is the purest possible example of the inbound case. You deployed nothing. An attacker used a tool against you, and the loss is your own money, not somebody else's claim.
So the question is not whether you have AI insurance. The question is whether the policy you have for being defrauded, if you have one, extends to being defrauded this way.
Which policy is built for this
Two candidates, and for many small businesses only one of them exists.
Commercial crime cover. Traditionally this protected a business against dishonest employees and against theft. Over the last decade many crime wordings have added a social engineering or funds transfer fraud extension, precisely because the biggest losses stopped being an employee with a hand in the till and started being an outsider who talks a good employee into paying. If you have a crime policy, this extension is where to look, and it is very often optional, separately priced and sublimited.
The cyber crime section of a cyber policy. This is where most small businesses will actually find the cover, if they have it at all. Cyber policies commonly carry a section for funds transfer fraud, cyber crime or social engineering, and it does the same job as the crime extension: it responds when your business is tricked into transferring money by a fraudulent instruction. Again it is frequently an add-on, with a sublimit that can sit a long way below the limit printed on the front of the schedule.
Two policies that will almost certainly not respond are worth naming, so nobody wastes a week on them. Professional indemnity answers claims by other people against you for your professional work. Nobody is claiming against you here; you lost your own money. An AI liability wording answers a failure of an AI system you use. No system of yours failed. The boundary between cyber and liability cover is set out at do I need AI agent insurance if I have cyber insurance, and this scenario sits firmly on the cyber side of it.
The sublimit, and why the headline number is not your number
When a business says it has a million of cyber cover, it usually means the policy limit. The funds transfer fraud section, where it exists, very often carries its own much smaller limit. It is not unusual for that sublimit to be a small fraction of the headline, and for a single fraudulent payment to exceed it. The reason is simple: an insurer can model the cost of a data breach with some confidence and cannot easily model how much money your bookkeeper is able to send in one afternoon.
So the first thing to do, before anything else in this article, is to find the schedule and read three lines: whether a funds transfer fraud, social engineering or cyber crime section is included at all; what its limit is; and what excess applies to it. If those lines are not there, you do not have the cover, whatever the brochure implied. Our guide to reading exclusions is at the AI policy exclusions guide, and the same discipline applies to sublimits, which are exclusions with a number attached.
The verification condition, which decides most of these claims
This is the part of the article that is worth the most money, and it is a condition rather than an exclusion, which is why people miss it.
Many wordings that cover a fraudulent instruction attach a condition: the instruction must have been verified through a separate channel before the payment was made. The classic form is a call back to a telephone number the business already held for the person, rather than the number in the message, before any new payee is set up or any bank detail is changed. Some wordings require this for every transfer above a threshold. Some require documented procedures to exist and to have been followed.
Now apply that to the Friday afternoon story. The bookkeeper received a voice note that sounded like the founder. She did not call the founder back on his known number, because why would she, she had just heard him. The payment went out on the strength of the voice alone. Under a wording with a verification condition, the claim may fail on that fact, and it will fail regardless of how good the clone was, because the condition is about what you did and not about how convincing the fraud was.
The uncomfortable truth in that is also the useful one. The condition is entirely within your control before the event and entirely outside your control afterwards. It is the cheapest insurance-related decision a small business can take, and we come back to it at the end.
Does anyone cover deepfake fraud by name?
Yes, and it is worth knowing about as a marker of where wordings are going, not as a recommendation, because whether your policy has anything similar is a question only your policy can answer.
Coalition, a cyber insurer, added an affirmative artificial intelligence endorsement to its US surplus and Canada cyber policies, dated 26 March 2024. It does exactly two things. It extends the security failure and data breach definitions to an AI security event, and it extends the funds transfer fraud trigger to a fraudulent instruction transmitted through the use of deepfakes or any other artificial intelligence technology. That second limb is the voice clone scenario written into a policy in plain words. The same insurer separately announced a deepfake response endorsement, providing technical analysis by a deepfake forensics firm with a written report, legal work to have the deepfake taken down, and crisis communications support, which its own announcement lists as available in the United Kingdom, Germany, Denmark, Sweden and France as well as the United States, Canada and Australia. Both announcements were read on the insurer's own site on 14 September 2026, and neither states a limit.
Two things follow for a European small business. The express funds transfer extension is, on the insurer's own description, a North American product, so it tells you what is possible rather than what you can buy locally. And the existence of a separate response endorsement, covering the cost of dealing with a deepfake rather than the money lost to one, is a reminder that these are two different losses. Recovering the money is one question. Proving to a customer or a platform that the clip of you was fake is another, and it has its own cost. The enterprise reading of which policy answers each is at agentinsured.eu, on which policy responds to an AI-forged payment instruction.
What the EU AI Act does, and does not do, for you
People reach for the AI Act at this point, because it is the AI law, and it is worth being precise about what it offers a fraud victim, which is nothing.
The Act contains a transparency duty for deployers of AI systems that generate deepfakes: they must disclose that the content has been artificially generated or manipulated. That duty has applied since 2 August 2026. It is aimed at legitimate users of these tools, and it is enforced by national authorities against them. A criminal cloning your voice to steal from you is not going to label the clip, and nothing in the Act gives you a claim against anybody for the money you lost. The deployer-side reading of that duty is at agentliability.eu, on the Article 50 transparency and labelling obligations, and it is a guide to what your own business must do if it uses these tools, not a route to recovery.
Your routes to the money are three, and they are ordinary. Your bank, immediately, because a recall request is worth most in the first hours. The police, because a crime reference number is something every insurer and most banks will ask for. And your policy, notified promptly, because notification conditions exist and a late notification is a second argument you do not need. Our sequence for the first three days after any AI-related incident is at the first 72 hours after an AI agent mistake, and the first day of it applies here unchanged.
The variant where your own AI agent made the payment
There is a version of this story that does blur the line, and it is becoming more common as small businesses give AI agents the ability to act rather than only to answer.
Suppose the fraudulent voice note was not acted on by your bookkeeper but by an AI assistant that has authority to raise payments, and it raised one. Now your AI did do something, on an instruction that an attacker forged. It looks inbound, because an attacker caused it, and it looks outbound, because your system executed it. This is the overlap we describe at is a prompt injection attack covered by business insurance, and it is precisely where two insurers can each point at the other.
The practical answer has two halves. On the insurance side, put the scenario to your broker in writing before it happens, and keep the reply. On the control side, an agent that can move money needs the same call-back rule a human does, enforced by the system rather than by a policy document, so that no instruction to pay a new payee is executed without a separate confirmation. What that control looks like when somebody assesses it is at agentcertified.eu, on certifying an AI agent that can move money.
What to do today
Four things, and only the last one costs anything.
Write a call-back rule and tell everyone. Any new payee, any change of bank details, and any urgent or unusual transfer is confirmed by calling the requester back on a number the business already holds. Never a number in the message. Never by replying on the channel the request came in on. Never waived because it is the founder and he sounds annoyed. Put it in one paragraph, print it, and make sure the person who pays the bills has read it. A voice is not an identity, and neither is a face on a video call.
Add a second pair of eyes above a threshold. Pick a number that hurts and require two people to approve any single payment above it. Fraudsters rely on one tired person under time pressure, and a second person breaks the pressure.
Read three lines of your schedule. Is funds transfer fraud, social engineering or cyber crime cover included, what is its limit, and what conditions attach to it. If you cannot find those lines, you do not have it.
Ask your broker one question in writing. Does our policy respond to a payment we made because an AI-generated voice or video impersonated one of our own people or a supplier, what is the sublimit, and what verification steps are a condition of cover. File the answer with the policy. What else to tell the broker about your AI use generally is at what to tell your insurance broker about AI agents.
None of that stops somebody cloning your voice. All of it means that when they do, the payment does not go out, and if it somehow does, the policy has a chance of answering.
Questions
Is a payment made because of a cloned voice an AI insurance claim?
No, and this is the first thing to get straight. AI liability cover responds when an AI system you deployed does something wrong. In a voice clone fraud your AI did nothing. Somebody else used an AI tool to impersonate a person you trust, and a human in your business acted on it. In insurance terms that is a funds transfer fraud or social engineering loss, and the policies built for it are crime cover and the cyber crime section of a cyber policy, not professional indemnity and not an AI liability wording.
Which policy usually covers funds transfer fraud for a small business?
Two candidates. A commercial crime policy, if you have one, may cover money lost to a fraudulent instruction, often under a social engineering or funds transfer fraud extension. A cyber policy very often carries a cyber crime or funds transfer fraud section that does the same job. In both cases the cover is frequently an optional extension with its own sublimit, which can be a small fraction of the headline limit, and with conditions attached. The policy schedule, not the brochure, tells you whether you bought it and at what amount.
What is the condition that decides most of these claims?
Verification. Many wordings that cover a fraudulent instruction require that the instruction was verified through a separate channel before the payment was made, for example a call back to a number the business already held rather than the number in the message. If the payment went out on the strength of the voice alone, a policy with that condition may not respond. This is the single most common reason a social engineering claim fails, and it is entirely within your control before the event and entirely outside it afterwards.
Does any insurer cover deepfake payment fraud by name?
At least one does, in express words, and it is worth knowing about as a marker of where wordings are going rather than as a recommendation. Coalition's affirmative AI endorsement extends its funds transfer fraud trigger to a fraudulent instruction transmitted through the use of deepfakes or any other artificial intelligence technology. That endorsement sits on its US surplus and Canada cyber policies. The same insurer separately offers a deepfake response endorsement, covering forensic analysis, takedown legal work and crisis communications, which its own announcement lists as available in the United Kingdom, Germany, Denmark, Sweden and France among other countries. Both were read on the insurer's own site on 14 September 2026. Whether anything similar sits in your own policy is a question for your wording.
Does the EU AI Act help me recover the money?
No. The Act places a transparency duty on people who deploy AI to generate deepfakes, requiring them to disclose that the content was artificially generated, and that duty has applied since 2 August 2026. A fraudster is not going to comply with it, and the Act does not give the victim of a fraud a claim against anybody. Your routes to recovery are your bank's recall process, a police report, and your insurance. The Act is relevant to what your own business must do when it uses AI, not to what you can claim when somebody else's AI is used against you.
What is the one thing I should do today?
Adopt a call-back rule and write it down. Any new payee, any change of bank details, and any urgent or unusual transfer is confirmed by calling the requester back on a number the business already holds, never a number in the message, and never by replying to the channel the request came in on. A voice is not an identity. That rule costs nothing, it is the condition many policies require, and it is the control an underwriter asks about first. Then ask your broker, in writing, whether your policy responds to a payment made because an AI-generated voice or video impersonated one of your people, what the sublimit is, and what verification steps are a condition.
Sources
- Coalition, announcement titled Coalition Adds New Affirmative AI Endorsement to Cyber Policies, dated 26 March 2024. The two extensions described in this article, the AI security event limb and the funds transfer fraud limb covering a fraudulent instruction transmitted through the use of deepfakes or any other artificial intelligence technology, and the statement that the endorsement applies to US surplus and Canada cyber policies, were read at coalitioninc.com on 14 September 2026. No limit, amount or reinsurer is stated on that page and none is stated here.
- Coalition, announcement titled Coalition Adds Deepfake Response Endorsement. The three services described, the technical analysis by a deepfake forensics firm including a written report, the legal work to have the deepfake taken down, and the crisis communications support, and the list of countries in which the endorsement is stated to be available, were read at coalitioninc.com on 14 September 2026. The page states that limitations and exclusions apply and refers readers to the policy for complete terms. No limit is stated.
- Regulation (EU) 2024/1689 (EU AI Act), Article 50, under which deployers of AI systems that generate or manipulate deepfake content must disclose that the content has been artificially generated or manipulated, subject to the exceptions set out in that article. Article 50 has applied since 2 August 2026. Regulation (EU) 2026/1744 (the AI Omnibus, in force 27 July 2026) moved the Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028 and did not alter the application date of Article 50. Timeline read at digital-strategy.ec.europa.eu.
- Descriptions of what commercial crime, cyber, professional indemnity and AI liability policies typically respond to, of sublimits, and of verification conditions are general market descriptions. No individual policy wording is quoted, no form or clause number is cited, and apart from the two announcements above no insurer's terms are described. Your own policy is the only document that decides your own position.
- This article does not state the law of any country on the recovery of money lost to fraud, on bank liability, or on the reporting of crime. Those questions depend on where you are and should be checked locally.
- The call-back rule, the two-person threshold and the broker question are this desk's own suggestions, offered as practical controls. They are not attributed to any regulator, insurer or standards body, and no insurer is named as requiring them.
- No relationship exists between Future Proof Intelligence and any insurer, bank, authority or broker named or referred to in this article. No product is recommended here and none is offered for sale on this site.