Deepfake Fraud & Your Cyber Insurance Gap: NC 2026

Cyber insurers began excluding AI deepfake fraud in 2026. Why NC small businesses can't rely on policies alone, and what to do. (336) 886-3282.

Cover Image for Deepfake Fraud & Your Cyber Insurance Gap: NC 2026

TL;DR: A quiet but expensive shift hit the cyber insurance market in 2026. As insurance trade reporting has documented, many carriers began excluding AI-generated deepfake fraud from standard social engineering coverage, on the argument that traditional social engineering coverage requires direct human manipulation and an AI-generated voice or video creates an intermediary layer that voids the claim. Meanwhile deepfake-driven fraud losses have run to hundreds of thousands of dollars per event, with wire-transfer schemes reaching into the millions. For a North Carolina small business, the takeaway is twofold: read your policy for AI and deepfake exclusions before you renew, and reduce your reliance on insurance by hardening the payment and identity-verification controls that stop the fraud in the first place.

Key takeaway: The fraud that is growing fastest is the fraud your cyber policy may have quietly stopped covering. Insurance is a backstop, not a control. The only reliable defense against a convincing fake is a verification process the fake cannot pass.

Not sure whether your cyber policy covers AI-driven fraud? Contact Preferred Data Corporation at (336) 886-3282 for a fraud-controls and security review. BBB A+ rated, serving High Point, Greensboro, Winston-Salem, Charlotte, Raleigh, and the Piedmont Triad since 1987.

What is the deepfake cyber insurance coverage gap?

The coverage gap is the growing space between the AI-driven fraud businesses are actually experiencing and what standard cyber insurance policies will pay for. According to insurance industry reporting, carriers moved during 2026 to exclude AI-generated deepfake fraud from standard social engineering coverage, leaving businesses that renewed early in the year potentially uncovered for this exact vector.

Why the exclusion exists and why it matters:

  • The legal logic is technical, but the loss is real. Standard social engineering coverage was written to require direct human manipulation, and carriers argue an AI-generated deepfake introduces an intermediary that falls outside that language.
  • The losses are large. Reporting cites deepfake-related losses averaging in the hundreds of thousands of dollars, and wire-transfer fraud schemes reaching as high as $25 million in extreme cases.
  • The attack surface is expanding. Reporting on AI in the workplace notes roughly 45% of employees now regularly use AI tools on corporate devices, up from about 15% a year earlier, with a large share running outside company controls, which broadens the ways attackers can impersonate and manipulate.

The practical result is that a business can hold a cyber policy, suffer a deepfake-enabled wire fraud, and discover the specific loss is excluded.

Why can't a small business just rely on cyber insurance?

Insurance transfers financial risk, but it does not prevent the incident, and in 2026 it may not even pay for the newest form of it. A policy is a backstop for when controls fail, not a substitute for having controls, and the deepfake exclusions make that distinction expensive to ignore.

Three reasons insurance alone is a losing bet:

  1. Coverage is narrowing exactly where the threat is growing. As carriers carve out AI-generated fraud, the fastest-rising loss type is becoming one of the least reliably covered.
  2. Carriers increasingly require controls to pay. Cyber policies now commonly demand multi-factor authentication, security awareness training, and defined verification procedures, and a claim can be reduced or denied when required controls were absent.
  3. The reputational and operational damage is uninsurable. Even a paid claim does not restore a customer relationship or the hours lost untangling a fraudulent transfer.

Key takeaway: If your defense against a fake CEO voicemail is a hope that insurance will cover it, you have neither a defense nor, increasingly, the insurance. Controls come first, and insurance covers what slips past them.

Want to know if your controls would stop a deepfake wire request? Call Preferred Data at (336) 886-3282 or explore our Cybersecurity and Managed IT services.

How do you stop deepfake and business email compromise fraud?

You stop AI-enabled fraud with verification processes that do not depend on recognizing a voice or a face, because those are exactly what attackers can now fake convincingly. The single most effective control is an out-of-band callback: any request to move money or change payment details is confirmed through a known, pre-established channel before it is acted on.

The controls that actually work:

  • Out-of-band verification for payments. Confirm any funds transfer or banking-detail change by calling back a known number on file, never a number or contact supplied in the request itself.
  • A code word or dual-approval for high-value transfers. Require a second authorized person, or a pre-agreed verification step, for transactions over a set threshold, so no single person can be socially engineered into a wire.
  • Security awareness training that covers deepfakes. Employees who know that a familiar voice or a live video is no longer proof of identity are far harder to manipulate. Many insurers now require this training regardless.
  • Multi-factor authentication and email hardening. Business email compromise often starts with a compromised inbox. MFA and properly configured email security cut off the access that makes impersonation possible.

Notably, the insurance market itself is beginning to respond. Reporting on affirmative AI endorsements describes carriers introducing coverage, such as Coalition's Affirmative AI Endorsement, that explicitly treats an AI security event as covered and extends funds-transfer triggers to deepfake-generated instructions. Asking your broker about such endorsements is worth doing, but it complements strong controls rather than replacing them.

Insurance-first thinking versus a controls-first defense

FactorRely on the policyControls first, insurance as backstop
Deepfake wire requestMay be excludedBlocked by out-of-band callback
Coverage certaintyShrinking for AI fraudControls work regardless of policy language
Insurer requirementsOften unmet, risking denialMFA and training in place, claims defensible
High-value transfersSingle point of failureDual approval, threshold controls
Employee readinessUntrained, trusts a familiar voiceTrained to verify, not to recognize
OutcomeUncertain payout, real damageFraud stopped before money moves

Ready to build fraud controls that do not depend on luck? Call (336) 886-3282 or learn about our Cybersecurity services.

What should a North Carolina business do before its next renewal?

Before renewing, read the policy for AI and deepfake exclusions, confirm you meet the carrier's required controls, and close the verification gaps that let this fraud succeed. Renewal is the natural moment to align what you are insured for with the threats you actually face, and to make sure a technicality will not deny a future claim.

A pre-renewal checklist:

  • Ask your broker directly whether AI-generated or deepfake fraud is covered, excluded, or available via an affirmative AI endorsement.
  • Inventory your required controls such as MFA, security awareness training, and documented payment-verification procedures, and confirm they are actually in place, not just promised on the application.
  • Document your verification process for payments and vendor changes, so it is a real, auditable control rather than an informal habit.
  • Train your team on deepfakes specifically, so the human layer, which is where this fraud lands, is prepared.

Aligning coverage and controls turns your policy from a source of false confidence into a genuine backstop behind defenses that work.

How does Preferred Data help NC businesses defend against AI fraud?

Preferred Data Corporation has protected North Carolina businesses since 1987, and we focus on the controls that stop AI-enabled fraud before it reaches your bank account. Our Cybersecurity and Managed IT services put multi-factor authentication and hardened email security in place to prevent the account compromise behind most business email compromise, help you build and document out-of-band payment-verification procedures, and deliver security awareness training that specifically prepares your team for deepfake voices and video.

Because we are local, on-site within 200 miles of High Point, we work with your actual people and processes to build verification steps that fit how your business really operates, so the controls get used rather than bypassed under pressure.

Get a fraud-controls and cybersecurity review. Contact Preferred Data Corporation at (336) 886-3282. We deliver Cybersecurity, Managed IT, and security awareness training for small businesses and manufacturers across the Piedmont Triad. Serving the region since 1987, BBB A+ rated.

Frequently Asked Questions

Does cyber insurance cover deepfake fraud in 2026?

Often not under standard social engineering coverage. Insurance trade reporting indicates many carriers moved in 2026 to exclude AI-generated deepfake fraud, arguing that traditional social engineering coverage requires direct human manipulation while an AI-generated voice or video introduces an intermediary layer. Some carriers offer affirmative AI endorsements that restore coverage, so you should ask your broker directly before renewing.

How much can deepfake fraud cost a business?

A lot. Insurance industry reporting cites deepfake-related losses averaging in the hundreds of thousands of dollars per event, with wire-transfer fraud schemes reaching as high as $25 million in extreme cases. For a small business, even a single successful fraudulent transfer can be financially severe, especially if the loss turns out to be excluded from coverage.

What is the best defense against a deepfake voice or video scam?

An out-of-band verification process. Because attackers can now convincingly fake a familiar voice or face, the defense cannot rely on recognizing them. Confirm any request to move money or change payment details by calling back a known, pre-established number, and require dual approval for high-value transfers so no single person can be manipulated into a wire.

Why do cyber insurers require security controls?

Because controls reduce the frequency and size of claims. Insurers increasingly require multi-factor authentication, security awareness training, and documented verification procedures as conditions of coverage, and a claim can be reduced or denied if required controls were not actually in place. Meeting these requirements both lowers your risk and protects your ability to collect.

Yes. Both are forms of social engineering aimed at tricking someone into moving money or data. Business email compromise often begins with a compromised inbox, and deepfake audio or video is increasingly layered on to make the impersonation more convincing. The same controls, MFA, email hardening, and out-of-band verification, defend against both.

What should I do before renewing my cyber insurance policy?

Read the policy for AI and deepfake exclusions, ask your broker whether an affirmative AI endorsement is available, confirm you actually meet the carrier's required controls, and document your payment-verification process. Renewal is the right moment to align coverage with the threats you face and to ensure a technicality will not deny a future claim.

Support