Why it matters for your company
A cyber policy is several coverages under one limit. On the first-party side sit incident response, data restoration, extortion payments, and business interruption while systems are down. On the third-party side sit privacy liability, network security liability and regulatory defense.
For AI products the definitions decide the claim. A prompt injection that makes a model leak customer data may or may not be a security event under a form written before language models existed, and each side of the policy defines that trigger separately. Both halves need reading.
Related terms
- Technology errors and omissions (tech E&O)Professional liability for technology companies: it responds when your product or service fails to perform and a customer suffers a financial loss. It is the anchor line for an AI or software company.
- SublimitA smaller cap inside a policy's main limit that applies to one kind of loss. A $3M cyber policy with a $250,000 sublimit for social engineering pays no more than $250,000 for that claim.
- Business interruptionCoverage that replaces income lost and extra expenses incurred while covered physical damage is repaired. It is usually part of a property policy, and the physical loss is what triggers it.
- Silent AIAI-related risk that a policy neither expressly covers nor expressly excludes, so whether it responds depends on how general wording is read after a loss. The term borrows from silent cyber.
- Affirmative AI coveragePolicy wording or a standalone product that names AI-related losses as covered, instead of leaving them silent or excluding them. It arrives as an endorsement to cyber or E&O, or as a dedicated AI liability policy.