Your cyber insurance policy was quietly rewritten in 2026. And if you haven’t read the new exclusions line by line, you’re probably not covered for what you think you are.

I review cyber policies for a living. Here are 6 shifts I’m seeing in every 2026 renewal — and most insureds have no idea.

1. AI EXCLUSIONS ARE NOW DEFAULT

Through 2024, AI-related losses were silently covered. In 2026, every major US carrier (Chubb, AIG, Travelers, Coalition, At-Bay, Beazley) ships a default AI exclusion endorsement.

Some exclude AI-generated content. Some exclude losses caused by AI vendors. Some exclude AI-driven decision outputs.

The default flipped from “AI is covered unless excluded” to “AI is excluded unless you negotiate it back.”

If your team uses AI tools for security decisions, customer communications, or fraud detection — check your exclusion language now.

2. RANSOM PAYMENT CAPS HIDING IN THE FINE PRINT

Your policy says $5M coverage. But the ransom payment sub-limit? $250K.

That means if you pay a $1.2M ransom, you eat $950K out of pocket. The headline limit is marketing. The sub-limit is reality.

I’ve seen mid-market companies renew without noticing the cap dropped from their prior year. Brokers: please flag this.

3. MFA ATTESTATION IS NO LONGER ENOUGH

Carriers accepted “yes” on the MFA question for three straight years. Then they started denying claims where the insured only had MFA on one admin account.

In 2026, you need evidence: a screenshot or CSV from your identity provider showing MFA enforcement across all users. Attestation without evidence is now a soft denial trigger.

4. SOCIAL ENGINEERING GETS ITS OWN SUB-LIMIT

Business email compromise used to fall under your general cyber coverage. Now carriers are carving social engineering into its own line item — often with a cap of $100K-$250K.

BEC is the #1 cybercrime by dollar loss. And your coverage for it just got smaller.

5. 72-HOUR SUPPLY CHAIN NOTIFICATION

Your vendor gets breached. You now have 72 hours to notify your carrier — even if you weren’t directly hit.

Miss that window? Coverage dispute. Most mid-market companies don’t have a process for this. Most don’t even know it’s required.

6. “WE HAVE ANTIVIRUS” IS NOW SCORED AS NO EDR

The 2026 application asks: what EDR product, deployed on what percentage of endpoints, monitored by whom, with what response SLA.

Carriers want CrowdStrike, SentinelOne, Defender for Endpoint Plan 2, or similar tier-1 EDR — backed by 24/7 SOC monitoring. Webroot and McAfee are scored as nothing.


The bottom line: cyber insurance isn’t getting harder to buy. It’s getting harder to use. The gap between what you signed and what’s actually covered is where claims get denied.

If you haven’t reviewed your 2026 renewal line by line, you should. Or hire someone who will.


What’s the biggest surprise you’ve seen in a 2026 cyber policy renewal?

References: Cowbell 2026 Claims Report