A modern cyber form for companies whose products and operations run on AI. Every module below can be tailored per account; all coverage descriptions are indicative and subject to underwriting.
Defense and damages for claims arising from security failures, unauthorized access, data breaches, and privacy violations — including regulatory proceedings, fines and penalties where insurable.
Digital forensics, breach counsel, notification, call center, credit monitoring, and crisis communications, coordinated by our response panel from the first call.
Extortion payments where lawful and approved, professional negotiation, and restoration costs.
Lost income and extra expense from security events and system failure — with dependent business interruption for cloud, API, and model providers your product relies on.
Funds transfer fraud and social engineering — explicitly including AI-enabled impersonation, synthetic voice, and deepfake-assisted schemes.
Costs to restore or recreate data and systems corrupted or destroyed in a covered event.
Where most policies are silent — or newly excluding — Bali states in writing how the policy responds when the loss involves your AI systems: an attacker manipulating your customer-facing AI into disclosing data, abuse of AI features and endpoints driving covered first-party loss, AI-enabled social engineering of your staff or your systems, and security failures of the AI infrastructure your product depends on. If AI is how you operate, it shouldn't be where your coverage ends.
Indicative appetite — accounts outside these bands are considered case by case.
| Dimension | Target |
|---|---|
| Target insureds | AI-native software companies; SaaS with embedded AI features; data, ML, and AI infrastructure companies; tech-enabled services automating operations with AI |
| Company size | Early-stage through mid-market |
| Limits | Primary and excess placements; limits scaled to account size |
| Retentions | Scaled to revenue and posture |
| Territory | United States |
| Generally out of appetite | Cryptocurrency exchanges and custody; adult content; online gambling; standalone payment processing |
Security expectations: MFA on privileged access, tested backups, and EDR are baseline. For AI features with real authority — payments, data access, system actions — we expect guardrails, human escalation paths, and logging, and we price accounts that have them accordingly.