Technology by RateShield. Coverage placed by Lakeshore Risk Advisors LLC, an independent Illinois brokerage.

Want to see how much you could save? Get a free savings estimate in 60 seconds.

← All articles

Does Your Crime Policy Cover an AI Agent That Wires Money to a Fraudster?

August 12, 2026 · 8 min read

An Illinois logistics company outside Naperville runs its accounts payable through an AI agent. The agent reviews incoming invoices, matches them against purchase orders, and initiates wire transfers when approvals clear. Faster than any human process, no vacation coverage problems, no manual keying errors. It works exactly as designed.

Until a fraudster figures out that it does.

A vendor-impersonation packet arrives. Embedded inside a legitimate-looking PDF invoice is a string of hidden instructions. The AI agent processes the document, reads the embedded prompt, and routes $97,000 to a bank account in a jurisdiction the company has never done business with. The transfer clears in under three hours. The money is gone.

The CFO calls the broker. "Which policy covers this?"

The answer nobody wants to give: it depends on policy language most businesses haven't read, and right now the odds aren't good.

What everyone assumes and why it's probably wrong

Most businesses with crime and cyber coverage assume one of those policies reaches this. The crime policy has a computer fraud provision. The cyber policy has a funds transfer fraud (FTF) insuring agreement. Both sound like they're describing exactly what just happened.

But insurance coverage turns on definitions, not descriptions. And the definitions in most standard commercial crime and cyber forms weren't written with AI agents in mind. They were written when "employee" meant a human being and "fraudulent instruction" meant a phone call or an email to a person.

The coverage gap in this scenario isn't hypothetical. It's structural. It's baked into the definitions, and it won't bend just because the facts feel like they should qualify.

Crime policies and the "natural person" problem

Start with the commercial crime form. ISO's standard theft and fidelity forms cover computer fraud and funds transfer fraud. Both provisions look relevant when an AI agent wires money to a fraudster.

But both provisions hinge on the definition of "employee." ISO's commercial crime form defines employee as "a natural person." That's a legal term of art. It means a human being. It excludes software. It excludes automation. It excludes AI agents.

When your payment agent initiates a wire because a malicious document injected instructions into its processing pipeline, that transfer wasn't made by an employee. It wasn't made by you directly, either. It was made by a software system acting on compromised instructions. The crime policy's definition of who can trigger coverage doesn't reach that.

And it's not just the employee definition. Many crime FTF provisions require that the fraudulent instruction be received by a financial institution or by an employee. The fraudster's instructions went to an AI agent. Whether that satisfies "received by an employee" is a legal question, and the answer under most standard forms is probably no.

Cyber FTF: designed for social engineering, not prompt injection

Cyber policies often include a funds transfer fraud insuring agreement, and it's the first place brokers look when a business loses money through electronic fraud. The FTF provision covers losses from fraudulent instructions to transfer money. That sounds exactly like what happened.

Except the mechanism doesn't fit. FTF provisions in most cyber forms are built around social engineering of people. A fraudster sends a spoofed email to your CFO or your AP coordinator, impersonating a vendor or a bank. The human follows the instructions. The money moves.

The FTF provision was designed to cover that pattern. A human being received a fraudulent communication and acted on it. Your business lost money as a result.

When an AI agent receives a manipulated input and initiates a transfer on its own processing authority, there's no human receiving the fraudulent instruction. The fraudster communicated with the AI. The AI acted. If your process included human approval and the AI bypassed it because the manipulated prompt told it to, you've got a slightly different fact pattern, but you're still probably outside the FTF definition as written in most forms.

Some cyber FTF provisions have broader language that doesn't explicitly require the fraudulent instruction to land on a human. Those are the ones worth reading closely. But they're not the norm, and you'd need to get the actual policy language in front of someone who knows what to look for before you could rely on that coverage.

Computer fraud: the unauthorized access wall

Computer fraud provisions in crime and cyber policies cover losses from someone accessing your computer systems without authorization, or exceeding their authorized access. A fraudster hacking in, stealing credentials, and initiating a transfer fits this provision well.

Prompt injection looks like it should qualify. A fraudster inserted malicious instructions into your AI agent's processing pipeline. That wasn't something your company authorized. It feels like unauthorized access.

But here's where the definition breaks. Most computer fraud provisions require unauthorized access to your computer system by an outside party. In a prompt injection attack, the fraudster doesn't access your system. They submit input to a system your company intentionally built to accept input from vendors and external parties.

Your AI agent was designed to read invoices. It was designed to accept documents from outside your company. When a fraudster puts hidden instructions inside an invoice, they're using an interface your company deliberately made available. The interface worked exactly as designed. The attack was in the content, not in the access.

Whether that constitutes "unauthorized access" in the legal sense of the policy definition is genuinely unclear, and the answer in most jurisdictions is probably no. The fraudster was "authorized" to submit an invoice. Your AI was "authorized" to read it. Nobody exceeded their authorization in the traditional sense. The fraud was in what the instructions said, not in how they got into the system.

A court could go either way depending on how the specific policy defines "unauthorized." But "might win this argument in litigation" isn't the same as "covered," and you don't want to find out the hard way.

Why this is the sharpest unwritten question in AI liability

The AI coverage gap most people talk about is errors and omissions: your AI gives a customer bad advice, they lose money, does E&O respond? That matters, and it's a real coverage question.

But the funds transfer fraud scenario is sharper for three reasons.

First, the loss is immediate and concrete. There's no ambiguity about whether harm occurred. $97,000 left your account and went to a fraudster. That's not an E&O dispute about whether output quality constitutes a professional error. That's a wire transfer that settled. The question isn't whether you have damages. It's whether the policy applies at all.

Second, these attacks are already happening. Prompt injection against AI agents that handle financial operations isn't theoretical. Security researchers have demonstrated that AI agents with payment authority can be manipulated through invoice content, email metadata, forged API responses, and embedded text strings in documents. Threat actors are aware of this. Businesses deploying AI payment agents are actively being targeted.

Third, most businesses with AI in their AP workflows haven't asked whether their crime or cyber policy covers AI-directed transfers. The assumption is that the old FTF coverage still applies because the outcome looks the same: money got sent to a fraudster. But the mechanism is different enough that the definitions in most standard forms don't reach it cleanly.

What your program probably looks like right now

If you've got a standard commercial crime policy and a standard cyber policy, and you haven't specifically reviewed them for AI payment agent exposure, this is a reasonable picture of where you stand.

Crime policy, computer fraud: probably doesn't respond. The attacker didn't access your system without authorization. They submitted a document your AI was built to accept.

Crime policy, funds transfer fraud: probably doesn't respond. The fraudulent instruction didn't go to an employee (a natural person). It went to an AI system.

Cyber policy, FTF: same problem. Most FTF provisions require social engineering of a human. Prompt injection of an AI agent is a different attack pattern.

Cyber policy, first-party loss or data/network fraud: some cyber forms have broader first-party provisions that might reach this, depending on the specific language. This is the most plausible coverage path, and it's also the least standardized. The language varies more across carriers here than in any other provision, which means you actually have to read what you have.

General liability: designed for bodily injury and property damage. Doesn't cover this kind of financial loss.

The honest picture is that most commercial programs weren't designed to cover AI-initiated wire fraud and probably won't respond without ambiguity, dispute, or denial.

Three things worth doing now

If your business uses AI agents in any financial workflow, including AP, procurement, billing, or treasury, these are the conversations worth having before a claim.

Get the actual definitions. Ask your broker for the policy language on "employee," "computer fraud," and "funds transfer fraud" from your crime and cyber forms. Read the definitions, not just the insuring agreement headings. The question isn't whether you have FTF coverage. It's whether an AI-initiated transfer qualifies under the definition structure in your specific form.

Ask explicitly at renewal. When you renew your cyber or crime policy, ask whether a prompt injection attack against your AI payment agent would trigger the FTF or computer fraud insuring agreements. Ask them to confirm in writing. If they say yes, make sure it's documented. If they say they don't know, that's also informative.

Keep a human in the wire loop. Until coverage catches up to the exposure, requiring human confirmation for any wire transfer above a threshold (something in the range of $5,000 to $10,000 as a starting point) forces a person into the approval chain. The AI can initiate. A human has to confirm before the wire settles. That breaks the prompt injection attack chain because the fraudster has to social engineer a person, not just manipulate a document. It won't earn you a premium credit, but it closes the gap the coverage question can't resolve yet.

Specialty markets are starting to move

A handful of insurers focused on AI liability are working on coverage that explicitly addresses AI-directed payment fraud. Some of the emerging markets writing AI user coverage, as opposed to coverage for companies that build AI tools, are developing endorsements that respond to prompt injection and AI-initiated wire fraud scenarios.

This coverage isn't standard market yet. It's not in most commercial programs because nobody needed it three years ago and the forms haven't caught up. But if your business has given payment authority to an AI agent, the standard program gap is real enough that it's worth having a broker who knows these specialty markets walk through your exposure.

That conversation won't be "add one endorsement and you're covered." It'll be an honest read of your current crime and cyber forms, a clear picture of where AI-directed transfers fall through, and a decision about whether specialty coverage is worth the additional premium given what you've actually deployed.

If your Illinois business uses AI agents in accounts payable, procurement, or any other financial workflow, reach out to Jack Ray directly. He works with commercial clients across DuPage County, the Chicago suburbs, and the broader Illinois market and can review your crime and cyber program for exactly this gap.

Email: jray@lakeshoreriskadvisors.com

Are you overpaying for home protection?

Compare options from multiple providers in 60 seconds. Free, no obligation.

Get your free estimate