Europe’s AI caution does not reduce the threat
Europe has taken a cautious approach to artificial intelligence. Regulation, data-protection concerns and public scepticism mean many organisations have limited staff access to generative AI tools or delayed wider AI projects altogether. That may be sensible governance, but it can create a dangerous false assumption: if a business is not using AI, it is not exposed to AI-related risk.
The opposite is true. Criminals do not need a UK SME’s permission, budget or internal AI policy to use AI against it. The central implication of SC Media UK’s report is that European hesitation over AI is colliding with a cyber threat landscape in which attackers are already adopting it. For smaller businesses, this matters because AI can make established attacks faster, more convincing and easier to scale.
A cyberattack does not need to involve a futuristic autonomous hacking tool to cause severe loss. A realistic invoice email sent to an accounts assistant, a cloned voice message authorising a payment, or a tailored phishing page that captures Microsoft 365 credentials can be enough. Once an attacker is inside an email account or cloud system, the consequences may include diverted payments, stolen customer information, business interruption, extortion and regulatory costs.
Why AI changes the economics of cybercrime
Cybercriminals have long used phishing, password theft and social engineering because people and poorly secured systems remain easier targets than hardened technical infrastructure. AI does not replace those techniques; it improves the attacker’s ability to run them at volume and with greater credibility.
Better-written and better-targeted phishing
Historically, many phishing emails were easy to spot. They contained poor grammar, generic greetings or implausible claims. Generative AI can help criminals produce fluent British English, adapt a message for a particular industry and create several variations to avoid basic filtering. A fraudster can use public information from a company website, LinkedIn profiles, tenders and social media to imitate a director, supplier or client.
For a UK SME, the risk is especially acute where staff routinely handle invoices, payroll changes, customer documents or bank details. An email appearing to come from a familiar supplier may ask for a change to payment details. A message apparently sent by a managing director may request an urgent transfer while they are travelling. AI makes these pretexts more polished, but the underlying control is still straightforward: no change to bank details should be accepted solely on the basis of an email.
Voice and image impersonation
Deepfake audio and video are also becoming more accessible. An attacker may clone a senior employee’s voice from publicly available recordings or use a synthetic video call to add pressure to a fraudulent request. Small firms often have close, informal working relationships, which can make a supposed instruction from an owner or finance lead seem credible.
The practical answer is not to distrust every colleague. It is to establish a verification process that cannot be bypassed by urgency. For example, confirm high-value payments and bank-detail amendments through a known telephone number, a separate authenticated channel or a documented two-person approval process. Do not call the number included in the suspicious message.
Faster reconnaissance and exploitation
AI can help attackers review leaked data, identify likely targets and draft malicious content quickly. It may also assist less technically capable criminals in understanding code or configuring common attack tools. This does not mean every criminal can now breach any organisation. Good identity controls, patching, backups and network security remain highly effective. It does mean that SMEs should assume they will receive more credible attacks and should reduce the opportunity for a single employee mistake to become a major incident.
What this means for cyber insurance buyers
Cyber insurance is designed to support an organisation after a cyber event, but it is not a substitute for prevention. In the UK market, insurers increasingly assess whether an applicant has basic safeguards in place before offering broad cover or competitive terms. AI-fuelled social engineering strengthens that focus because email compromise and payment fraud can produce expensive claims very quickly.
Review social engineering and funds transfer cover
Not every cyber policy responds in the same way to a fraudulent payment. Some policies include social engineering, crime or funds-transfer fraud cover; others provide it only as an optional extension, with a lower sub-limit or a specific excess. A business should not assume that a standard cyber policy will reimburse every payment made after a convincing fake email, call or invoice.
When reviewing cover, ask the broker or insurer clear questions:
- Does the policy cover social-engineering fraud, including AI-generated impersonation?
- Is a loss caused by a changed supplier bank account covered?
- What is the sub-limit for funds-transfer fraud, and is it adequate for normal payment values?
- Does the policy require a call-back, dual authorisation or another verification control before a claim will be paid?
- Are incident-response costs, legal advice, customer notification and business interruption covered after an email compromise?
The detail matters. A £25,000 fraud sub-limit may be inadequate for a business that regularly pays six-figure supplier invoices. Equally, a policy condition requiring multi-factor authentication (MFA) can become critical if the firm has left an administrator account protected only by a password.
Expect more scrutiny of controls
Insurers are likely to continue examining practical controls that reduce common attack paths. For most SMEs, the priorities are not exotic AI defences. They are proven measures implemented consistently: MFA for email, remote access and cloud applications; tested offline or immutable backups; prompt patching; restricted administrator rights; endpoint protection; and staff training tailored to real job roles.
An insurer may ask whether MFA is enabled for all users, whether backups are tested and whether an incident-response plan exists. Answering accurately is essential. Incomplete or misleading proposal information can complicate a claim, while a control that exists only on paper offers limited protection when an attacker strikes.
A practical 30-day response plan for UK SMEs
AI risk can feel abstract, so turn it into operational decisions. The following actions are achievable for many small and medium-sized businesses within a month.
1. Protect email and cloud identities first
Enable MFA across Microsoft 365, Google Workspace, VPNs, remote-desktop services, accounting platforms and administrator accounts. Prefer authenticator apps, security keys or passkeys over SMS where feasible. Disable legacy email protocols that bypass MFA, remove unused accounts and review mailbox forwarding rules. Attackers commonly use a compromised mailbox to monitor conversations before sending a believable payment request.
2. Make payment verification non-negotiable
Write a short procedure for new bank details, payment amendments and urgent transfer requests. Require independent verification using a trusted contact record, not contact details supplied in the request. Set approval thresholds and ensure that no single individual can both create and release significant payments.
3. Train for realistic deception
Annual checkbox training is not enough. Give finance, HR, customer service and executive assistants examples relevant to their work: payroll diversion, invoice fraud, false CVs, fake legal requests and impersonated directors. Staff should know that excellent grammar, a familiar writing style and even a recognisable voice are no longer proof of authenticity.
4. Test recovery, not just backups
Keep backups segregated from day-to-day accounts and test whether key files and systems can be restored within the time the business can tolerate. Record who contacts the IT provider, insurer, bank, solicitor and affected customers if an incident occurs. Fast decisions can reduce both operational damage and the eventual insurance claim.
5. Re-read the policy before the incident
Check notification requirements, the insurer’s incident-response helpline, exclusions, policy limits and any security conditions. Save the emergency contact number outside the company email system. If ransomware, a data breach or suspected business email compromise occurs, notify the insurer promptly before appointing expensive external suppliers, unless immediate action is required to contain harm.
The strategic lesson: cautious AI governance must include defence
European businesses are right to consider privacy, intellectual-property and regulatory risks before deploying AI internally. However, a restrictive AI-use policy alone does not make a company safer. It should sit alongside cyber resilience planning that recognises adversaries are using AI to improve familiar fraud and intrusion methods.
For UK SMEs, the most valuable response is not to buy every new AI security product. It is to make identity protection, payment controls, staff verification habits and insurance review proportionate to the firm’s actual exposure. A well-configured email environment, a disciplined call-back process and a cyber policy that genuinely addresses social engineering can prevent or soften the losses most likely to arise from AI-enabled deception.
FAQ
Does cyber insurance automatically cover an AI-generated phishing scam?
No. Cover depends on the policy wording. A phishing-led breach may trigger cyber cover, but a fraudulent payment may fall under a separate social-engineering or funds-transfer fraud section, often with its own limit and conditions. Ask for the wording and confirm the applicable sub-limit.
Is multi-factor authentication necessary for a cyber insurance policy?
Many insurers expect MFA, particularly for email, remote access and privileged accounts. Requirements differ by insurer and policy, but MFA is both a major underwriting factor and one of the strongest defences against account takeover.
Can a small business defend itself against deepfake voice fraud?
Yes. Deepfakes are most effective when staff rely on voice or video alone. Use independent verification for payment requests and changes to sensitive information, require dual approval for significant transfers, and give staff permission to challenge urgent instructions.
What should an SME do first after suspected email compromise?
Contact the IT provider or internal security lead immediately, change or revoke affected sessions, preserve evidence, check mailbox rules and notify the insurer through its approved incident-response route. If money has been sent, contact the bank without delay; rapid reporting gives the best chance of freezing or recovering funds.
Source: SC Media UK — Fri, 25 Sep 2026 19:21:32 GMT