Adds full cyber and affirmative AI cover to financial-institutions suite
CFC integrated its Cyber Proactive Response policy and explicit AI language into modular products for investment managers and other financial institutions.
London, United Kingdom · More than 90 countries
A global specialty insurance provider focused on cyber, technology and emerging risks. CFC combines delegated underwriting, digital broker trading, in-house cyber response and Lloyd’s Syndicate 1988, which participates exclusively on business underwritten by CFC group entities.
CFC shows how an MGA can become an integrated underwriting system without simply turning into a conventional carrier. The group combines specialist product design, broker distribution, threat intelligence, incident response and proprietary trading technology, while Syndicate 1988 gives it a direct channel to third-party Lloyd’s capital. That architecture aligns CFC more closely with underwriting outcomes than a pure commission model, but it also concentrates several roles—risk selection, portfolio data, claims learning and capital access—inside one platform. The 2025 accounts provide a useful external check. Syndicate 1988 reported $453.2 million of gross written premium, an $87.6 million calendar-year profit and an 82.0% net combined ratio, while its business remained limited to delegated facilities underwritten by CFC group entities. The portfolio’s micro-and-SME orientation and limited critical natural-catastrophe exposure can diversify capital, though cyber aggregation and rapidly changing technology risks require their own stress tests. CFC’s Lane Assist pilot is strategically important because it moves generative AI from support work into a live underwriting workflow. In its April 21, 2026 pilot announcement, CFC said each recommendation required underwriter checking and approval before issue. That dated description does not establish the scope of any subsequent rollout; durable value will depend on measured differences in selection, referrals, overrides and downstream claims rather than quote speed alone. The broader move to affirmative AI language across seven product areas is similarly consequential. Explicit wording can reduce silent exposure and claims ambiguity, but only if underwriting, pricing and incident-response data keep pace with model drift and new liability theories. The indicators to watch are Syndicate 1988’s performance through softer cyber pricing, the share of low-complexity submissions handled without touch, human override rates, severity trends in funds-transfer and AI-related claims, and whether third-party capital remains willing to pay a participation fee for access to the portfolio.
MGA Index analysis: the next question is what the pilot population can tell an observer. CFC’s April announcement described a small number of lower-complexity cyber submissions. Performance in that group would not, on its own, establish performance across the full submission flow. A useful evaluation would identify eligible cases, exclusions, referrals and missing-data rates before comparing speed or accuracy. Otherwise, an apparent improvement could reflect an easier mix of work rather than a better underwriting process.
Human approval is a control point, not a complete measure of control quality. For an evaluation, retain the original recommendation, the final decision and the reason for a material change. Distinguish extraction corrections from appetite decisions, pricing changes and wording changes. A low override rate could indicate accurate recommendations, but could also reflect a narrow sample or insufficient challenge. Neither interpretation follows from the rate alone. These are proposed evaluation criteria, not findings about CFC’s internal performance.
A practical review would also follow a sample of approved recommendations into issued policies. Did the intended terms survive quote revisions and binding? Were important facts carried through correctly? Operational checks can expose defects before claims mature, but they do not substitute for later underwriting results. Evaluating speed, policy accuracy and loss experience separately avoids claiming a financial benefit from an operational result.
The counterpoint is that an early pilot should not be expected to prove ultimate loss performance immediately. Requiring mature claims evidence before any controlled use would make responsible experimentation difficult. A proportionate approach is to limit the initial scope, document errors and escalation, and expand only when evidence supports the next use case. The relevant question is what has been demonstrated at each stage, not whether the workflow has earned a broad label such as autonomous underwriting.
CFC integrated its Cyber Proactive Response policy and explicit AI language into modular products for investment managers and other financial institutions.
The former Direct Line Group CEO joined to lead CFC’s next phase of growth; outgoing CEO Louise O’Shea remained a significant shareholder.
The program addresses AI-related exposures in technology E&O, professional liability, eHealth, intellectual property, management liability, media and cyber products.
The agentic-underwriting workflow extracts submission data and prepares quote recommendations for lower-complexity cyber risks, with each output reviewed and approved by an underwriter.
The Lloyd’s annual report shows $453.2 million of 2025 gross written premium, $87.6 million of calendar-year profit and an 82.0% net combined ratio.