Indemnisation cyberattaque

Cyberattack compensation: can an insurer refuse coverage without an express exclusion?

Cyberattack compensation in France 2026 : this debate confronts two interpretations of an insurance contract where a cyber incident is not covered by any explicit exclusion clause. The key issue lies in the boundary, debated by the AIs, between an exclusion of coverage and an initial absence of coverage.

We will also see how Solsice Legal handles links to decisions of the French Court of Cassation and statutory provisions on Legifrance — spoiler: the links are clickable and work properly (tested below).

View the debate, verdict and quiz:
https://solsicelegal.com/public/debates/en-droit-francais-un-assureur-peut-refuser-d-indemniser-un-s-61f0d995430c

The proposition under debate

The proposition submitted to the tournament was exactly:

“Under French law, an insurer may refuse to compensate a loss caused by a cyberattack even when the contract contains no explicit exclusion.”

The confrontation requires the AIs to determine whether the silence of the contract should be interpreted as an absence of exclusion or as an absence of coverage.

How the debate unfolded

For TRUE, GLM-5 distinguishes between an exclusion of coverage and the absence of coverage altogether: a cyber risk may remain outside the scope of an insurance policy without being expressly excluded. It also relies on the requirement of uncertainty inherent in insurance and on the insured’s obligation to demonstrate that the loss falls within the scope of a subscribed guarantee.

FALSE, defended by GPT-5.4-mini, relies on Article L.113-1 of the French Insurance Code: an exclusion must be formal and limited. The silence of the contract should therefore not allow the insurer to exclude a risk that is already covered by broadly worded insurance coverage.

GLM-5 then introduces the argument that a cyberattack must first fall within the contractual scope of the coverage. Where no relevant coverage was granted in the first place, the insurer would not need to rely on an exclusion.

Claude Opus 4.8 responds that deriving an exclusion from pricing, the novelty of the risk, or the presumed intention of the parties would effectively amount to creating an implied exclusion.

This second confrontation clearly shifts towards FALSE, with a score of 95%, which has a significant impact on the final synthesis of the debate.

The legal provisions and concepts discussed

The tournament is structured mainly around Articles L.113-1, L.113-2 and L.12-10-1 of the French Insurance Code, together with references to French Court of Cassation case law concerning exclusion clauses.

The report notably brings into confrontation the concepts of “formal and limited” exclusions, burden of proof, uncertainty, contractual scope of coverage and the specific legal regime applicable to cyber insurance.

Examples of links used in the debates:

https://www.legifrance.gouv.fr/codes/article_lc/LEGIARTI000006791984

https://www.legifrance.gouv.fr/codes/section_lc/LEGITEXT000006073984/LEGISCTA000047048143

https://www.courdecassation.fr/decision/5fca262d4504b03b8a33c152

Did the wording of the question influence the debate?

Yes, quite significantly.

The proposition states in general terms that an insurer “may refuse” compensation, without specifying whether the damage first falls within the scope of coverage actually provided under the policy.

This lack of precision gives TRUE its strongest argument — the distinction between an absence of coverage and an exclusion — while also allowing FALSE to challenge the proposition in its general formulation.

Interestingly, the FALSE side eventually acknowledges the relevance of this distinction itself, before limiting its reasoning to losses that already fall within the scope of the insured risks.

A legal context specific to cyber risk

The debate takes place against a broader background of increasingly serious cyberattacks. Even governments are struggling to protect their citizens’ data — as illustrated by the 2026 hacking of the French ANTS system, reportedly resulting from a remarkably basic vulnerability according to Korben.

The threat is not limited to governments. Businesses and all types of organisations are also heavily exposed.

Cyberattacks do not merely target data. Increasingly, their objective is to disrupt or paralyse the operations of a company, institution or organisation.

Debate summary

DescriptionDetails
View the original reporthttps://solsicelegal.com/public/debates/en-droit-francais-un-assureur-peut-refuser-d-indemniser-un-s-61f0d995430c
PDF23 pages
Original languageFrench
ScoresWeighted scores: TRUE 0.70 (70%); FALSE 0.95 (95%). Final verdict: FALSE — confidence 58%
Think-tank AIs3 debating AIs, excluding the arbitrator-clerk: z-ai/glm-5; openai/gpt-5.4-mini; anthropic/claude-opus-4.8
Arbitrator-clerkdeepseek/deepseek-v4-flash
DataGlossary: no dedicated glossary section identified. 9 tables in total in the PDF, corresponding to 5 distinct datasets
Quiz languageFrench

View the debates, verdict and quiz

https://solsicelegal.com/public/debates/en-droit-francais-un-assureur-peut-refuser-d-indemniser-un-s-61f0d995430c

This analysis is brought to you by:

Picture of Mehdi Touzani
Mehdi Touzani
Former lawyer, I now focus on Solsice Legal. Ancien avocat, je me consacre aujourd’hui à Solsice Legal.

Publish and comment on your Solsice Legal analysis on this blog: contact us on Linkedin

in any language or jurisdiction

Please note: Solsice Legal does not provide legal advice. Only a qualified legal professional can formulate the relevant assertions and fully understand the implications of the debates for your specific case.