Cyberattack compensation in France 2026 : this debate confronts two interpretations of an insurance contract where a cyber incident is not covered by any explicit exclusion clause. The key issue lies in the boundary, debated by the AIs, between an exclusion of coverage and an initial absence of coverage.
We will also see how Solsice Legal handles links to decisions of the French Court of Cassation and statutory provisions on Legifrance — spoiler: the links are clickable and work properly (tested below).
View the debate, verdict and quiz:
https://solsicelegal.com/public/debates/en-droit-francais-un-assureur-peut-refuser-d-indemniser-un-s-61f0d995430c
The proposition under debate
The proposition submitted to the tournament was exactly:
“Under French law, an insurer may refuse to compensate a loss caused by a cyberattack even when the contract contains no explicit exclusion.”
The confrontation requires the AIs to determine whether the silence of the contract should be interpreted as an absence of exclusion or as an absence of coverage.
How the debate unfolded
For TRUE, GLM-5 distinguishes between an exclusion of coverage and the absence of coverage altogether: a cyber risk may remain outside the scope of an insurance policy without being expressly excluded. It also relies on the requirement of uncertainty inherent in insurance and on the insured’s obligation to demonstrate that the loss falls within the scope of a subscribed guarantee.
FALSE, defended by GPT-5.4-mini, relies on Article L.113-1 of the French Insurance Code: an exclusion must be formal and limited. The silence of the contract should therefore not allow the insurer to exclude a risk that is already covered by broadly worded insurance coverage.
GLM-5 then introduces the argument that a cyberattack must first fall within the contractual scope of the coverage. Where no relevant coverage was granted in the first place, the insurer would not need to rely on an exclusion.
Claude Opus 4.8 responds that deriving an exclusion from pricing, the novelty of the risk, or the presumed intention of the parties would effectively amount to creating an implied exclusion.
This second confrontation clearly shifts towards FALSE, with a score of 95%, which has a significant impact on the final synthesis of the debate.
The legal provisions and concepts discussed
The tournament is structured mainly around Articles L.113-1, L.113-2 and L.12-10-1 of the French Insurance Code, together with references to French Court of Cassation case law concerning exclusion clauses.
The report notably brings into confrontation the concepts of “formal and limited” exclusions, burden of proof, uncertainty, contractual scope of coverage and the specific legal regime applicable to cyber insurance.
Examples of links used in the debates:
https://www.legifrance.gouv.fr/codes/article_lc/LEGIARTI000006791984
https://www.legifrance.gouv.fr/codes/section_lc/LEGITEXT000006073984/LEGISCTA000047048143
https://www.courdecassation.fr/decision/5fca262d4504b03b8a33c152
Did the wording of the question influence the debate?
Yes, quite significantly.
The proposition states in general terms that an insurer “may refuse” compensation, without specifying whether the damage first falls within the scope of coverage actually provided under the policy.
This lack of precision gives TRUE its strongest argument — the distinction between an absence of coverage and an exclusion — while also allowing FALSE to challenge the proposition in its general formulation.
Interestingly, the FALSE side eventually acknowledges the relevance of this distinction itself, before limiting its reasoning to losses that already fall within the scope of the insured risks.
A legal context specific to cyber risk
The debate takes place against a broader background of increasingly serious cyberattacks. Even governments are struggling to protect their citizens’ data — as illustrated by the 2026 hacking of the French ANTS system, reportedly resulting from a remarkably basic vulnerability according to Korben.
The threat is not limited to governments. Businesses and all types of organisations are also heavily exposed.
Cyberattacks do not merely target data. Increasingly, their objective is to disrupt or paralyse the operations of a company, institution or organisation.
Debate summary
| Description | Details |
|---|---|
| View the original report | https://solsicelegal.com/public/debates/en-droit-francais-un-assureur-peut-refuser-d-indemniser-un-s-61f0d995430c |
| 23 pages | |
| Original language | French |
| Scores | Weighted scores: TRUE 0.70 (70%); FALSE 0.95 (95%). Final verdict: FALSE — confidence 58% |
| Think-tank AIs | 3 debating AIs, excluding the arbitrator-clerk: z-ai/glm-5; openai/gpt-5.4-mini; anthropic/claude-opus-4.8 |
| Arbitrator-clerk | deepseek/deepseek-v4-flash |
| Data | Glossary: no dedicated glossary section identified. 9 tables in total in the PDF, corresponding to 5 distinct datasets |
| Quiz language | French |