The insurance industry does not need a standalone AI policy - yet. That was the central takeaway from a KYND webinar on 1 September 2026, where senior cyber insurance leaders agreed that AI exposure is already embedded in existing lines, particularly cyber and technology errors and omissions. But the panel identified a more urgent problem: undeclared AI use by employees and suppliers is creating a visibility gap that leaves insurers unable to assess or price the risk they are underwriting.
One panellist described AI as the next stage of technology risk rather than a separate category. The cause of a loss still determines which policy responds. If an AI-powered hiring tool discriminates against candidates, the resulting exposure remains an employment and legal issue, with the business liable as it would be for a human decision. Companies developing their own AI may face a different set of exposures and could require more dedicated cover.
Human accountability remains at the centre of AI liability
Human involvement was a recurring theme throughout the discussion. The panel said someone still selects the technology, creates the prompts, and determines how much autonomy an AI system is given. The cases examined were linked to inadequate guardrails or systems being used outside their intended limits, rather than software operating entirely independently. The panel suggested organisations should treat AI agents in a similar way to employees - with clear rules, controlled access, and accountability for their actions.
Establishing that responsibility is more straightforward when AI is developed internally. It becomes more complicated when technology is purchased from a third party or incorporated into a supplier's product. For professionals managing these risks, understanding the chain of accountability is becoming essential. Courses such as AI for Insurance Courses are responding to this need by helping underwriters and claims teams map liability across increasingly complex technology supply chains.
Undeclared AI is the visibility gap insurers cannot ignore
The strongest consensus centred on undeclared AI - tools used by employees or suppliers without the organisation's knowledge or approval. Verizon's 2026 Data Breach Investigations Report found regular AI use on corporate devices had quadrupled in a year to 45% of employees, with 67% of that activity taking place through personal accounts that businesses cannot monitor. Gartner expects more than 40% of organisations to experience a security or compliance incident linked to unauthorised AI tools by 2030. Capgemini found 42% of property and casualty insurers had not measured their AI outcomes.
The webinar highlighted a potential tension between tighter AI governance and employee behaviour. Restricting access to approved tools could encourage some employees to turn to alternatives on personal devices. The panel discussed the importance of providing sanctioned AI tools that meet employees' needs rather than relying solely on restrictions. KYND drew a parallel with shadow IT, noting that its work identifying those risks has informed a forthcoming feature designed to help identify AI technologies being used by businesses.
Claims data is already missing the AI signal
AI is already appearing in insurance claims, though insurers may not always recognise or record it as an AI-related loss. Claims systems generally lack a specific category for AI, and establishing whether AI contributed to an incident can be difficult. An IBM study cited during the webinar found around one in four malicious breaches were AI-enabled, with an average cost of roughly $6 million - approximately $1 million higher than a conventional breach.
The panel had differing views on what this means for insurers. Some participants viewed AI as creating a systemic exposure with similarities to catastrophe risk. Others considered the underlying risk largely unchanged, with AI instead making certain capabilities cheaper and more widely available. That could affect the frequency and severity of losses while leaving insurers with the possibility of pricing for the exposure.
Aggregation risk sits in a handful of frontier models
Aggregation emerged as one of the most significant areas of concern. Between 60% and 80% of the market relies on the same small group of underlying frontier models. A major problem affecting one provider could create losses across a significant portion of an insurer's portfolio. The panel called for insurers to develop a more detailed understanding of their exposure to individual models, including dependency and concentration. This would also require pricing approaches capable of distinguishing between different underlying technologies.
Greater visibility only becomes useful if insurers act on the information. The panel noted that insurers already have visibility into areas such as cloud concentration, but this does not always translate into changes in pricing or underwriting appetite. Identifying AI use at the point of underwriting could provide a more detailed picture of exposure than relying on periodic questionnaires. For regulatory affairs teams navigating these emerging requirements, AI Regulatory Compliance Courses offer structured guidance on building oversight frameworks that capture AI-specific exposures.
Why this matters for insurance professionals
The webinar did not resolve whether AI will become a standalone insurance class, nor was that the objective. Instead, the discussion made three things clear: AI involvement alone does not determine whether a claim is a cyber claim, undeclared AI represents a significant visibility gap, and insurers cannot properly assess or price an exposure they cannot see. The scale of that challenge is changing rapidly. One panellist described a business already running almost all of its operations on AI, illustrating how different the risk profile could become as organisations move from experimenting with AI to making it fundamental to their operations. For underwriters, claims handlers, and risk managers, the immediate priority is not a new product line - it is building the capability to see what is already on the books.
Your membership also unlocks: