Cyber Insurance: How AI Changed the Rules
CyberKainos. Reading time: 6 mins
And what insurers are now asking for
At some point since your last renewal, your cyber insurer has probably (and quietly) rewritten the rules. Not through a phone call or a letter, but in the policy wording itself and through a growing set of questions on the renewal form that didn’t use to be there. If your organisation has been adopting AI tools without a documented governance programme to show your cyber insurer, the gap between what you think you’re covered for and what you actually are may be much wider than you realise. This isn’t a future risk. It will have already shaped a lot of 2026 renewals, and will continue to do so into 2027.
The questions insurers ask have changed regarding cyber insurance
Cyber insurers previously covered AI-related risk implicitly, without ever naming AI directly. Cyber insurance professionals call this ‘silent AI’ cover: not explicitly excluded, but never explicitly included either. That ambiguity is now closing fast.
Insurers are getting more specific about what they’ll ask before they’ll write your policy. By some industry estimates, the large majority of cyber insurance firms (over eight in ten by recent counts) now build AI governance questions directly into renewal applications such as:
- Do you have a written AI use policy defining which tools are approved and how data can be used within them?
- Can you demonstrate that staff have been trained on AI misuse?
- Do you hold a documented AI risk assessment covering which tools are in use and what controls manage the exposure?
- Is AI governance folded into your existing security programme or handled informally on the side?
- Has AI been involved in any prior incident at your organisation?
- Do you actively audit which AI tools are genuinely in use, rather than assuming your policy document reflects reality?
Answer these well, and you’re in a strong position. Answer with anything else, including ‘we’re working on it’, and you should expect that to show in your cyber insurance premium and your terms.
The exclusions are getting explicit too
At the same time, insurers are also narrowing what “silent AI” cover actually protects you against. In January 2026, the Insurance Services Office introduced a new generative AI exclusion into standard commercial general liability policies, specifically carving out bodily injury, property damage, and advertising related claims arising from generative AI use. Separately, and more pointedly for boards, several insurers have introduced broad “absolute” AI exclusions into management liability lines, employment practices, and fiduciary liability policies that protect directors and officers personally, not just the company.
That last point should land clearly at board level: this isn’t only about whether the company’s cyber policy pays out after an incident. It’s increasingly about whether the protection that directors themselves rely on still covers a claim that traces back to an AI-related decision or failure. Cover isn’t disappearing everywhere, but it’s fragmenting, with narrower definitions, tighter carve-backs, and underwriting positions that assume you have nothing in place unless you can prove otherwise.
The UK picture: adoption is racing ahead of governance
The exposure is particularly stark for UK organisations right now. Recent industry data suggests 97% of UK businesses are either using or actively exploring AI.
Meanwhile, 59% of UK businesses have experienced a cyber ‘event’ in 2026 so far, and 59% of those incidents involved a supplier in some way. Perhaps most tellingly for anyone thinking about supplier risk, 75% of UK businesses worry about cyber risk stemming from their suppliers’ AI use, yet only 28% actually audit the AI systems their third parties are using.
This is the gap underwriters are now pricing in. Insurers are responding with sharper supplier classification requirements, tighter contractual security expectations, and revised wording around business interruption and data compromise that originates through a third party.
Put simply: AI adoption is outrunning AI governance, and insurers, whose entire business model depends on pricing that gap accurately, have (unsurprisingly) noticed.
Why this issue belongs on the board’s agenda, not just the broker’s
It’s tempting to leave this conversation to whoever renews the insurance policy each year, but that rather downgrades what’s actually happening. A declined claim, a narrowed policy, or a steep premium increase at renewal isn’t an operational inconvenience, it’s a direct financial consequence of a governance gap the board should be responsible for closing. It’s a great example of when management liability exclusions widen, exposure increasingly reaches the boardroom, not just the balance sheet.
The finance-minded framing is straightforward: the cost of building basic AI governance now is a known, budgetable expense. The cost of discovering a coverage gap after an incident, when a claim is reduced, delayed, or denied outright because you can’t produce the documentation an underwriter expected, is neither known nor budgetable. It’s exactly the kind of asymmetric risk boards exist to manage.
What “insurable” actually looks like
The encouraging news is that cyber insurance firms are being clear in what they are asking for, and what they consider good AI governance looks like when evidencing that AI is integrated into your existing security programme:
- Written AI acceptable use policies that are actually followed rather than filed away.
- Staff training, complete with completion records.
- Documented risk assessments covering the AI tools in use across the business (including the ones staff adopted without asking).
- A named, accountable owner who can produce all of the above credibly when a renewal application (or a claim) requires it. This is precisely the gap a vCISO closes: not just building the governance programme itself, but making sure it’s documented, current, and defensible the moment an insurer or a claims adjuster asks to see it.
The bottom line
Your cyber insurer isn’t waiting for regulation to catch up with AI risk; they are already pricing it in. Organisations that treat AI as a governance priority will walk into their next cyber insurance renewal with answers, and secure better terms as a result. Those that don’t will find out the hard way exactly how ‘silent’ their AI cover really was.