Your Underwriter Became Your AI Regulator: What Cyber Insurers Are Asking For in 2026
Dr. Abeer Alshammari · Published 8/25/2026
The most effective AI governance enforcement mechanism operating inside most organisations right now is not a regulator. It is a renewal date. Regulatory timelines slip, guidance goes back out for consultation, and enforcement takes years to reach a first contested case. An insurance renewal arrives on a fixed day, and the questionnaire in front of it has to be answered in writing by someone who can be held to the answer.
Over the past year the policy wordings have moved considerably faster than most governance programmes have. Many organisations are discovering that at renewal rather than in advance of it.
The wordings moved first
Two shifts matter. The first is exclusionary: standard commercial general liability forms began carrying generative-AI exclusion endorsements from January 2026, and cyber and technology errors-and-omissions policies have increasingly sub-limited AI-related loss rather than covering it silently under existing grants. The second is conditional: a number of carriers now make cover for AI-related incidents contingent on named controls, packaged as an "AI security rider" rather than sitting inside the base policy.
Separately, the Lloyd's Market Association's revised state-backed cyber exclusions moved the test away from attributing an attack to a particular state and towards whether the attack significantly impaired the functioning of a state's essential services. That is a quiet but consequential change for anyone whose incident-response plan assumed attribution disputes would take years to resolve. The coverage question now turns on impact evidence you may need to produce quickly.
What underwriters are actually asking for
The questions being put at submission are converging on a short and fairly consistent list:
- A current inventory of AI systems, models and AI-enabled vendor features in production -- including the ones procured by business units without security review.
- Documented pre-deployment risk assessments for each system, covering intended use, known limitations, training-data provenance and monitoring arrangements.
- Dated evidence of adversarial testing for any system that can read or act on production data, usually expected to map to the NIST AI Risk Management Framework or MITRE ATLAS.
- A clear map of where human oversight sits, and what the system is permitted to do without it.
None of this is novel as governance. What is novel is that failing to answer, or answering in a way you cannot evidence, now carries an immediate and quantified commercial price.
Where claims will actually be contested
Read the exclusions rather than the marketing. The recurring triggers across AI riders are narrow and specific: action taken by the system outside its defined scope; deployment without the audit telemetry the policy requires; known defects not disclosed at submission; and intentional misuse.
Three of those four are governance failures, not security failures. "Outside its defined scope" presumes a scope was defined and written down before deployment. "Audit telemetry" presumes agent actions are logged in a form an adjuster can read months later. "Known defects not disclosed" presumes the people who ran your red team and the people who completed your insurance submission spoke to each other. Organisations that treat the underwriting questionnaire as a procurement chore rather than a governance artefact are manufacturing the gap that will later be used against them.
Build one evidence pack, not three
The practical response is consolidation. The AI system inventory, the risk assessments, the adversarial testing record and the human-oversight map are the same four artefacts demanded by ISO/IEC 42001 certification, by the EU AI Act's technical documentation obligations, and by the underwriter. Most organisations are currently producing them three times, in three formats, for three audiences, and keeping none of the three current.
Maintain one control-evidence pack, versioned, with dates on everything, and generate the three views from it. The version history does more work than the content ever will: an assessment dated before deployment is evidence, while the same assessment reconstructed after an incident is closer to an admission.
The governance point
Insurance has become an accidental conformity-assessment regime for AI. That is not an ideal outcome. Underwriters are pricing risk, not setting public policy, and the controls they name tend to reflect what is cheap to verify rather than what most reduces harm. But it does settle a question boards have been circling for two years. AI governance now has a number attached to it, and the number appears on a renewal quote.
Treat the questionnaire as the first audit you get to fail cheaply. Every audit after it costs more.
Try it yourself
An interactive CyberAbeer experience for this topic is in development.
Coming soon