Undeclared AI is the exposure insurers can’t yet price

Undeclared AI is the exposure insurers can’t yet price

The cyber insurance market is still treating AI largely as an extension of existing technology risk, rather than as a reason to create a separate insurance category. But as businesses introduce AI tools across their operations, insurers are facing a different problem: they do not always have visibility into where the technology is being used or the risks it may create.

That issue was a central theme of KYND’s Cyber Drop webinar on 1 September. The session brought together senior figures from the cyber insurance sector to build on the InsurTech firm’s The Wild West of AI Risk white paper. Panellists generally agreed that AI-related risks can be covered through existing cyber and technology errors and omissions (E&O) policies. However, businesses developing their own AI systems may require dedicated cover for the exposures created by those systems. One panellist characterised AI as the next phase of technology risk.

How responsibility is assigned is another consideration. The panel pointed to human involvement in decisions around AI, including the choice of tool, the way it is prompted and the level of autonomy it receives. The losses discussed were linked to inadequate guardrails or AI being used outside its intended limits, rather than the technology operating entirely independently.

One proposal discussed during the session was to approach AI agents in much the same way as employees, giving them specific rules and controlled access. That becomes less straightforward when an organisation obtains AI from a third party or the technology is incorporated into a supplier’s product. In those circumstances, identifying who is responsible for an outcome can become more difficult.

A larger concern for insurers is AI activity that remains outside the view of the organisation itself. Employees and suppliers can use tools without declaring them, potentially leaving IT teams unaware of their use. Verizon’s 2026 Data Breach Investigations Report found that regular AI use on corporate devices had increased fourfold in a year, reaching 45% of employees. It also found that 67% of this activity was taking place through personal accounts outside business oversight.

The wider research cited during the webinar points to similar concerns. Gartner forecasts that more than 40% of organisations will experience a security or compliance incident related to unauthorised AI tools by 2030. Capgemini, meanwhile, found that 42% of property and casualty insurers have not yet measured their AI outcomes.

The panel also raised a potential consequence of how businesses respond to this problem. Introducing stricter controls around AI may improve oversight, but could also encourage employees to turn to unauthorised tools if the approved alternatives do not perform adequately.

The impact of AI is already making its way into claims, although insurers may not always be able to identify it. Claims systems lack a dedicated category for AI in many cases, while establishing whether AI played a role in an incident can be difficult. An IBM study referenced during the webinar found that approximately one in four malicious breaches were AI-enabled, with an average cost of around $6m. This was approximately $1m higher than the average cost of conventional breaches.

There was disagreement among panellists about what this means from an insurance perspective. Some viewed AI-enabled breaches as a systemic exposure that could resemble catastrophe risk, while others considered the underlying risk unchanged, with AI instead allowing it to become more widely distributed.

The concentration of AI models introduces another potential source of exposure. Between 60% and 80% of the market relies on a relatively small group of frontier models. As a result, an issue affecting one provider could potentially extend across multiple businesses and insurance portfolios.

Understanding that concentration therefore depends on insurers being able to see which models are being used and where dependencies exist. Model-by-model visibility could provide a clearer picture of how exposure is distributed and support the assessment and pricing of AI-related risk.

The discussion ultimately suggests that the immediate question for cyber insurance is not whether AI needs its own product. Instead, it is whether insurers can obtain enough information about how AI is being deployed to understand the risks already sitting within existing policies. KYND’s Cyber Drop webinar highlights this visibility challenge across undeclared AI use, claims attribution and concentration around frontier models.

Read the full KYND analysis.

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our weekly InsurTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.