Undisclosed AI use threatens cyber insurance portfolios

Undisclosed AI use threatens cyber insurance portfolios

KYND, the cyber risk intelligence specialist, has rolled out an AI discovery capability that lets cyber insurers detect AI technologies across a company’s online estate, reducing their dependence on what policyholders choose to disclose.

Starting from a single domain, the tool allows underwriters to map the AI technologies running across a business’s external digital footprint without asking the business for any input. This gives insurers an independent, observed data source to sit alongside proposal forms and underwriting discussions.

The detection covers AI assistants and chatbots, generative AI tools, AI embedded in marketing and commerce technology, and the AI crawlers that an organisation’s infrastructure allows.

The release arrives as fast-moving AI adoption presents insurers with a mounting problem. Underwriters are under growing pressure to understand how companies deploy AI and what exposures follow, yet that judgement often rests on self-reported information. Adoption can also outpace an organisation’s ability to oversee and govern the technology.

IBM data shows that one in five organisations suffered a breach last year linked to ‘shadow AI’, meaning AI used without formal sign-off or governance. Organisations with high levels of shadow AI faced breach costs averaging $670,000 more than those with little or none.

When used consistently across a book of business, KYND’s data can also help portfolio and reinsurance teams see where shared AI technologies and dependencies recur across multiple insureds, allowing them to investigate possible concentrations of exposure.

KYND provides cyber risk intelligence to the insurance market. AI detection forms one part of its broader technology detection offering, which identifies payment and cloud services, analytics, tracking pixels, session-recording tools, identity and access management, and the platforms on which websites are built.

This helps insurers understand the technology dependencies behind individual risks and potential concentrations across portfolios.

The launch extends KYND’s research into silent AI exposure within insurance portfolios. Its recent white paper, The Wild West of AI Risk, cautioned that companies are taking up AI faster than they report it.

This could leave exposure undetected at underwriting and allow concentrations to accumulate across insurers’ books. The new capability aims to start closing that visibility gap by adding independently observed technology data to self-declared information.

KYND co-founder Melanie Hayes said, “Proposal forms and underwriting conversations remain essential, but AI use is changing rapidly and businesses themselves may not always have complete oversight of the technologies being used across their organisation.

“Giving underwriters independently observed information means the conversation can start with greater visibility of what is detectable on the risk, helping underwriters ask more informed questions and build a clearer picture of the exposure.”

Hayes added, “As AI becomes more deeply embedded across businesses, insurers will increasingly need to understand where common technologies and dependencies are appearing across their books.

“The industry is still building its understanding of how AI-related losses will develop. Being able to identify those dependencies now gives insurers a stronger foundation to understand and manage exposure as it evolves.”

Enjoying the stories?

Subscribe to our weekly InsurTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.