AccuroAI
Products
What We Do
Solutions
Company
Resources
Book demo
← Blog·Strategy10 read

The AI Questions on Your Next Cyber Insurance Renewal

Silent AI coverage is ending the way silent cyber did, compressed into months. The exclusion filings, the survey numbers from the people pricing your risk, the affirmative products emerging on the other side — and the six questions to prepare evidence for now.

J
James Okafor
Field CISO
2026-08-18

For two decades, AI risk was covered by your liability policies for a boring reason: nobody had thought to exclude it. Insurers call this "silent" coverage, and it is ending the way silent cyber ended — except compressed into months instead of years. Effective January 1, 2026, the insurance industry's standard-forms body introduced three generative-AI exclusion endorsements for general liability, and by July, an analysis of roughly ten thousand state filings found more than 60 property and casualty insurance groups had filed to adopt AI exclusions (41 groups) or schedule them (20 more). One carrier, W.R. Berkley, has an absolute AI exclusion (Form PC 51380) attaching to D&O, employment practices, and fiduciary coverage parts — excluding "any actual or alleged use, deployment, or development of Artificial Intelligence."

Which means your next renewal is not last year's renewal. The questionnaire is growing an AI section, the coverage you didn't know you had is being carved out, and the underwriter across the table has already formed a view: in a joint Allianz Commercial/D&O Diary survey published August 4, 91.2% of insurer respondents said a lack of transparency about AI use should negatively affect the underwriting assessment. The people pricing your risk have decided that opacity costs you money. This post is the preparation guide.

Last verified: August 20, 2026. Insurance terms vary by policy and jurisdiction — verify specifics with your broker.

What changed, with dates

WhenWhatWhy it reaches you
Jan 1, 2026ISO/Verisk generative-AI exclusion endorsements become available for attachment: CG 40 47 (broad — bodily injury, property damage, and personal & advertising injury "arising out of generative artificial intelligence"), CG 40 48 (limited — Coverage B only), CG 35 08 (products/completed operations)The standard machinery for pulling AI out of general liability now exists; each renewal is a chance for it to appear on yours
Jul 23, 2026Trade analysis of ~10,000 filings: 60+ P&C groups filed to adopt or schedule AI exclusionsThis is not a fringe experiment; it is the market moving
2025–2026Carrier-specific exclusions surface — W.R. Berkley's absolute AI exclusion on D&O/EPL/fiduciary lines; press reports of carriers seeking regulator permission for AI exclusions (AIG later stated it has no current plans to implement them)Management-liability lines — where AI governance failures land — are in scope first. Notably, brokers report no AI exclusions on cyber or tech E&O products yet (Lockton, July 2026) — the carve-outs are arriving through GL and D&O
Aug 4, 2026Allianz Commercial/D&O Diary survey (250 industry professionals): 94% say boards should approve AI-use policies; 94% say poor AI governance increases D&O claim likelihood; ~80% expect D&O underwriters to request additional AI-risk informationThe consensus view of the people who will underwrite, broker, and litigate your AI risk

And the claims backdrop explains the urgency: Gallagher Re documents a 978% rise in generative-AI-related US lawsuits from 2021 to 2025 (137% in the last year alone), and the FBI's 2025 internet-crime report introduced its first dedicated AI category — 22,364 complaints, $893M in reported losses. The subtlety insurers' own claims data adds: Resilience's H1 2026 analysis found 85.3% of incurred losses came from human-error attacks — phishing, social engineering, transfer fraud — up from 17.7% two years earlier, with zero losses yet from AI-native vectors like prompt injection. AI is supercharging the old attacks before it creates new ones, which is exactly why the renewal questions focus on deepfake training, payment controls, and data governance rather than model internals.

The questions to expect on the application

Broker advisories from 2026 renewals converge on a specific, auditable list. Aon's practical agenda (May 2026) and compliance-firm guidance describe underwriters increasingly expecting:

  1. An AI tool and model inventory — what AI is in use, including the unsanctioned layer. "We don't really know" is now an underwriting data point, and not in your favor.
  2. AI governance documentation — a board-approved usage policy (the thing 94% of the survey says boards should own), named ownership, and a risk-assessment process for new AI deployments.
  3. Data-leakage safeguards — what prevents sensitive data from reaching AI tools, and what evidence exists that it works.
  4. Human-oversight points — where people review AI-driven decisions and actions, documented, especially for anything customer-facing or financial.
  5. Testing evidence — pre-deployment risk assessments and, for systems touching production data, red-teaming or adversarial-testing records.
  6. Third-party AI exposure — which vendors embed AI in services you depend on, and how that is assessed.

Read that list twice and you'll notice something: it is an AI governance platform's output, item for item. The inventory is discovery. The leakage safeguard is DLP with logs. The oversight points are approval gates. The evidence is the audit trail. Organizations running governance tooling answer the questionnaire by exporting reports; organizations without it answer by drafting prose and hoping.

The other side of the ledger: AI coverage you can now buy

The market isn't only subtracting. A wave of affirmative AI products launched in the last eighteen months — Lloyd's-backed AI liability cover for model underperformance and hallucinations (Armilla with Chaucer, April 2025, extended as Vanguard AI in February 2026), a Lloyd's MGA writing dedicated genAI liability explicitly targeting the gap the ISO exclusions create (Testudo, with capacity reaching $9.25M per insured), Munich Re-backed performance cover for AI vendors (Mosaic × aiSure, up to $15M), and cyber carriers folding affirmative AI events into base policies (Coalition, from April 2025) or across whole product suites (CFC, mid-2026). Even American Express's agent purchase protection belongs to this family — AI-error underwriting, conditioned on governance.

The pattern across every one of these: affirmative AI cover is underwritten on governance evidence. The exclusions punish opacity; the new products reward documentation. Same artifacts either way.

The honest premium picture

Two things are true at once. Brokers describe a soft cyber market — buyer-friendly pricing through 2026, rates well off their 2022 peak — while S&P forecasts cyber premiums rising 15–20% in 2026 on AI-driven threats, and security-leader surveys report both directions personally: in Delinea's survey of 750+ security leaders, 42% said their cyber policies already contain AI exclusions, while 86% reported premium reductions or credits for AI-based security controls. The synthesis: soft pricing, hardening scrutiny. The rate environment is kind; the questions are not; and demonstrated AI controls are already being priced in — in your favor.

The renewal-prep checklist (start 90 days out)

  1. Run AI discovery and produce the inventory before the application asks — including shadow usage, because a broker-visible gap between your stated and actual AI estate is the worst possible finding.
  2. Get the AI usage policy board-approved and dated. It is the single most-requested artifact.
  3. Export the evidence pack: DLP event logs, approval-gate records, agent inventory with access posture, framework mappings.
  4. Ask your broker two questions in writing: which AI exclusions have been added or filed on each of our lines, and what affirmative AI options exist for the gap.
  5. Check the definition. ISO's generative-AI definition is broad ("a machine-based learning system... with the ability to create content or responses"); understand what of yours falls inside it before the carrier decides for you.
  6. If you deploy agents that act autonomously, raise it proactively — standard-forms bodies are already weighing agentic-AI exclusions as the next wave.

FAQ

Will disclosing more AI use raise our premium?

The survey data says the opposite risk is bigger: insurers penalize opacity (91.2% of insurer respondents), and 86% of security leaders report credits for demonstrated AI controls. Disclosure with evidence reads as maturity; discovery of undisclosed use at claim time reads much worse.

Do the ISO exclusions apply to us automatically?

No — they're optional endorsements carriers attach at renewal. Which is exactly why the renewal conversation matters: the moment of attachment is the moment to negotiate scope or price the alternative.

Our AI risk is "just employees using ChatGPT." Does any of this apply?

That is precisely the exposure the questionnaires probe — workforce AI use, data leakage, and governance. And it's the easiest version to evidence well: discovery plus DLP logs answer it in two exhibits.

What's the one thing to do this quarter?

The inventory. Every question on the application assumes you have one; every affirmative product underwrites on it; and it's the artifact that takes longest to produce honestly. (It is also the first thing our 72-hour pilot delivers, which is not a coincidence — the renewal questionnaire and our reporting describe the same evidence.)

Sources: D&O Diary / Allianz Commercial survey results (Aug 4, 2026) · The Insurer — 60+ P&C groups file AI exclusions (Jul 23, 2026) · Claims Journal on ISO forms CG 40 47 / CG 40 48 / CG 35 08 and Gallagher Re litigation data · Fenwick & West — The End of "Silent AI"? (Jun 2026) · Aon — AI Risk 2026: A Practical Agenda (May 2026) · Munich Re — Cyber Insurance: Risks and Trends 2026 · Delinea 2025/26 cyber insurance research · FBI IC3 2025 report · Armilla/Chaucer, Testudo, Mosaic × aiSure, Coalition, CFC.

Related: Why AI Governance Just Became a Board-Level Job · Agentic AI Governance ROI · Who's Liable When Your Agent Makes a Bad Purchase? · Executive Reporting.

See AccuroAI in action.
30-minute demo tailored to your top AI risk.
Book a demo
More from the blog
See AccuroAI in action.

Book a 30-minute demo and see how security teams use AccuroAI to discover, govern, and protect every AI asset across their organization.

Book a demoTalk to security