If you were in the industry during the “silent cyber” era, you may remember how it played out—unpriced risk sitting inside policies, coverage ambiguity that felt manageable, until claims volumes made it anything but.
What silent cyber taught us about pricing risk
Silent cyber was the insurance industry’s term for cyber risk that accumulated inside traditional policies—like general liability and property—without ever being explicitly priced or excluded. It cost the industry billions in unexpected claims and forced carriers to retroactively rewrite policy language they should have addressed years earlier.
Now, we’re seeing the same patterns showing up with AI, and it’s already affecting numbers.
Stanford HAI’s 2026 AI Index Report found that documented AI incidents rose to 362—up from 233 the year prior. That’s a 55% jump in one year. And according to Gallagher’s 2026 AI Adoption and Risk survey, roughly one in five insureds have already experienced economic losses or filed insurance claims tied to AI-related risks.
As it turns out—in addition to the policyholders who built their own AI—the exposure is also coming from the AI embedded in the vendors themselves.
Your Policyholders’ Vendor Stacks Are Full of AI
Whether they know it or now, almost every commercial policyholder in your book is using AI right now:
- Their CRM added a copilot.
- Their HR platform auto-ranks candidates.
- Their customer service tool runs on a large language model.
Most of these features rolled out in routine software updates with no procurement review, no disclosure, and no risk assessment—creating a massive visibility gap.
Skyhigh Security’s 2025 data shows that 89% of enterprise AI usage was invisible to organizations, with most AI interactions happening without central oversight. And BigID’s AI risk report found that 64% of organizations lack full visibility into their AI risk exposure—with nearly half having no AI-specific security controls in place.
If your policyholders can’t see their own AI exposure, your underwriters definitely can’t either. Traditional submission questionnaires—the ones built around firewalls, compliance certifications, and revenue bands—don’t capture this. That means every commercial submission you’re reviewing today has AI risk insurance implications baked into it, whether the applicant discloses it or not.
RELEVANT: 5 Steps to Stabilize Your Operations when Claims Volumes Spike
How One AI Incident Can Trigger Four Denials at Once
You may have already seen a version of this play out on your claims desk. A policyholder’s AI-powered customer service tool gives a client bad financial advice, causing the client to sue. The policyholder then files a claim, and every line of coverage has a reason it doesn’t apply:
- Cyber policy claims no breach occurred.
- Professional liability says the new AI-output carve-out applies.
- General liability points to the January 2026 ISO (Insurance Services Office) endorsements.
- Media liability argues machine-generated content isn’t “your” content.
Early data is telling the same story. Gallagher’s survey found that of those insureds who experienced AI-related losses, just over half were covered in full. Another 44% were only partially covered, and roughly 3% were entirely uninsured. When nearly half of early AI claims fail to pay in full, it’s an indication of a larger hurdle worth tackling proactively.
The Third-Party AI Exclusion
The January 2026 ISO exclusions made the market’s direction clear. And the exclusion worth watching most closely targets third-party AI tools—losses tied not to AI the policyholder built, but to AI embedded in their vendors’ products and services.
That exclusion reaches every SaaS product in the stack that added an AI feature without notice. And because most policyholders don’t even know which of their vendors are using AI, they’re self-insuring without realizing it.
According to Gallagher Re, the market’s already responding. Gallagher Re’s Q1 2026 InsurTech Report found that 95% of InsurTech funding in Q1 2026 went to AI-focused companies—with InsurTechs focused on AI liability and cyber insurance alone raising over $440 million in the quarter. Capital is flooding in because investors see a pricing vacuum. And Stanford HAI’s 2026 AI index confirms that responsible AI benchmarks aren’t keeping pace with capability benchmarks—almost all leading model developers publish performance results, but reporting on safety and governance remains spotty.
In other words, the AI systems creating exposure for your policyholders are advancing faster than anyone’s ability to assess their risk. That’s a gap your insurance pricing strategy needs to account for right now.
Traditional actuarial models won’t work
There’s no 20-year loss history for AI liability. Actuarial tables don’t exist for hallucination risk or model drift. This suggests that pricing variables need to change.
Here are some factors that could drive that premium differentiation in your AI risk insurance approach today:
- What the AI does: Consumer-facing, decision-making AI—like chatbots, underwriting tools, and hiring screeners—is a fundamentally different risk than internal productivity tools. Price accordingly.
- Degree of human oversight: Ask about autonomy levels, human checkpoints, and rollback procedures. Policyholders who can document human-in-the-loop controls will find themselves safer and more insurable.
- Vendor concentration: If 60% of a policyholder’s vendor stack runs on the same foundation model, a single model failure becomes a correlated loss event across your portfolio. That’s not a per-risk question. It’s a portfolio accumulation question.
- Governance maturity: Does the insured have an AI inventory? Do their vendor contracts require AI disclosure? Is there documented oversight? Governance is becoming underwriting currency—the stronger the documentation, the more confidently you can price.
We’re seeing the affirmative market already taking shape. The Willis Research Network’s May 2026 Risk and Resilience Review highlighted the March 2026 launch of HSB’s AI Liability Insurance—designed to fill gaps where standard general liability wording doesn’t cleanly cover AI-related bodily injury, property damage, or AI-generated content. It’s an early signal that carriers are starting to price affirmatively rather than just exclude.
READ NEXT: Compliant Modernization For Data and AI in Insurance
The Silent Cyber Lesson
The carriers that got ahead of silent cyber—who clarified language, built new products, and priced the risk affirmatively—gained market share. And they set the standard the rest of the industry eventually followed.
Silent AI is the same inflection point, and the total addressable exposure is even larger. Gallagher Re reports that global InsurTech funding hit $1.63 billion in Q1 2026—the highest since late 2022— signaling that the market is already moving to fill this gap.
A bottleneck worth considering is your talent. You need underwriters who understand AI systems, actuaries who can build scenario models for risks without long loss histories, and AI governance specialists embedded in underwriting teams. And we’re seeing that talent getting scarcer—Stanford HAI found that the number of AI researchers and developers moving to the U.S. has dropped 89% since 2017, with an 80% decline in the last year alone.
For carriers, this is an opportunity to own the next chapter of commercial underwriting
Insight Global helps insurers build the teams that close this gap—from AI governance specialists and data scientists to underwriting talent with technology fluency. Chat with us to find out what your team needs.
Talk to Insight Global's Insurance Experts
Questions? Call us toll-free: 855-485-8853

by Emilie Skaug 


