CFOtech US - Technology news for CFOs & financial decision-makers
United States
Insurers warned of hidden AI exposure across portfolios

Insurers warned of hidden AI exposure across portfolios

Fri, 24th Jul 2026 (Today)
Karen Joy Bacudo
KAREN JOY BACUDO Finance Editor

KYND has warned that insurers may be building hidden exposure to artificial intelligence across their portfolios as businesses adopt AI faster than they disclose it.

That disclosure gap can allow AI use to go undetected during underwriting, leaving insurers with concentrations of risk that may not become visible until claims emerge.

Insurance underwriting depends on policyholders disclosing how they use technology in their operations. KYND said that process is being tested by the speed at which organisations are introducing AI tools into routine business functions, often without clearly reflecting that use in insurance discussions.

In KYND's view, the issue is less about whether AI should sit within cyber, professional indemnity or other lines of cover, and more about whether insurers can identify where AI is already embedded in their books. Hidden use of common AI models or platforms across multiple insureds, it argued, could create accumulation risk.

"Many organisations are embedding AI into everyday business processes, but that isn't always being reflected in underwriting conversations. Rather than focusing solely on where AI should sit within policy wordings, insurers should be prioritising visibility of AI adoption across their portfolios. AI-related claims are already emerging, so understanding those exposures before claims materialise will be critical to assessing and pricing risk effectively. Without that visibility, insurers risk hidden accumulation exposure, particularly where multiple policyholders rely on the same underlying AI platform or model. Identifying those concentrations early will be key to building more resilient portfolios," said Aaron Aanenson, Head of Insurance, North America, at KYND.

Claims emerging

KYND's white paper argues that AI-related losses are no longer theoretical. It pointed to disputes already arising over inaccurate outputs, copyright infringement and bias, even though insurers still have little historical claims data to judge how those exposures might develop.

That lack of data leaves the market in a position similar to the early stages of cyber insurance, when exposures built up within broader policies before underwriters had a clear view of the scale of the risk or how to price it. KYND compared the current moment with the build-up of so-called silent cyber, when insurers discovered that cyber-related losses could attach to policies not explicitly designed to cover them.

Research cited by KYND shows that 77% of organisations now use ChatGPT, underscoring the breadth of AI adoption across the economy. For insurers, that suggests the challenge is not confined to technology companies or specialist risks, but could run through a wide range of commercial portfolios.

Market participants are already responding by trying to limit exposure in some areas. The debate has been particularly active in the US, where insurers and standard-setting bodies have been examining how AI exclusions should apply in general liability and other forms.

A spokesperson for a specialist cyber MGA said: "I think the only thing the industry is keeping up on is excluding AI from areas it doesn't want exposure to. In the US, you've seen a lot of general liability and ISO forms introducing AI exclusions - very similar to what they did when cyber became a thing, taking general liability off the table. Where we haven't quite settled is in the E&O and cyber space: how it fits, what would actually be triggered."

Visibility challenge

The concern for insurers is that exclusions alone do not solve the problem of measuring aggregate exposure. If several insured businesses depend on the same third-party AI service, a flaw, outage or legal challenge linked to that service could affect multiple policyholders at once.

That creates a portfolio management issue as much as a wording issue. Underwriters may need to know not just whether a client uses AI, but which systems it uses, where they sit in workflows, and how central they are to decision-making, customer interactions or content generation.

For companies buying insurance, the warning also points to growing scrutiny of technology disclosures. As AI tools become part of everyday operations, businesses may face more detailed questions from insurers about their use of external models, internal controls, governance and oversight.

KYND said the industry's immediate task is to improve visibility rather than wait for a fuller claims record to emerge. Insurers that fail to identify concentrations early, it argued, may discover only after losses occur that exposure had accumulated across multiple policyholders using the same underlying AI platform or model.