AI has joined the risk conversation, but it hasn't rewritten the rules (yet)
A new insurance category isn't the answer
Every renewal conversation now touches AI somewhere. Whether a business has built an AI product, plugged a large language model into its customer service or simply started using AI tools internally, the question of "how does this affect our insurance?" is coming up more often.
The honest answer is AI is not creating a new, standalone category of insurance. Instead, it is reshaping how existing covers, mainly professional indemnity (PI) and cyber, need to respond. The businesses that get this right will not need anything out of the ordinary, just good governance, the right disclosure, and a broker who is actually asking the right questions.
AI businesses vs AI adopters
There is a distinction between two types of businesses.
The first is the AI business: a company where AI is the product. These businesses tend to be in a reasonably good position, because the AI element is disclosed upfront. Insurers know what they are underwriting, categorise the risk accordingly, and price it on that basis. There is no hidden exposure because the fact they are an AI business tells insurers all they need to know.
The second, larger group is the AI adopter: a traditional business using AI tools internally, often without a formal review process. This is where the real work sits and is often more of a governance question rather than an insurance one. Does the business know where AI is being used across the organisation? Are there controls around data, outputs, and decision-making? Is AI use reflected on the risk register?
Well-governed businesses in this second group should generally be fine. The exposure comes from AI use that nobody has mapped, rather than AI use that has been properly identified and managed.
Do you need dedicated AI cover?
In short, no. Dedicated, standalone AI insurance policies are unlikely to become a mainstream policy in the near term. The more relevant question is how insurers are responding to AI exposure within the policies businesses already hold, particularly Professional Indemnity and Cyber insurance.
Most insurers currently treat AI as sitting within their existing technology risk frameworks, rather than as something requiring a new policy. What the market is still working through is how explicit that position needs to be in the policy wording itself, which brings us to the current sticking point.
Silent cover vs affirmative wording
Technology policies, which most AI-based business would be insured under, are tailor to pick up civil liabilities and technology errors and omission. Meaning, if something is not excluded, it is covered. This means most policies currently provide "silent" AI cover. AI-related claims are not specifically mentioned, but nor are they excluded, so in principle they would respond, provided the claim arises from an insured event that isn't otherwise excluded under the policy.
The alternative is "affirmative" cover, where an insurer adds explicit wording confirming that AI-related claims fall within scope. This is generally better for clients, because it removes ambiguity about how a claim will be treated.
Having spoken with several of the insurers most active in this space, it is clear that all of them are moving in the direction of affirmative wording. Some are already treating AI as something to be addressed head-on in the policy. Others are progressing more cautiously towards the same outcome, and a smaller number are taking a wait-and-see approach, preferring to observe how claims and case law develop before committing to specific language.
None of this is cause for alarm. It reflects a market that’s still adapting, not one that is unwilling to cover AI risk at all. And the direction of travel is moving towards more explicit language over time, which is a positive for policyholders. In the meantime, businesses that are doing the right things on governance and controls should not expect their cover to be materially worse off, whether the wording in front of them is silent or affirmative.
.png?width=856&height=482&name=2026%20Blog%20Images%20%20(13).png)
So, what does good governance actually look like?
That governance question is crucial with systems that take actions on a business's behalf rather than just producing an output.
Firstly, keep an immutable record of everything an AI system does, so you can prove if it acted outside its bounds. Secondly, build governance into the infrastructure itself, with guardrails enforced by the system rather than written into a policy that sits on a shelf, so the AI genuinely cannot act outside them. Thirdly, tie it together with an orchestration layer, so the process stays coherent and controlled rather than a set of checks that don't join up.
This applies to any business using AI, but especially those selling agentic systems, who should be able to show it's built in. And it's exactly what a claim comes down to, evidence of if the AI system overstepped its bounds, and evidence that you met a reasonable best practice on governance. If this is in place, it matters far less whether your policy wording is silent or explicit on AI.
Why cyber touches every business, not just tech ones
AI adoption, by definition, increases a business's technology exposure. Every AI tool sits on top of data, systems, and integrations, and each of those is a potential point of failure or attack. This reinforces the case for cyber cover.
As our Co-Founder & Broking Director, Liam Green, puts it: "There isn't a business without a single tech exposure. AI does not create that exposure from nothing; it just accelerates risk that was already there.”
Despite that, there is still a gap between the businesses that need cyber cover and the ones that actually buy it. Just 10% of UK businesses hold a standalone cyber insurance policy, and even once you count cover bundled into wider policies, that only rises to 47%, despite technology touching nearly every part of how they operate. AI adoption is only widening that gap between exposure and protection.
The broker question that matters most
None of the above works without the right broker relationship. It’s vital to have someone who understands the business well enough to spot how your AI exposure surfaces in your insurance programme.
A good broker should be asking specific questions – where (and how) is AI being used across the business? Is that reflected on the risk register? And which insurer partners are actually thinking seriously about AI risk? If a broker is not talking to you about AI, disclosure, and insurer appetite as part of the renewal conversation, you could be left exposed.
If you want to talk through how AI use in your business might affect your existing cover, get in touch!
Disclaimer: This content has been produced for general information purposes and should not be taken as formal advice. You should always seek specific professional advice before acting on any of the information given.