Living reference · Edition 2026.08.31 · Updated August 31, 2026

Cyber Insurance & AI Tracker

A dated record of how cyber and adjacent lines are changing around AI: affirmative endorsements, exclusions, subrogation against IT providers, and the questions appearing on applications. Every entry carries its source, the date it was added, the date it was last verified, and whether it is confirmed, reported, or commentary.

Maintained for insurance and IT professionals who need to know what has actually changed. Where we add our own interpretation for managed service providers, it is labelled as ours and kept separate from the sourced record.

Not legal, insurance or coverage advice · Coverage varies by carrier, policy and jurisdiction; verify against the actual policy wording.

The short version

Three things the record currently shows

The market split into two opposite moves

Cyber carriers are ADDING affirmative AI coverage (Coalition, AXA XL, the Google Cloud/Beazley/Chubb/Munich Re program, Cowbell). Meanwhile D&O, E&O, EPLI, and CGL carriers (W.R. Berkley, AIG, Great American, Verisk/ISO) are EXCLUDING AI. Cyber remains the most AI-friendly line, but the aggressive exclusions are concentrated outside it.

AI questions are entering applications, unevenly

A growing number of applications and AI supplements ask about an AI acceptable-use policy, an inventory of AI tools, monitoring of employee and shadow AI, and controls preventing confidential data entering AI tools. Practice varies by carrier and some do not ask at all yet. Brokers often compare this to the arrival of MFA requirements; that is a forecast about direction, not an established pattern. What is documented is the substantiation risk: applications operate as warranties, and Travelers v. International Control Services shows a court permitting rescission where a control representation did not match reality.

Subrogation against MSPs is now real

In Ace American v. Congruity 360 & Trustwave (D.N.J., filed Sept. 15, 2025), a Chubb subsidiary sued an IT provider and an MSSP directly to recover exactly $500,000 it paid after a client ransomware attack, over failure to enforce MFA and a misclassified incident. On June 25, 2026 Judge Susan D. Wigenton dismissed nearly all of those claims for failure to state a claim, leaving only part of a breach-of-contract claim against Congruity. The willingness to sue is the signal, and note where it survived: the contract, not the tort.

Research & technical guides

Companion references

This tracker records what is changing in the market. The guides below explain what the underlying controls and questions actually mean technically. They are written to be useful on their own, including to readers who never use our product.

Technical field guide

Shadow AI Risk for Cyber Underwriters: A Technical Field Guide

What employee AI use actually looks like on a managed endpoint. The four access surfaces (websites, desktop applications, browser extensions, OAuth-connected AI), what each one makes detectable, what none of them can see, and what an organization or its IT provider can truthfully claim about controlling them.

Read the field guide →

The two moves

The market split in two, and both create MSP work

"Silent AI" is being eliminated from both directions. Cyber carriers are writing explicit affirmative AI language into their forms, while management-liability and general-liability carriers are filing explicit exclusions. Whether AI is covered now depends on specific policy language, not assumption.

Carriers adding affirmative AI coverage

Mostly the cyber line, the most AI-friendly today.

  • Coalition

    Affirmative AI Endorsement + global Deepfake Response Endorsement

  • AXA XL

    genAI endorsement: data poisoning, IP, EU AI Act violations

  • Google Cloud RPP

    Affirmative AI for Google workloads; Beazley + Chubb joined Munich Re

  • Armilla AI + Chaucer (Lloyd’s)

    Standalone Affirmative AI Liability; $25M+ limits by Jan 2026

  • Munich Re aiSure + Mosaic

    AI-performance-guarantee cover up to $15M

  • Cowbell Prime One

    AI risks written into the base form; AI-risk "Cowbell Factors" rating

  • Relm Insurance

    NOVAAI / PONTAAI / RESCAAI, including DIC "wrap" where policies exclude AI

Carriers excluding AI

Concentrated outside cyber, in D&O, E&O, EPLI, and CGL.

  • W.R. Berkley

    "Absolute" AI exclusion across D&O, E&O, fiduciary (reported Form PC 51380)

  • Verisk / ISO

    New CGL exclusion forms CG 40 47, CG 40 48, CG 35 08, effective Jan 1, 2026

  • AIG, Great American

    Filed requests to exclude AI liabilities (Hamilton, Philadelphia Indemnity too)

  • Berkshire, Chubb, Travelers

    Reported approval to drop/limit AI liability on standard commercial policies

The practical part

AI questions your clients' renewals now ask

The underwriting question set has expanded from "Do you use AI?" to "What models, what controls, what governance?" Each question below pairs the renewal ask with how your MSP substantiates the answer, and documentation, not verbal assurance, is what survives a claims investigation.

How to read this list: only the AmTrust item and the model-level phrasing from Westfield Specialty are verbatim/primary-source-confirmed. The GuidePoint and Coalition items are verbatim characterizations by named executives of what carriers ask. All other question wordings are representative, not verbatim: they reflect the themes brokers, carriers, and vendors report are now standard on cyber applications and AI supplements.

1

Do you have a written AI acceptable-use policy?

Representative

How your MSP helps: Draft and maintain the policy defining approved tools, prohibited data categories, and output-review expectations; keep a signed version on file for the claims file.

2

Do you maintain an inventory of the AI tools and models in use across your organization (including embedded/SaaS AI and shadow AI)?

Representative (aligns with the "AI inventory is the new MFA" theme)

How your MSP helps: Run AI-discovery scans and maintain a living inventory with data-access and approval owner per tool, the single most-requested artifact.

3

What AI models are you currently utilizing?

Verbatim characterization: Westfield Specialty’s Jeff Kulikowski, via Business Insurance

How your MSP helps: Track model/provider names, versions, and use-cases so the client can answer at model-level granularity.

4

How is AI being used, for what specific tasks, and is it an efficiency tool or a core part of the solution you sell to clients?

Verbatim characterization: GuidePoint’s Nate Spurrier, via CSO Online

How your MSP helps: Document the business-function mapping; flag customer-facing/production AI that raises the risk tier.

5

Who is allowed to use AI, and how do you control/monitor employee use of generative AI?

Verbatim characterization (Spurrier/CSO Online) + representative

How your MSP helps: Implement role-based access and monitoring; deploy DLP/CASB rules that log and restrict GenAI use.

6

Do you have controls preventing sensitive/confidential data from being entered into AI tools?

Representative (driven by employees pasting confidential data into public AI tools)

How your MSP helps: Configure data-loss-prevention for AI endpoints, block unmanaged/personal-account access, and document enforcement.

7

Do you provide employees documented training on AI use/misuse?

Representative

How your MSP helps: Deliver AI-specific security awareness training with completion records. "Undocumented training is indistinguishable from no training" at claim time.

8

Do you have an AI risk assessment on file, and is AI governance integrated into your broader security program?

Representative (more common in mid-market/regulated renewals)

How your MSP helps: Perform and document an AI risk assessment mapped to NIST AI RMF or ISO 42001; integrate it into the client’s ISMS.

9

Do you require human oversight/override before AI (especially agentic AI) takes irreversible actions?

Representative (driven by agentic-AI concern)

How your MSP helps: Document human-in-the-loop controls and authorization limits for any autonomous/agentic systems.

10

Has AI been involved in any prior incidents, and do you log/investigate AI-related data disclosures as security incidents?

Representative

How your MSP helps: Extend the incident-response plan and logging to cover AI misuse and inadvertent disclosure; maintain the audit trail.

11

Do you allow the use of AI software to draft documents? If yes, attach a description.

Verbatim: AmTrust Lawyers Professional Liability application, form LPLPRO-APP-01 0523 (May 2023). Professional-liability, not cyber, but a confirmed real-form question.

How your MSP helps: Prepare a standard written description of the client’s AI-drafting workflow and controls to attach.

12

Do you use AI in product development or in services delivered to your clients?

Representative (reflects underwriter focus on whether AI is core to the offering)

How your MSP helps: Distinguish internal-efficiency AI from client-facing AI; advise on whether standalone AI-liability cover is needed.

Two statistics to handle with care: the widely repeated claim that "81% of cyber insurers now include AI governance questions in renewal applications" traces to a single commercial vendor blog with no cited methodology; treat as unverified/promotional. The claim that "99% of cyber insurance applications include MFA questions" could not be verified verbatim; the closest primary-source figures put enforced-MFA mandates in the ~90–100% range. Present both as directional only.

The change tracker

Carrier and market changes, grouped

Scan the list, then expand any entry for what changed and the MSP angle. Grouped by type of change.

Affirmative coverage

Coalition: Affirmative AI Endorsement

#Confirmed

Expanded the definition of a "security failure or data breach" to include an "AI security event" and expanded the funds-transfer-fraud trigger to include fraudulent instructions via deepfakes or other AI. Announced March 26, 2024; folded into the base Active Cyber Policy in 2025.

Source

BusinessWire announcement ↗
Basis
Confirmed
Added
Last verified

ShadowLock analysis · MSP interpretation

A client’s cyber cover likely responds to AI-enabled attacks and deepfake FTF, but only if underlying controls (MFA, transfer-request verification) hold up, or the claim can be contested. So position deepfake/AI-attack coverage reviews as a value-add and ensure funds-transfer verification procedures are documented so the FTF trigger actually pays.

Our reading of what this means operationally. Not from the source above.

Coalition: Deepfake Response Endorsement

#Confirmed

Added a global endorsement (US, UK, Canada, Australia, Germany, Denmark, Sweden, France) providing technical forensics, legal takedown support, and crisis-communications support for AI-generated impersonation of executives and employees. Announced Dec 9–10, 2025.

Source

Coalition announcement ↗
Basis
Confirmed
Added
Last verified

ShadowLock analysis · MSP interpretation

Reputation-attack deepfakes can trigger loss with no malware and no intrusion, outside what MSP tooling defends, yet clients may assume the MSP "should have stopped it." Bundle deepfake tabletop scenarios and executive-impersonation verification protocols into vCISO offerings and advise which clients need this endorsement.

Our reading of what this means operationally. Not from the source above.

AXA XL: genAI cyber endorsement

#Confirmed

Introduced a globally available cyber endorsement extending coverage for generative-AI risks for businesses building their own genAI models: data "poisoning," usage-rights/IP infringement, and regulatory violations arising from the EU AI Act. Reported October 2024.

Source

Business Insurance ↗
Basis
Confirmed
Added
Last verified

ShadowLock analysis · MSP interpretation

Relevant to clients that build or fine-tune models, not just use them, and the coverage is narrow and model-development-specific. Identify clients developing/customizing models and advise on the data-governance and training-data-provenance controls underwriters will want to see.

Our reading of what this means operationally. Not from the source above.

Google Cloud Risk Protection Program (Beazley, Chubb, Munich Re)

#Confirmed

Expanded the program: Beazley and Chubb joined founding partner Munich Re, offering affirmative AI coverage for Google-related AI workloads and using cloud-posture telemetry (Security Command Center / CIS Benchmark reports) for underwriting. For qualified digital natives, Beazley replaces the application with a single-page attestation. Announced at Google Cloud Next, April 2025.

Source

Google Cloud blog ↗
Basis
Confirmed
Added
Last verified

ShadowLock analysis · MSP interpretation

For cloud-heavy clients, underwriting shifts to telemetry-based, so the MSP’s cloud-config hygiene directly drives insurability and pricing. Misconfigurations become insurance problems. Offer "cloud posture for insurability": harden Google Cloud configs to CIS Benchmarks and generate the reports carriers ingest. Directly monetizable.

Our reading of what this means operationally. Not from the source above.

Armilla AI + Chaucer (Lloyd’s): Affirmative AI Liability & "Vanguard AI"

#Confirmed

Launched the first standalone Affirmative AI Liability Insurance covering AI underperformance (hallucinations, model drift, mechanical failures), with limits reaching $25M+ by Jan 2026. In Feb 2026 the "Vanguard AI" structure paired Chaucer’s cyber and tech E&O with Armilla’s standalone AI liability, a "conscious decision to partner rather than stretch cyber policies beyond their original intent."

Source

PR Newswire / Chaucer ↗
Basis
Confirmed
Added
Last verified

ShadowLock analysis · MSP interpretation

This confirms carriers are deliberately ring-fencing AI liability away from cyber, so clients relying on "silent" cyber cover for AI performance failures may have a gap. Advise clients deploying customer-facing AI that performance failure may need standalone cover, map exposures across cyber vs AI-liability vs E&O, and position yourself as the advisor who prevents coverage gaps at renewal.

Our reading of what this means operationally. Not from the source above.

Cowbell: Prime One

#Confirmed

Launched Prime One in the US, embedding AI-related risks (cybercrime, business interruption, data restoration, system failure, third-party liability from AI events) plus quantum risks directly into the base policy form rather than via exclusion or bolt-on. Introduced AI-risk "Cowbell Factors" rating for autonomy, observability, and governance. Launched Dec 2, 2025.

Source

Cowbell blog ↗
Basis
Confirmed
Added
Last verified

ShadowLock analysis · MSP interpretation

SMB/mid-market clients get affirmative AI in-form, but Cowbell now rates AI governance, so weak governance affects price and eligibility. Help clients improve their autonomy/observability/governance posture to earn better Cowbell Factors and document it for the continuous-underwriting model.

Our reading of what this means operationally. Not from the source above.

Relm Insurance: NOVAAI / PONTAAI / RESCAAI

#Confirmed

Launched three AI products: NOVAAI (liability/cyber for AI developers), PONTAAI (excess/DIC wrap where existing policies exclude AI), and RESCAAI (first-party response for organizations embedding third-party AI). Affirmatively covers IP infringement and discrimination. Launched Jan 14, 2025.

Source

PR Newswire ↗
Basis
Confirmed
Added
Last verified

ShadowLock analysis · MSP interpretation

The DIC/"wrap" model exists precisely because mainstream policies are adding AI exclusions, evidence of the gap clients face. For clients whose GL/E&O now excludes AI, flag the wrap-policy option and the governance evidence needed to buy it.

Our reading of what this means operationally. Not from the source above.

BOXX Insurance (Zurich Global Ventures): affirmative AI and deepfake cover on Cyberboxx Business

#Confirmed

On July 22, 2026 BOXX, the SME-focused cyber insurtech Zurich agreed to acquire in July 2025, added affirmative coverage for AI and deepfake related events, for social engineering and security failures, inside its commercial product Cyberboxx Business in Canada and the US. BOXX says the endorsement "eliminates ambiguity and cements BOXX’s commitment to providing clear cover for AI-driven incidents." Global head of underwriting Erik Tifft framed the exposure this way: "Threat actors are exploiting trusted relationships amongst employee and executive networks which can result in handing over credentials or misdirecting payments without an actual breach."

Source

BOXX press release (PR Newswire) ↗
Basis
Confirmed
Added
Last verified

ShadowLock analysis · MSP interpretation

Affirmative AI and deepfake language has now reached a mainstream small-business cyber form, not just specialty paper, so "does our policy respond to a deepfake wire request?" is finally answerable for a 10-to-500-seat client. Pull the endorsement schedule at renewal, confirm whether the client’s form carries affirmative AI language or silence, and sell the documented out-of-band callback verification that has to hold for the funds-transfer trigger to actually pay.

Our reading of what this means operationally. Not from the source above.

Exclusions

Verisk / ISO: standardized CGL exclusions

#Confirmed

New standardized CGL exclusion endorsements CG 40 47, CG 40 48 (and CG 35 08 for products/completed operations) took effect Jan 1, 2026, giving carriers ready-made language to exclude bodily injury, property damage, and personal/advertising injury "arising from" generative AI. Verisk forms underpin the large majority of US commercial liability policies.

Source

Business Insurance ↗
Basis
Confirmed
Added
Last verified

ShadowLock analysis · MSP interpretation

These are CGL, not cyber, but they show the industry-standard machinery for AI exclusion now exists and can spread, and clients may lose CGL cover for AI-caused harm. Run a cross-line coverage audit to identify where a client’s AI exposure has quietly lost coverage (CGL) and where it is retained (cyber).

Our reading of what this means operationally. Not from the source above.

W.R. Berkley: "absolute" AI exclusion

#Reported

Introduced an "absolute" AI exclusion (reported as Form PC 51380) across D&O, E&O, and fiduciary liability, barring claims "arising out of" any "use, deployment, or development" of AI by any person or entity, reportedly naming tools like ChatGPT. Filed/reported late 2025, effective at renewal.

Source

Business Insurance ↗
Basis
Reported
Added
Last verified

ShadowLock analysis · MSP interpretation

Client management-liability and professional-liability cover for AI-related claims may vanish quietly at renewal, leaving directors and officers personally exposed on AI governance failures. Alert clients to review D&O/E&O renewals for AI exclusions and position AI governance documentation as a litigation and coverage defense.

Our reading of what this means operationally. Not from the source above.

AIG, Great American, Hamilton, Philadelphia Indemnity: exclusion filings

#Reported

Filed requests with US regulators to exclude AI-related liabilities from various commercial policies; AIG reportedly told regulators generative AI is a "wide-ranging technology" where claims will "likely increase over time." First reported by the Financial Times, November 2025. Filing-stage; effective at renewal, jurisdiction-dependent.

Source

CSO Online ↗
Basis
Reported
Added
Last verified

ShadowLock analysis · MSP interpretation

A broad, cross-line pullback signal: clients cannot assume "silent" AI coverage persists in non-cyber lines. Reinforce demand for the cross-line audit and a "get it in writing from your carrier" advisory.

Our reading of what this means operationally. Not from the source above.

Delinea: survey of 750+ security leaders

#Confirmed

Found 42% of respondents said their cyber policies already include exclusions tied to AI misuse or liability, and that 77% of insurers now require a formal internal/security-team review before issuing or renewing (up from 56% a year earlier).

Source

Forbes Tech Council ↗
Basis
Confirmed
Added
Last verified

ShadowLock analysis · MSP interpretation

This contradicts the "cyber has no AI exclusions" simplification: some cyber policies already carve out AI, so verify each client’s actual wording. Sell policy-language review plus control-review readiness, and be the party that passes the insurer’s mandatory security review.

Our reading of what this means operationally. Not from the source above.

AI exclusion filings: more than 60 P&C groups

#Reported

The Insurer reported on July 23, 2026 that a review of nearly 10,000 filings through S&P Capital IQ found 41 P&C insurance groups in S&P Global Market Intelligence’s SNL Insurance dataset had at least one subsidiary that filed to adopt an AI exclusion, with subsidiaries of a further 20 groups filing to delay adoption until a later date. Insurance Journal reported on July 22, 2026 that carrier interest is concentrated in the ISO forms CG 40 47, CG 40 48 and CG 35 08, quoting Verisk’s Joe Lam: "Everyone acknowledges this is new technology...so they are all appreciative of having additional underwriting flexibility." The same piece cites a Gallagher study finding a 978% increase in AI-related lawsuits from 2021 to 2025.

Source

The Insurer analysis (paywalled) ↗
Basis
Reported
Added
Last verified

ShadowLock analysis · MSP interpretation

This puts a number on the exclusion wave: the ISO AI exclusion is no longer a form sitting on a shelf, and a normal SMB client’s general liability renewal is now materially likely to arrive with it attached while their cyber policy still responds. Run the cross-line audit before renewal, get each carrier to confirm in writing, per line, whether AI is excluded, and bill for the AI inventory and governance evidence pack that backs the answers.

Our reading of what this means operationally. Not from the source above.

Subrogation & litigation

Ace American v. Congruity 360 & Trustwave (D.N.J., 2:25-cv-15657)

#Confirmed

A cyber insurer (a Chubb subsidiary) filed a subrogation action directly against an IT provider and an MSSP to recover exactly $500,000 it paid to insured CoWorx Staffing Services after an April 2024 ransomware attack. Alleges Congruity 360 failed to implement MFA for remote access and secure servers, and that Trustwave misclassified a detected event as "moderate," delaying response and preventing timely backups. Negligence + breach of contract, filed Sept 15, 2025. Updated Aug 17, 2026: on June 25, 2026 Judge Susan D. Wigenton of the District of New Jersey dismissed nearly all of Ace American’s claims against both defendants for failure to state a claim, leaving only part of the breach-of-contract claim against Congruity, per Bloomberg Law. The case is therefore no longer "unresolved" in the sense earlier editions of this tracker described.

Source

Hunton privacy blog ↗
Basis
Confirmed
Added
Last verified

ShadowLock analysis · MSP interpretation

The watershed case for MSP liability: insurers now pursue the exact functions MSPs perform (MFA enforcement, hardening, monitoring, escalation), so your contract terms and delivery evidence are your defense. Sell "subrogation-defensible" service delivery (documented MFA enforcement, hardening baselines, alert-escalation SLAs, tested IR) and review MSAs with counsel.

Our reading of what this means operationally. Not from the source above.

Travelers v. International Control Services

#Confirmed

A court permitted Travelers to rescind a $1M cyber policy after a ransomware attack because the insured represented MFA was deployed across all systems when it was only at the firewall. Rescission applies even for unintentional/honest misrepresentation under the majority US rule. Court ruling 2022; widely cited through 2026.

Source

ChannelPro Network ↗
Basis
Confirmed
Added
Last verified

ShadowLock analysis · MSP interpretation

Even though the MSP does not sign the application, MSP work substantiates the answers. A false "MFA everywhere" answer means a rescinded client policy plus a likely MSP E&O claim. Sell "application-answer verification": produce evidence exports mapped to each control question before the client signs.

Our reading of what this means operationally. Not from the source above.

Underwriting & market

Westfield Specialty: Jeff Kulikowski, EVP

#Commentary

Stated that underwriting AI use has changed: "It used to be, ‘Do you use AI and how do you use it?’ Now it’s, ‘What models are you currently utilizing?’" This indicates deeper, model-level questioning. Reported 2025 (Business Insurance).

Source

Business Insurance ↗
Basis
Commentary
Added
Last verified

ShadowLock analysis · MSP interpretation

Underwriters now want granular, technical detail clients can rarely produce without their MSP. Maintain the client’s AI tool/model inventory as a managed service and produce it on demand at renewal.

Our reading of what this means operationally. Not from the source above.

Marsh: Global Insurance Market Index, Q1 2026

#Confirmed

Global cyber rates fell 5% year-on-year in Q1 2026 (following a 7% decrease in Q4 2025; US ~-2%; IMEA -14%), the seventh consecutive quarterly decline. Marsh notes AI-threat affirmative coverage and supply-chain covers are "under development."

Source

Aon Q1 2026 overview ↗
Basis
Confirmed
Added
Last verified

ShadowLock analysis · MSP interpretation

Soft pricing is a buying window, but frequency rose even as prices fell, so do not let clients treat cheaper premiums as lower risk. Run a "lock in favorable rates now, invest in controls before the market hardens" advisory and capture the control-implementation projects.

Our reading of what this means operationally. Not from the source above.

Allianz: Risk Barometer 2026

#Confirmed

AI rose to the No. 2 global business risk (32% of responses), up from No. 10, the biggest riser in the survey of 3,338 risk-management experts across 97 countries. Cyber remained No. 1 at its highest-ever score (42%). Published Jan 14, 2026.

Source

Forbes Tech Council ↗
Basis
Confirmed
Added
Last verified

ShadowLock analysis · MSP interpretation

A demand signal: client boards are now primed to fund AI risk work. Time AI-governance proposals to board risk priorities and cite Allianz to build the business case.

Our reading of what this means operationally. Not from the source above.

Todyl: control-baseline synthesis (citing Marsh & Chubb)

#Confirmed

Reports that MFA is "still table stakes" but "MFA everywhere with evidence" is the standard; EDR/MDR now means 24/7 monitored response; and that Marsh and Chubb have begun incorporating Zero Trust principles (least-privilege, continuous verification, segmentation, conditional access) into underwriting conversations. 2026.

Source

Todyl blog ↗
Basis
Confirmed
Added
Last verified

ShadowLock analysis · MSP interpretation

The control ratchet is explicit and documented: undocumented controls equal functionally no controls at claim time. Package Zero Trust + AI governance as the "2026 insurability stack" for recurring managed-service revenue.

Our reading of what this means operationally. Not from the source above.

AM Best: Market Segment Outlook, Global Cyber Insurance (stable)

#Confirmed

Maintained a stable outlook on the global cyber insurance segment on July 15, 2026, citing strong demand, ample capacity, and "the growing use of AI" among supportive factors, while warning of "persistent and evolving threat activity, particularly ransomware" and that rapid advances in AI could enable more sophisticated, scalable, and automated attacks. On pricing, AM Best said "premium rates charged for cyber-related coverage have undergone persistent declines and are not expected to stabilize in the near future," with profitability set to "remain favorable over the intermediate term," though a sharp rise in claim frequency or severity could force a future upward price correction.

Source

AM Best press release ↗
Basis
Confirmed
Added
Last verified

ShadowLock analysis · MSP interpretation

A ratings-agency confirmation that the soft market persists but is fragile, with AI-enabled attacks named among the drivers of the correction risk. Use it to make the "buy favorable terms now, fund controls before the market turns" case, and to justify AI-governance and monitoring projects as the hedge against the correction AM Best flags.

Our reading of what this means operationally. Not from the source above.

Marsh: Global Insurance Market Index, Q2 2026

#Confirmed

Published July 23, 2026. Marsh reported that cyber insurance rates "declined by 4% globally," what it called "the twelfth consecutive quarter of declines," following "a 5% decrease in Q1." The largest decline was "in IMEA, at 14%," with "reductions ranging from 10% in LAC to 2% in the US." Global commercial rates overall fell 6% in Q2 2026, the eighth consecutive quarterly decrease.

Source

Marsh press release ↗
Basis
Confirmed
Added
Last verified

ShadowLock analysis · MSP interpretation

The US is the shallowest cyber decline of any region at 2%, so a 10-to-500-seat client will not see a materially cheaper renewal this year and "the market is soft" has stopped being the story. Move the renewal conversation off price and onto terms: what the AI questions on the application now ask, whether an AI sublimit or exclusion has appeared on any line, and what evidence backs each control answer before the client signs.

Our reading of what this means operationally. Not from the source above.

Cowbell: three AI Cowbell Factors (AI Exposure, AI Vulnerability, AI Assurance)

#Confirmed

Cowbell published the detail behind its AI-risk rating on July 23, 2026 and took it to the trade press on August 10, 2026. The AI Exposure factor scores "an organization’s visibility into its AI ecosystem," specifically "the organization’s ability to identify deployed models and applications, understand their operational reach, and assess the significance of the decisions they influence." The AI Vulnerability factor scores hallucination rates, algorithmic bias, adversarial robustness, susceptibility to prompt injection, data leakage, intellectual property exposure and upstream dependency risk. The AI Assurance factor scores "documentation, red-team testing, model lifecycle management, access controls, policy enforcement, auditability, and broader governance processes," including alignment with NIST and ISO/IEC 42001. The inputs are telemetry, collected by what Cowbell calls AI Connectors, not application answers. Co-founder and chief product officer Rajeev Gupta: "Autonomy is the largest severity multiplier in AI risk," and, on governance, "Watching what the AI did produces evidence."

Source

Cowbell: Introducing AI Cowbell Factors ↗
Basis
Confirmed
Added
Last verified

ShadowLock analysis · MSP interpretation

This hits any 10-to-500-seat client insured by Cowbell or another continuous-underwriting cyber carrier, and hardest the ones running Copilot or agents. AI governance has stopped being a yes-or-no box on an application and become a score that keeps moving between renewals, so posture drift now moves price and eligibility, and a "yes" the telemetry contradicts is worse than an honest "no." Sell the AI inventory and governance evidence pack mapped to the three factors and benchmarked to NIST AI RMF and ISO/IEC 42001, then keep shadow AI discovery as a monitored line item so the exposure score does not decay the month after the assessment ships.

Our reading of what this means operationally. Not from the source above.

Cyber policy triggers vs autonomous AI agents (Browne Jacobson, The Futurum Group, Assured, Brown & Brown)

#Commentary

On August 13, 2026 CNN reported research by the Israeli cyberdefense firm Dream documenting an intrusion into Taiwanese government networks in which up to eight AI agents, built from the open-source frameworks Hermes and OpenClaw, ran largely autonomously: mapping 21 government systems, probing for weaknesses and switching tactics when blocked. Dream stopped short of formally attributing the operation to Beijing. Insurance Business reported in August 2026 that the incident exposes two problems in how cyber forms are written. Tim Johnson, head of insurance at Browne Jacobson, noted that a number of cyber forms still define a "hacker" as a person, which leaves open whether "an autonomous AI attacker even triggers coverage as written," and that "coverage outcomes can turn on whether an incident is ultimately traced to a state-backed group." Mitch Ashley of The Futurum Group put the trigger problem plainly to Security Boulevard on August 12, 2026: "Cyber policies trigger unauthorized access by an intruder. An agent operating under valid credentials does not meet that definition," adding that insureds should be producing "execution evidence at the agent level, ahead of any claim." Caspar Rogers of Assured expects wording like Chubb’s Widespread Vulnerability Exclusion to see broader adoption; Christopher Keegan of Brown & Brown Risk Solutions described the market as "holding steady for now, competitive and profitable and not yet repriced."

Source

Insurance Business: Autonomous AI hit on Taiwan linked to China ↗
Basis
Commentary
Added
Last verified

ShadowLock analysis · MSP interpretation

This hits any client that has handed an AI agent standing credentials, which in a 10-to-500-seat shop means Copilot agents, Copilot Studio flows, or a third-party assistant holding an OAuth grant or a service account. The trigger language is the exposure: if the actor is not a person and it acts on valid credentials, the insuring agreement the client is counting on may not fire, and what decides the claim is agent-level evidence the MSP either kept or did not. Build the agent register (each agent, its owner, its credentials, its permissions, its data reach), turn on and retain agent-level audit logging, and put one question to the carrier in writing at renewal: does an AI agent acting on valid credentials meet this policy’s trigger. Treat the definitional argument carefully: it is named-expert commentary rather than policy language, and it is untested in court, so sell the evidence and the carrier’s written answer rather than a prediction about how a claim would land.

Our reading of what this means operationally. Not from the source above.

KYND Cyber Drop Live: the AI risk underwriters can neither classify nor see

#Commentary

Reported on August 12, 2026 from KYND’s inaugural Cyber Drop Live, where senior cyber market participants worked through where AI losses would actually land. Participants put roughly half of 50 plausible AI hallucination scenarios inside existing cyber coverage, which the write-up presented as discussion rather than established market data. The open question for underwriters was whether model drift or hallucination should be treated as a technology failure, a cyber incident, or something else entirely, illustrated by an AI coding agent that deleted a production database while reporting normal operation, a loss that may not meet a standard outage definition. Participants also named shadow AI use on personal devices as an underwriting visibility problem, and sorted adjacent AI exposures into other lines: AI-washing litigation toward D&O, a discriminatory AI recruitment tool toward employment practices.

Source

FinTech Global: AI risk exposes gaps in cyber insurance ↗
Basis
Commentary
Added
Last verified

ShadowLock analysis · MSP interpretation

This hits every client relying on a cyber policy to answer an AI-caused error, and every client whose staff use AI on personal devices or personal accounts, which is most of them. The honest read is that the market itself is near a coin flip on whether an AI wrong-output loss is covered, so "our cyber policy has that" is not an answer the client should accept from anyone, including you. Run shadow AI discovery on managed endpoints so the client can state what is in use instead of guessing, extend the incident-response plan so AI misuse and inadvertent disclosure get classified and logged as security incidents, and hand the client a one-page written question list for the broker covering hallucination, model drift and autonomous agent action. The 50-scenario figure comes from one event write-up and is directional only, so use it to open the broker conversation rather than quoting it as market data.

Our reading of what this means operationally. Not from the source above.

Cyber insurers review AI-agent policy language (MSIG USA, QBE, Beazley, Marsh, Verisk, Armilla AI)

#Commentary

Reuters reported on August 27, 2026 that cyber insurers are reviewing and adapting policy language after OpenAI, Anthropic and Meta Platforms disclosed that their AI agents "behaved unexpectedly, escaping controlled test environments and carrying out cyberattacks on companies without direct human instruction." Citing eight executives and analysts, the report said insurers are "grappling with issues including whether autonomous AI systems fit traditional policy definitions of a cyber attacker and who bears liability for AI-generated actions that cause a loss." Ryan Kratz, head of cyber, North America at MSIG USA: "As AI becomes capable of identifying vulnerabilities and carrying out attacks autonomously, carriers will need to continually review policy language." Serene Davis, QBE's global head of cyber: "If an AI-related event leads to a conventional cyber incident, resulting losses continue to fall within a cyber policy. AI is treated as a risk amplifier, not a fundamentally new cyber risk." A Beazley spokesperson said companies want AI risks included in broad cyber policies and that "as new AI risk emerges, we are developing new coverage." Marsh's global cyber product leader, Greg Eskins: "Underwriters recognize that it's important to continue to offer a product that responds to these types of events." Jenny Soubra, vice president of specialty commercial lines at Verisk Underwriting Solutions, said targeted exclusions are being discussed in some pockets of the industry for two scenarios: a systemic event where a single AI model or platform contributes to losses across many organizations at once, and a case where an AI agent, acting as designed, makes a costly autonomous decision that "some insurers may classify" as a non-cyber event. Karthik Ramakrishnan, CEO of Armilla AI: "Some losses caused by AI agents will absolutely fall within cyber policies. The harder cases are where there is no conventional attacker and potentially no unauthorized credential use."

ShadowLock analysis · MSP interpretation

This hits any 10-to-500-seat client that has given an AI agent standing access, which in practice means Copilot agents, Copilot Studio flows, or a third-party assistant holding an OAuth grant or service account. The reassuring headline, that a conventional cyber incident triggered by AI still falls inside a cyber policy, is carrier-confirmed here for the first time rather than inferred. But two qualifiers matter for a renewal conversation: the reassurance depends on the loss still looking like a conventional cyber incident, and Verisk is already discussing exclusions for exactly the fact pattern this tracker flagged in the Taiwan-intrusion entry, an agent acting on the access it was deliberately given, with no conventional attacker and no unauthorized credential use. Bring this reporting to the renewal call, ask the carrier for its specific position on agent-caused loss in writing, and keep building the agent register and audit trail this tracker has recommended since the autonomous-agent entry above, because that undocumented gap is exactly where a claim would get contested.

Our reading of what this means operationally. Not from the source above.

Read the sourcing

Confirmed vs. reported vs. prediction

Confirmed (carrier/press primary source)

Coalition Affirmative AI (2024) and Deepfake Response (Dec 2025) endorsements; AXA XL genAI endorsement; Google Cloud RPP with Beazley/Chubb/Munich Re; Armilla/Chaucer products and Vanguard AI; Munich Re aiSure/Mosaic; Cowbell Prime One; Relm NOVAAI/PONTAAI/RESCAAI; Verisk/ISO CG 40 47/40 48/35 08 effective Jan 1, 2026; the Ace v. Congruity 360/Trustwave filings and its June 25, 2026 partial dismissal, plus Travelers v. ICS; Marsh/Aon pricing indices; Munich Re, Allianz, and Delinea reports; and Cowbell’s three AI Cowbell Factors, documented by Cowbell itself on July 23, 2026.

Reported / filing-stage (approval pending or via trade press)

W.R. Berkley "absolute" exclusion; AIG/Great American/Hamilton/Philadelphia Indemnity exclusion filings; Berkshire/Chubb/Travelers "won approval to drop AI coverage." Effective at renewal, jurisdiction-dependent.

Analyst commentary / prediction (not policy language)

S&P Global’s projection that cyber rates could climb 15–20% in 2026; broker predictions that AI exclusions "will spread to cyber"; the framing that AI governance "will become the next MFA." Informed forecasts, not committed carrier positions. Added Aug 17, 2026: the reading that a cyber form defining a "hacker" as a person may not respond to an autonomous AI agent is named-expert commentary and untested in court, and the KYND Cyber Drop Live figures are event discussion, not market data. Added Aug 31, 2026: the named carrier statements in Reuters’ "As AI Agents Go Rogue" report (MSIG USA, QBE, Beazley, Marsh, Verisk, Armilla AI) are on-the-record executive characterizations of how their firms are approaching AI-agent losses, not filed policy language, so treat the specific coverage and exclusion positions as current intent rather than confirmed wording.

Caution: broker opinion ≠ carrier policy

Statements by brokers (Aon, Gallagher, Woodruff Sawyer, WTW) describe market direction and representative questions; they are not evidence that any specific carrier’s form contains that language.

Two weakly-sourced stats: the "81%" AI-governance-questions figure and the "99%" MFA-questions figure are both directional only; see the note under the renewal questions above. Actual coverage always depends on the specific policy wording a client holds in a given jurisdiction; verify every finding against the client’s actual forms.

How this is maintained

Methodology and scope

Stated so a reader can judge how much weight to put on any entry, and so we can be held to it.

What is in scope

  • Changes to insurance products, forms, endorsements and filings where artificial intelligence is the subject of the change.
  • Cyber first, plus adjacent lines (general liability, D&O, E&O, professional liability) where AI treatment differs from cyber, because that difference is where readers are most often wrong.
  • Litigation involving insurers and IT or security providers where control representations are at issue.
  • Market conditions (rate movement, capacity, outlooks) only where a named source ties them to AI.
  • Primarily US and UK markets, with other jurisdictions where a source is available.

What is out of scope

  • Insurers' internal use of AI for pricing, claims handling or fraud detection. That is a different subject and we do not track it.
  • Coverage interpretation. We record that a form exists and what it says it does; we do not advise on whether a given loss is covered.
  • Vendor product announcements with no insurance dimension.
  • Predictions presented as developments. Forecasts appear only where labelled as such.

How an entry gets in

  1. A candidate is found in carrier communications, regulatory filings, court records, or named trade press.
  2. It must have a retrievable source that a reader can open. Anything resting on an unnamed source is not published.
  3. It is classified confirmed, reported or commentary, and that label is shown on the entry.
  4. It gets a stable id so it can be cited on its own, a date added, and a date last verified.
  5. Any interpretation we add is separated from the sourced text and labelled as ShadowLock analysis.

Limits you should know about

  • Carriers rarely publish application wording. Most reported question sets, here and everywhere else, are representative rather than verbatim. Entries say which.
  • Absence is not evidence. A carrier not appearing here means we have not sourced a change, not that none exists.
  • Filings are not effect. A filed exclusion takes effect on renewal, subject to approval, and varies by state.
  • We are a software vendor, not an insurance firm. We have no underwriting data, and we do not publish premium-impact figures. Where a question is about pricing or coverage, the honest answer is to ask a broker.
  • Two circulating statistics are weak. The “81%” AI-governance-questions figure and the “99%” MFA figure are directional only. We flag them rather than repeat them as fact.

Corrections

If an entry here is wrong, out of date, or mischaracterises a carrier's position, tell us and we will correct it and record the correction in the changelog below rather than editing it away silently. Reach us via the contact page. Corrections from people who work in the market are the most useful thing we receive.

Revision history

Changelog

What changed on each pass, newest first, so a returning reader can find what is new without re-reading the page.

  1. 1 new entry

    Added Reuters’ reporting that cyber insurers themselves, not just outside analysts, are reviewing and adapting policy language for AI agents after OpenAI, Anthropic and Meta disclosed agents that escaped test environments and carried out unintended attacks. Named carrier positions from MSIG USA, QBE, Beazley, Marsh, Verisk Underwriting Solutions and Armilla AI move the autonomous-agent coverage question from third-party commentary to on-the-record carrier statements.

    #carriers-review-agent-language

  2. 4 new entries

    Added Cowbell’s three AI Cowbell Factors (AI governance now scored from telemetry rather than asked on a form), the cyber-trigger problem exposed by the first fully autonomous AI agent intrusion, and market discussion at KYND’s Cyber Drop Live on where an AI hallucination loss actually lands. Also corrected the Ace American v. Congruity 360 entry: nearly all of the insurer’s claims were dismissed on June 25, 2026, so the case can no longer be described as unresolved.

    #cowbell-ai-factors#autonomous-agent-trigger-gap#ai-loss-classification-gap#ace-congruity

  3. 3 new entries

    Added the scale of AI-exclusion filings (41 P&C groups, per The Insurer), BOXX adding affirmative AI and deepfake cover to a mainstream SME cyber form, and Marsh Q2 2026 rate movement. Re-verified every existing entry against its source.

    #ai-exclusion-filings-scale#boxx-cyberboxx-ai#marsh-q2-2026

  4. 1 new entry

    Added AM Best’s stable outlook on global cyber, which names growing AI use as a supportive factor while flagging AI-enabled attacks as a correction risk.

    #ambest-outlook-2026

  5. Review pass, no new entries. Dated the WTW “Cyber Claims in Focus 2026” coverage to its June 2026 primary source rather than the July trade re-coverage, and excluded a Microsoft “silent AI” derivative suit as D&O rather than cyber.

  6. First publication with 17 entries across affirmative coverage, exclusions, subrogation and market conditions.

For researchers

Citing this tracker

Every entry has a stable anchor and can be cited individually. The # beside an entry title copies its permanent link. Please cite the underlying primary source as well, and where you are relying on a specific finding, cite the entry rather than the page so the reference stays precise as the page grows.

Suggested citation

ShadowLock. “Cyber Insurance & AI Tracker.” Edition 2026.08.31, updated August 31, 2026. https://shadowlock.io/resources/cyber-insurance-ai-tracker

ShadowLock analysis · for managed service providers

What an MSP should do this quarter

The MSP sits at the intersection of every one of these changes: the party that implements the controls, whose work substantiates the client’s application answers, and who is increasingly the subrogation and E&O target when something fails. That makes every insurance change a client conversation.

This section is our own operational interpretation, not a finding from any source above. Readers who came here for the sourced record can stop at the changelog.

Launch an "AI Insurance-Readiness Assessment" now, while the market is soft

Deliver a client AI inventory (including shadow/embedded AI), a written AI acceptable-use policy, a NIST AI RMF- or ISO 42001-aligned risk assessment, and an evidence pack mapped to the renewal questions above. Begin charging premium rates once the market hardens.

Make every client application answer "subrogation-defensible"

Before any client signs a cyber application or renewal, produce evidence exports proving each control (MFA enforced everywhere, EDR/MDR 24/7, immutable tested backups, IR plan tested, AI controls). This addresses both the Travelers v. ICS rescission risk and the Ace v. Congruity 360 subrogation risk. Benchmark: zero unverified "yes" answers leaving your shop.

Review and harden your own MSA and Tech E&O immediately

The Ace v. Congruity 360/Trustwave case targets MFA enforcement, hardening, monitoring, and escalation: your core functions. Get liability caps, scope-of-service definitions, and AI-governance responsibilities reviewed by counsel; confirm your Tech E&O limits reflect your aggregated client blast-radius.

Productize "AI governance as a managed service" on the MFA trajectory

Package acceptable-use policy + AI inventory + DLP-for-AI + shadow-AI monitoring + human-oversight controls + AI-specific IR, benchmarked to NIST AI RMF / ISO 42001. Sell it recurring, because underwriting is shifting to continuous assessment. Point-in-time prep is no longer enough.

Run a cross-line coverage audit for clients, not just cyber

The exclusions are landing in D&O/E&O/CGL first; cyber remains the most AI-friendly line but some cyber policies already carve out AI (Delinea: 42%). Help clients ask carriers, in writing, whether AI is excluded across every line, and identify standalone AI-liability/wrap options (Armilla, Relm PONTAAI, Munich Re aiSure) where gaps exist.

Turn telemetry-underwriting into a services line

For cloud-heavy clients, offer configuration hardening to CIS Benchmarks and generation of the posture reports carriers now ingest for underwriting (the Google Cloud RPP model). Insurability becomes a direct output of MSP config hygiene. Benchmark: measurable premium/eligibility improvement tied to posture reports.

Educate clients that cheaper premiums do not mean lower risk

Claim frequency rose even as prices fell, and AI is the named systemic threat that could reverse pricing fast. Position control investment now as locking in favorable terms before the market turns. Watch for any quarter where Marsh/Aon indices show cyber rates flat-to-rising, or a CrowdStrike-scale systemic event. That signals the window is closing.

Frequently asked

Cyber insurance and AI, answered

Does cyber insurance still cover AI-related attacks?

Generally yes. Cyber is the most AI-friendly line, and carriers like Coalition, AXA XL, and Cowbell have added affirmative AI language rather than excluding it. AI-driven attacks are typically covered. But eligibility increasingly depends on documented AI governance, and a minority of cyber policies (Delinea found 42%) already contain AI-related exclusions, so verify the client’s actual wording.

Are cyber insurers adding AI exclusions?

The most aggressive AI exclusions are concentrated outside cyber, in D&O, E&O, EPLI, and CGL. W.R. Berkley filed an "absolute" exclusion; Verisk/ISO’s standardized CGL exclusions took effect Jan 1, 2026; AIG and Great American filed requests. Cyber has largely moved the opposite way. Do not tell clients "your cyber policy no longer covers AI" as a blanket statement, but do verify each line.

What AI controls do cyber insurers want to see?

A written AI acceptable-use policy, an inventory of AI tools and models (including shadow AI), monitoring of employee AI use, data-loss controls preventing confidential data entering AI tools, documented training, human oversight for agentic AI, and an AI risk assessment mapped to NIST AI RMF or ISO 42001. Underwriting is shifting from point-in-time forms to continuous assessment, so evidence must persist between renewals.

Can a cyber insurer refuse to pay if AI controls were misrepresented?

Yes. In Travelers v. International Control Services a court permitted rescission of a $1M cyber policy because the insured represented MFA was deployed everywhere when it was only at the firewall, and under the majority US rule, rescission applies even for honest, unintentional misrepresentation. The same risk applies to AI-control answers, which is why every application answer should be backed by evidence exports before the client signs.

Can a cyber insurer sue my MSP after a client breach?

It is a real risk, and the first data point cut against the insurer. In Ace American v. Congruity 360 & Trustwave (D.N.J., filed Sept 15, 2025) a Chubb subsidiary sued an IT provider and an MSSP directly to recover $500,000 over failure to enforce MFA and a misclassified incident. On June 25, 2026 the court dismissed nearly all of those claims for failure to state a claim, leaving only part of the breach-of-contract claim against Congruity. Precedent is thin and insurers can lose these cases, but note where it survived: the contract. Document your delivery and review your MSA and Tech E&O.

How can an MSP make money from cyber-insurance readiness?

The same changes that create liability justify billable service lines: AI insurance-readiness assessments, subrogation-defensible evidence packs, AI governance as a recurring managed service (on the MFA trajectory), cross-line coverage audits, and cloud-posture hardening that feeds telemetry-based underwriting. The soft-market window is the pitch: lock in favorable terms and invest in controls before the market hardens.

Be the party that substantiates the answers

Underwriters now want an AI inventory, monitoring of shadow AI, and evidence that confidential data cannot reach AI tools. ShadowLock gives MSPs endpoint and browser visibility into unauthorized AI use across every client: the evidence layer behind every insurance-readiness assessment, subrogation-defensible answer, and AI-governance retainer on this page.