Living tracker · Updated July 10, 2026

Cyber Insurance & AI Tracker for MSPs

Cyber is adding affirmative AI coverage while D&O, E&O, and CGL carriers exclude it, AI governance is becoming the next MFA, and subrogation against MSPs is now real. This tracker turns each change into the MSP liability read and the revenue opportunity.

Current as of July 10, 2026 · Not legal advice; confirm coverage against the client's actual policy.

The short version

Three things every MSP should take away

The market split into two opposite moves

Cyber carriers are ADDING affirmative AI coverage (Coalition, AXA XL, the Google Cloud/Beazley/Chubb/Munich Re program, Cowbell). Meanwhile D&O, E&O, EPLI, and CGL carriers (W.R. Berkley, AIG, Great American, Verisk/ISO) are EXCLUDING AI. Cyber remains the most AI-friendly line, but the aggressive exclusions are concentrated outside it.

AI governance is becoming the next MFA

Underwriters now ask whether clients have an AI acceptable-use policy, an inventory of AI tools, monitoring of employee and shadow AI, and controls preventing confidential data entering AI tools. Just as with MFA, a "yes" without documented evidence is a claim-denial and policy-rescission risk.

Subrogation against MSPs is now real

In Ace American v. Congruity 360 & Trustwave (D.N.J., filed Sept. 15, 2025), a Chubb subsidiary sued an IT provider and an MSSP directly to recover exactly $500,000 it paid after a client ransomware attack, over failure to enforce MFA and a misclassified incident. The case is recent and unresolved, but it targets the exact functions MSPs perform.

The two moves

The market split in two, and both create MSP work

"Silent AI" is being eliminated from both directions. Cyber carriers are writing explicit affirmative AI language into their forms, while management-liability and general-liability carriers are filing explicit exclusions. Whether AI is covered now depends on specific policy language, not assumption.

Carriers adding affirmative AI coverage

Mostly the cyber line, the most AI-friendly today.

  • Coalition

    Affirmative AI Endorsement + global Deepfake Response Endorsement

  • AXA XL

    genAI endorsement: data poisoning, IP, EU AI Act violations

  • Google Cloud RPP

    Affirmative AI for Google workloads; Beazley + Chubb joined Munich Re

  • Armilla AI + Chaucer (Lloyd’s)

    Standalone Affirmative AI Liability; $25M+ limits by Jan 2026

  • Munich Re aiSure + Mosaic

    AI-performance-guarantee cover up to $15M

  • Cowbell Prime One

    AI risks written into the base form; AI-risk "Cowbell Factors" rating

  • Relm Insurance

    NOVAAI / PONTAAI / RESCAAI, including DIC "wrap" where policies exclude AI

Carriers excluding AI

Concentrated outside cyber, in D&O, E&O, EPLI, and CGL.

  • W.R. Berkley

    "Absolute" AI exclusion across D&O, E&O, fiduciary (reported Form PC 51380)

  • Verisk / ISO

    New CGL exclusion forms CG 40 47, CG 40 48, CG 35 08, effective Jan 1, 2026

  • AIG, Great American

    Filed requests to exclude AI liabilities (Hamilton, Philadelphia Indemnity too)

  • Berkshire, Chubb, Travelers

    Reported approval to drop/limit AI liability on standard commercial policies

The practical part

AI questions your clients' renewals now ask

The underwriting question set has expanded from "Do you use AI?" to "What models, what controls, what governance?" Each question below pairs the renewal ask with how your MSP substantiates the answer, and documentation, not verbal assurance, is what survives a claims investigation.

How to read this list: only the AmTrust item and the model-level phrasing from Westfield Specialty are verbatim/primary-source-confirmed. The GuidePoint and Coalition items are verbatim characterizations by named executives of what carriers ask. All other question wordings are representative, not verbatim: they reflect the themes brokers, carriers, and vendors report are now standard on cyber applications and AI supplements.

1

Do you have a written AI acceptable-use policy?

Representative

How your MSP helps: Draft and maintain the policy defining approved tools, prohibited data categories, and output-review expectations; keep a signed version on file for the claims file.

2

Do you maintain an inventory of the AI tools and models in use across your organization (including embedded/SaaS AI and shadow AI)?

Representative (aligns with the "AI inventory is the new MFA" theme)

How your MSP helps: Run AI-discovery scans and maintain a living inventory with data-access and approval owner per tool, the single most-requested artifact.

3

What AI models are you currently utilizing?

Verbatim characterization: Westfield Specialty’s Jeff Kulikowski, via Business Insurance

How your MSP helps: Track model/provider names, versions, and use-cases so the client can answer at model-level granularity.

4

How is AI being used, for what specific tasks, and is it an efficiency tool or a core part of the solution you sell to clients?

Verbatim characterization: GuidePoint’s Nate Spurrier, via CSO Online

How your MSP helps: Document the business-function mapping; flag customer-facing/production AI that raises the risk tier.

5

Who is allowed to use AI, and how do you control/monitor employee use of generative AI?

Verbatim characterization (Spurrier/CSO Online) + representative

How your MSP helps: Implement role-based access and monitoring; deploy DLP/CASB rules that log and restrict GenAI use.

6

Do you have controls preventing sensitive/confidential data from being entered into AI tools?

Representative (driven by employees pasting confidential data into public AI tools)

How your MSP helps: Configure data-loss-prevention for AI endpoints, block unmanaged/personal-account access, and document enforcement.

7

Do you provide employees documented training on AI use/misuse?

Representative

How your MSP helps: Deliver AI-specific security awareness training with completion records. "Undocumented training is indistinguishable from no training" at claim time.

8

Do you have an AI risk assessment on file, and is AI governance integrated into your broader security program?

Representative (more common in mid-market/regulated renewals)

How your MSP helps: Perform and document an AI risk assessment mapped to NIST AI RMF or ISO 42001; integrate it into the client’s ISMS.

9

Do you require human oversight/override before AI (especially agentic AI) takes irreversible actions?

Representative (driven by agentic-AI concern)

How your MSP helps: Document human-in-the-loop controls and authorization limits for any autonomous/agentic systems.

10

Has AI been involved in any prior incidents, and do you log/investigate AI-related data disclosures as security incidents?

Representative

How your MSP helps: Extend the incident-response plan and logging to cover AI misuse and inadvertent disclosure; maintain the audit trail.

11

Do you allow the use of AI software to draft documents? If yes, attach a description.

Verbatim: AmTrust Lawyers Professional Liability application, form LPLPRO-APP-01 0523 (May 2023). Professional-liability, not cyber, but a confirmed real-form question.

How your MSP helps: Prepare a standard written description of the client’s AI-drafting workflow and controls to attach.

12

Do you use AI in product development or in services delivered to your clients?

Representative (reflects underwriter focus on whether AI is core to the offering)

How your MSP helps: Distinguish internal-efficiency AI from client-facing AI; advise on whether standalone AI-liability cover is needed.

Two statistics to handle with care: the widely repeated claim that "81% of cyber insurers now include AI governance questions in renewal applications" traces to a single commercial vendor blog with no cited methodology; treat as unverified/promotional. The claim that "99% of cyber insurance applications include MFA questions" could not be verified verbatim; the closest primary-source figures put enforced-MFA mandates in the ~90–100% range. Present both as directional only.

The change tracker

Carrier and market changes, grouped

Scan the list, then expand any entry for what changed and the MSP angle. Grouped by type of change.

Affirmative coverage

Coalition: Affirmative AI Endorsement

Affirmative

Expanded the definition of a "security failure or data breach" to include an "AI security event" and expanded the funds-transfer-fraud trigger to include fraudulent instructions via deepfakes or other AI. Announced March 26, 2024; folded into the base Active Cyber Policy in 2025.

MSP angle

A client’s cyber cover likely responds to AI-enabled attacks and deepfake FTF, but only if underlying controls (MFA, transfer-request verification) hold up, or the claim can be contested. So position deepfake/AI-attack coverage reviews as a value-add and ensure funds-transfer verification procedures are documented so the FTF trigger actually pays.

Primary source: BusinessWire announcement ↗

Coalition: Deepfake Response Endorsement

Affirmative

Added a global endorsement (US, UK, Canada, Australia, Germany, Denmark, Sweden, France) providing technical forensics, legal takedown support, and crisis-communications support for AI-generated impersonation of executives and employees. Announced Dec 9–10, 2025.

MSP angle

Reputation-attack deepfakes can trigger loss with no malware and no intrusion, outside what MSP tooling defends, yet clients may assume the MSP "should have stopped it." Bundle deepfake tabletop scenarios and executive-impersonation verification protocols into vCISO offerings and advise which clients need this endorsement.

Primary source: Coalition announcement ↗

AXA XL: genAI cyber endorsement

Affirmative

Introduced a globally available cyber endorsement extending coverage for generative-AI risks for businesses building their own genAI models: data "poisoning," usage-rights/IP infringement, and regulatory violations arising from the EU AI Act. Reported October 2024.

MSP angle

Relevant to clients that build or fine-tune models, not just use them, and the coverage is narrow and model-development-specific. Identify clients developing/customizing models and advise on the data-governance and training-data-provenance controls underwriters will want to see.

Primary source: Business Insurance ↗

Google Cloud Risk Protection Program (Beazley, Chubb, Munich Re)

Affirmative

Expanded the program: Beazley and Chubb joined founding partner Munich Re, offering affirmative AI coverage for Google-related AI workloads and using cloud-posture telemetry (Security Command Center / CIS Benchmark reports) for underwriting. For qualified digital natives, Beazley replaces the application with a single-page attestation. Announced at Google Cloud Next, April 2025.

MSP angle

For cloud-heavy clients, underwriting shifts to telemetry-based, so the MSP’s cloud-config hygiene directly drives insurability and pricing. Misconfigurations become insurance problems. Offer "cloud posture for insurability": harden Google Cloud configs to CIS Benchmarks and generate the reports carriers ingest. Directly monetizable.

Primary source: Google Cloud blog ↗

Armilla AI + Chaucer (Lloyd’s): Affirmative AI Liability & "Vanguard AI"

Affirmative

Launched the first standalone Affirmative AI Liability Insurance covering AI underperformance (hallucinations, model drift, mechanical failures), with limits reaching $25M+ by Jan 2026. In Feb 2026 the "Vanguard AI" structure paired Chaucer’s cyber and tech E&O with Armilla’s standalone AI liability, a "conscious decision to partner rather than stretch cyber policies beyond their original intent."

MSP angle

This confirms carriers are deliberately ring-fencing AI liability away from cyber, so clients relying on "silent" cyber cover for AI performance failures may have a gap. Advise clients deploying customer-facing AI that performance failure may need standalone cover, map exposures across cyber vs AI-liability vs E&O, and position yourself as the advisor who prevents coverage gaps at renewal.

Primary source: PR Newswire / Chaucer ↗

Cowbell: Prime One

Affirmative

Launched Prime One in the US, embedding AI-related risks (cybercrime, business interruption, data restoration, system failure, third-party liability from AI events) plus quantum risks directly into the base policy form rather than via exclusion or bolt-on. Introduced AI-risk "Cowbell Factors" rating for autonomy, observability, and governance. Launched Dec 2, 2025.

MSP angle

SMB/mid-market clients get affirmative AI in-form, but Cowbell now rates AI governance, so weak governance affects price and eligibility. Help clients improve their autonomy/observability/governance posture to earn better Cowbell Factors and document it for the continuous-underwriting model.

Primary source: Cowbell blog ↗

Relm Insurance: NOVAAI / PONTAAI / RESCAAI

Affirmative

Launched three AI products: NOVAAI (liability/cyber for AI developers), PONTAAI (excess/DIC wrap where existing policies exclude AI), and RESCAAI (first-party response for organizations embedding third-party AI). Affirmatively covers IP infringement and discrimination. Launched Jan 14, 2025.

MSP angle

The DIC/"wrap" model exists precisely because mainstream policies are adding AI exclusions, evidence of the gap clients face. For clients whose GL/E&O now excludes AI, flag the wrap-policy option and the governance evidence needed to buy it.

Primary source: PR Newswire ↗

Exclusions

Verisk / ISO: standardized CGL exclusions

Exclusion

New standardized CGL exclusion endorsements CG 40 47, CG 40 48 (and CG 35 08 for products/completed operations) took effect Jan 1, 2026, giving carriers ready-made language to exclude bodily injury, property damage, and personal/advertising injury "arising from" generative AI. Verisk forms underpin the large majority of US commercial liability policies.

MSP angle

These are CGL, not cyber, but they show the industry-standard machinery for AI exclusion now exists and can spread, and clients may lose CGL cover for AI-caused harm. Run a cross-line coverage audit to identify where a client’s AI exposure has quietly lost coverage (CGL) and where it is retained (cyber).

Primary source: Business Insurance ↗

W.R. Berkley: "absolute" AI exclusion

Exclusion

Introduced an "absolute" AI exclusion (reported as Form PC 51380) across D&O, E&O, and fiduciary liability, barring claims "arising out of" any "use, deployment, or development" of AI by any person or entity, reportedly naming tools like ChatGPT. Filed/reported late 2025, effective at renewal.

MSP angle

Client management-liability and professional-liability cover for AI-related claims may vanish quietly at renewal, leaving directors and officers personally exposed on AI governance failures. Alert clients to review D&O/E&O renewals for AI exclusions and position AI governance documentation as a litigation and coverage defense.

Primary source: Business Insurance ↗

AIG, Great American, Hamilton, Philadelphia Indemnity: exclusion filings

Exclusion

Filed requests with US regulators to exclude AI-related liabilities from various commercial policies; AIG reportedly told regulators generative AI is a "wide-ranging technology" where claims will "likely increase over time." First reported by the Financial Times, November 2025. Filing-stage; effective at renewal, jurisdiction-dependent.

MSP angle

A broad, cross-line pullback signal: clients cannot assume "silent" AI coverage persists in non-cyber lines. Reinforce demand for the cross-line audit and a "get it in writing from your carrier" advisory.

Primary source: CSO Online ↗

Delinea: survey of 750+ security leaders

Exclusion

Found 42% of respondents said their cyber policies already include exclusions tied to AI misuse or liability, and that 77% of insurers now require a formal internal/security-team review before issuing or renewing (up from 56% a year earlier).

MSP angle

This contradicts the "cyber has no AI exclusions" simplification: some cyber policies already carve out AI, so verify each client’s actual wording. Sell policy-language review plus control-review readiness, and be the party that passes the insurer’s mandatory security review.

Primary source: Forbes Tech Council ↗

Subrogation & litigation

Ace American v. Congruity 360 & Trustwave (D.N.J., 2:25-cv-15657)

Subrogation

A cyber insurer (a Chubb subsidiary) filed a subrogation action directly against an IT provider and an MSSP to recover exactly $500,000 it paid to insured CoWorx Staffing Services after an April 2024 ransomware attack. Alleges Congruity 360 failed to implement MFA for remote access and secure servers, and that Trustwave misclassified a detected event as "moderate," delaying response and preventing timely backups. Negligence + breach of contract. Filed Sept 15, 2025; recent and unresolved.

MSP angle

The watershed case for MSP liability: insurers now pursue the exact functions MSPs perform (MFA enforcement, hardening, monitoring, escalation), so your contract terms and delivery evidence are your defense. Sell "subrogation-defensible" service delivery (documented MFA enforcement, hardening baselines, alert-escalation SLAs, tested IR) and review MSAs with counsel.

Primary source: Hunton privacy blog ↗

Travelers v. International Control Services

Subrogation

A court permitted Travelers to rescind a $1M cyber policy after a ransomware attack because the insured represented MFA was deployed across all systems when it was only at the firewall. Rescission applies even for unintentional/honest misrepresentation under the majority US rule. Court ruling 2022; widely cited through 2026.

MSP angle

Even though the MSP does not sign the application, MSP work substantiates the answers. A false "MFA everywhere" answer means a rescinded client policy plus a likely MSP E&O claim. Sell "application-answer verification": produce evidence exports mapped to each control question before the client signs.

Primary source: ChannelPro Network ↗

Underwriting & market

Westfield Specialty: Jeff Kulikowski, EVP

Market

Stated that underwriting AI use has changed: "It used to be, ‘Do you use AI and how do you use it?’ Now it’s, ‘What models are you currently utilizing?’" This indicates deeper, model-level questioning. Reported 2025 (Business Insurance).

MSP angle

Underwriters now want granular, technical detail clients can rarely produce without their MSP. Maintain the client’s AI tool/model inventory as a managed service and produce it on demand at renewal.

Primary source: Business Insurance ↗

Marsh: Global Insurance Market Index, Q1 2026

Market

Global cyber rates fell 5% year-on-year in Q1 2026 (following a 7% decrease in Q4 2025; US ~-2%; IMEA -14%), the seventh consecutive quarterly decline. Marsh notes AI-threat affirmative coverage and supply-chain covers are "under development."

MSP angle

Soft pricing is a buying window, but frequency rose even as prices fell, so do not let clients treat cheaper premiums as lower risk. Run a "lock in favorable rates now, invest in controls before the market hardens" advisory and capture the control-implementation projects.

Primary source: Aon Q1 2026 overview ↗

Allianz: Risk Barometer 2026

Market

AI rose to the No. 2 global business risk (32% of responses), up from No. 10, the biggest riser in the survey of 3,338 risk-management experts across 97 countries. Cyber remained No. 1 at its highest-ever score (42%). Published Jan 14, 2026.

MSP angle

A demand signal: client boards are now primed to fund AI risk work. Time AI-governance proposals to board risk priorities and cite Allianz to build the business case.

Primary source: Forbes Tech Council ↗

Todyl: control-baseline synthesis (citing Marsh & Chubb)

Market

Reports that MFA is "still table stakes" but "MFA everywhere with evidence" is the standard; EDR/MDR now means 24/7 monitored response; and that Marsh and Chubb have begun incorporating Zero Trust principles (least-privilege, continuous verification, segmentation, conditional access) into underwriting conversations. 2026.

MSP angle

The control ratchet is explicit and documented: undocumented controls equal functionally no controls at claim time. Package Zero Trust + AI governance as the "2026 insurability stack" for recurring managed-service revenue.

Primary source: Todyl blog ↗

Read the sourcing

Confirmed vs. reported vs. prediction

Confirmed (carrier/press primary source)

Coalition Affirmative AI (2024) and Deepfake Response (Dec 2025) endorsements; AXA XL genAI endorsement; Google Cloud RPP with Beazley/Chubb/Munich Re; Armilla/Chaucer products and Vanguard AI; Munich Re aiSure/Mosaic; Cowbell Prime One; Relm NOVAAI/PONTAAI/RESCAAI; Verisk/ISO CG 40 47/40 48/35 08 effective Jan 1, 2026; the Ace v. Congruity 360/Trustwave and Travelers v. ICS filings/rulings; Marsh/Aon pricing indices; Munich Re, Allianz, and Delinea reports.

Reported / filing-stage (approval pending or via trade press)

W.R. Berkley "absolute" exclusion; AIG/Great American/Hamilton/Philadelphia Indemnity exclusion filings; Berkshire/Chubb/Travelers "won approval to drop AI coverage." Effective at renewal, jurisdiction-dependent.

Analyst commentary / prediction (not policy language)

S&P Global’s projection that cyber rates could climb 15–20% in 2026; broker predictions that AI exclusions "will spread to cyber"; the framing that AI governance "will become the next MFA." Informed forecasts, not committed carrier positions.

Caution: broker opinion ≠ carrier policy

Statements by brokers (Aon, Gallagher, Woodruff Sawyer, WTW) describe market direction and representative questions; they are not evidence that any specific carrier’s form contains that language.

Two weakly-sourced stats: the "81%" AI-governance-questions figure and the "99%" MFA-questions figure are both directional only; see the note under the renewal questions above. Actual coverage always depends on the specific policy wording a client holds in a given jurisdiction; verify every finding against the client’s actual forms.

The revenue read

What an MSP should do this quarter

The MSP sits at the intersection of every one of these changes: the party that implements the controls, whose work substantiates the client’s application answers, and who is increasingly the subrogation/E&O target when something fails. That makes every insurance change a client conversation.

Launch an "AI Insurance-Readiness Assessment" now, while the market is soft

Deliver a client AI inventory (including shadow/embedded AI), a written AI acceptable-use policy, a NIST AI RMF- or ISO 42001-aligned risk assessment, and an evidence pack mapped to the renewal questions above. Begin charging premium rates once the market hardens.

Make every client application answer "subrogation-defensible"

Before any client signs a cyber application or renewal, produce evidence exports proving each control (MFA enforced everywhere, EDR/MDR 24/7, immutable tested backups, IR plan tested, AI controls). This addresses both the Travelers v. ICS rescission risk and the Ace v. Congruity 360 subrogation risk. Benchmark: zero unverified "yes" answers leaving your shop.

Review and harden your own MSA and Tech E&O immediately

The Ace v. Congruity 360/Trustwave case targets MFA enforcement, hardening, monitoring, and escalation: your core functions. Get liability caps, scope-of-service definitions, and AI-governance responsibilities reviewed by counsel; confirm your Tech E&O limits reflect your aggregated client blast-radius.

Productize "AI governance as a managed service" on the MFA trajectory

Package acceptable-use policy + AI inventory + DLP-for-AI + shadow-AI monitoring + human-oversight controls + AI-specific IR, benchmarked to NIST AI RMF / ISO 42001. Sell it recurring, because underwriting is shifting to continuous assessment. Point-in-time prep is no longer enough.

Run a cross-line coverage audit for clients, not just cyber

The exclusions are landing in D&O/E&O/CGL first; cyber remains the most AI-friendly line but some cyber policies already carve out AI (Delinea: 42%). Help clients ask carriers, in writing, whether AI is excluded across every line, and identify standalone AI-liability/wrap options (Armilla, Relm PONTAAI, Munich Re aiSure) where gaps exist.

Turn telemetry-underwriting into a services line

For cloud-heavy clients, offer configuration hardening to CIS Benchmarks and generation of the posture reports carriers now ingest for underwriting (the Google Cloud RPP model). Insurability becomes a direct output of MSP config hygiene. Benchmark: measurable premium/eligibility improvement tied to posture reports.

Educate clients that cheaper premiums do not mean lower risk

Claim frequency rose even as prices fell, and AI is the named systemic threat that could reverse pricing fast. Position control investment now as locking in favorable terms before the market turns. Watch for any quarter where Marsh/Aon indices show cyber rates flat-to-rising, or a CrowdStrike-scale systemic event. That signals the window is closing.

Frequently asked

Cyber insurance and AI, answered

Does cyber insurance still cover AI-related attacks?

Generally yes. Cyber is the most AI-friendly line, and carriers like Coalition, AXA XL, and Cowbell have added affirmative AI language rather than excluding it. AI-driven attacks are typically covered. But eligibility increasingly depends on documented AI governance, and a minority of cyber policies (Delinea found 42%) already contain AI-related exclusions, so verify the client’s actual wording.

Are cyber insurers adding AI exclusions?

The most aggressive AI exclusions are concentrated outside cyber, in D&O, E&O, EPLI, and CGL. W.R. Berkley filed an "absolute" exclusion; Verisk/ISO’s standardized CGL exclusions took effect Jan 1, 2026; AIG and Great American filed requests. Cyber has largely moved the opposite way. Do not tell clients "your cyber policy no longer covers AI" as a blanket statement, but do verify each line.

What AI controls do cyber insurers want to see?

A written AI acceptable-use policy, an inventory of AI tools and models (including shadow AI), monitoring of employee AI use, data-loss controls preventing confidential data entering AI tools, documented training, human oversight for agentic AI, and an AI risk assessment mapped to NIST AI RMF or ISO 42001. Underwriting is shifting from point-in-time forms to continuous assessment, so evidence must persist between renewals.

Can a cyber insurer refuse to pay if AI controls were misrepresented?

Yes. In Travelers v. International Control Services a court permitted rescission of a $1M cyber policy because the insured represented MFA was deployed everywhere when it was only at the firewall, and under the majority US rule, rescission applies even for honest, unintentional misrepresentation. The same risk applies to AI-control answers, which is why every application answer should be backed by evidence exports before the client signs.

Can a cyber insurer sue my MSP after a client breach?

It is now a real, though early and unresolved, risk. In Ace American v. Congruity 360 & Trustwave (D.N.J., filed Sept 15, 2025) a Chubb subsidiary sued an IT provider and an MSSP directly to recover $500,000 over failure to enforce MFA and a misclassified incident. Precedent is thin and insurers can lose these cases, but the subrogation trend targets exactly the functions MSPs perform. Document your delivery and review your MSA and Tech E&O.

How can an MSP make money from cyber-insurance readiness?

The same changes that create liability justify billable service lines: AI insurance-readiness assessments, subrogation-defensible evidence packs, AI governance as a recurring managed service (on the MFA trajectory), cross-line coverage audits, and cloud-posture hardening that feeds telemetry-based underwriting. The soft-market window is the pitch: lock in favorable terms and invest in controls before the market hardens.

Be the party that substantiates the answers

Underwriters now want an AI inventory, monitoring of shadow AI, and evidence that confidential data cannot reach AI tools. ShadowLock gives MSPs endpoint and browser visibility into unauthorized AI use across every client: the evidence layer behind every insurance-readiness assessment, subrogation-defensible answer, and AI-governance retainer on this page.