Shadow AI Puts Cyber Insurance Coverage at Risk
Originally Published: Aug. 6, 2026
By Tracey Birkenhauer, journalist and Chief Impact Officer, STACK Cybersecurity
As shadow AI becomes more common in the workplace, it's creating a growing collision between employee productivity and cyber insurance coverage. When employees use unauthorized AI tools, including public chatbots, unapproved coding assistants, or browser extensions, they often introduce security and compliance risks that fall outside established controls.
Following a breach or other security incident, insurance carriers are increasingly scrutinizing these unsanctioned technologies and, in some cases, using them as grounds to deny or reduce claims.
Shadow AI, the use of AI tools employees adopt without IT or security approval, is a security risk and an insurance liability. A business that can't demonstrate it properly governed and secured AI use may find a claim reduced or denied at the exact moment it needs coverage most.
Executive Summary
Shadow AI has become a cyber insurance problem, not just a security problem. When employees use unauthorized AI tools to process sensitive data, insurers may argue the business violated policy conditions, failed to maintain required controls, or triggered an AI-related exclusion or sublimit.
That can leave a company paying for breach response, legal work, and business interruption out of pocket. Traditional IT tools often miss browser-based AI use, extensions, and unauthorized software-as-a-service (SaaS) logins, which makes it hard to prove what happened after the fact. Businesses that want to protect their coverage need continuous discovery, written governance, and documented AI controls before an incident occurs, not after.
Navigating Cyber Insurance AI Coverage
The commercial insurance landscape is undergoing a massive transformation regarding artificial intelligence. Insurers are actively pulling back from “silent AI,” the practice of implicitly covering AI-related risks through standard cyber and technology errors and omissions (Tech E&O) policies without explicitly mentioning AI.
As businesses approach insurance renewals, carriers are rolling out AI-specific exclusions and revised policy forms to tightly control their exposure.
Following a security incident, claim denials rarely come in the form of a direct statement that a firm used AI improperly. Instead, insurers often focus on whether the company failed to maintain required security controls, violated policy conditions, mishandled sensitive data, or allowed unauthorized technology use that contributed to the incident. When shadow AI is involved, it can become a factor in determining whether coverage applies, even if it's not cited as the sole reason for denying a claim.
- The Rise of "Gap Risk": Protection is increasingly fragmenting across different lines of coverage, including cyber, Tech E&O, directors and officers (D&O), and employment practices liability insurance (EPLI). Because each line is independently narrowing its AI protections, companies face serious coverage gaps where no single policy offers comprehensive safeguards.
- Quiet Coverage Erosion: Reductions in protection often happen behind the scenes. Rather than a single, highly visible exclusion, insurers are trimming coverage quietly through revised base forms, narrower definitions, and restrictive carve-backs.
- Compliance, Legal Risks: Shadow AI creates compliance and legal risks. Unauthorized AI use can violate GDPR, the EU AI Act, HIPAA, PCI DSS, SOC 2 requirements, and other regulatory frameworks, even if the company had no knowledge of the rogue tool.
- Recommended Next Steps: Review your insuring agreements, exclusions, and endorsements as a unified package to uncover hidden vulnerabilities.
If your company lacks the tools to identify and remediate Shadow AI, contact STACK Cybersecurity immediately for our Managed AI solution, AI Guardian. With our managed AI, you can even get transcripts of every AI conversation your staff is having. Contact Us
How Insurers Are Rewriting Cyber Policies for AI
Insurers introduced standardized generative AI exclusion endorsements for commercial general liability policies effective Jan. 1, 2026. Cyber carriers have followed with their own AI sublimits and tighter exclusion language, according to legal analysts tracking the shift. A November 2025 Delinea survey of more than 750 security leaders in the United States and the United Kingdom found that 42% of respondents said their cyber insurance policies already exclude AI misuse or liability from coverage.
Download the STACK Cybersecurity Cyber Liability Insurance Checklist
There are three common ways a claim gets challenged. An insurer may say the company failed to disclose AI use during underwriting. It may say the business didn't maintain the security controls the policy required. Or it may argue the incident falls under an AI-related exclusion, such as unauthorized software or data handling outside approved systems.
A cyber policy can look strong on paper. But if the insurer can point to unapproved AI use, the company may learn too late that the loss is only partially covered, or not covered at all.
Some insurers now offer affirmative AI endorsements or standalone products to provide AI-related coverage. These offerings remain in early stages and aren't yet widely adopted.
What Counts as Shadow AI in an Insurance Claim
Shadow AI covers any AI application, model, or service employees use without the knowledge or approval of IT and security. That includes free consumer chatbots, AI-powered browser extensions, coding assistants installed without review, and AI features embedded inside a SaaS platform that security never assessed. Employees paste in contracts, customer records, financial data, incident details, and source code because the tool is fast and convenient, often without realizing that data may now sit outside every control the business told its insurer it had in place.
"The companies getting burned are not only dealing with a security event," said Rich Miller, CEO of STACK Cybersecurity. "They are also dealing with the insurance carrier asking whether that AI tool was approved, whether the data should have been there, and whether the company did enough to prevent it in the first place."
Rise of AI Exclusions in Cyber Insurance
Berkley has introduced what it describes as an "absolute" AI exclusion in certain directors and officers (D&O), errors and omissions (E&O), and fiduciary liability policies. According to publicly available policy language, the exclusion may apply to claims arising from the use, development, or deployment of artificial intelligence, statements made about AI, alleged violations of AI-related laws or regulations, and regulatory demands tied to AI risk management.
The scope of these exclusions can be significant because some insurers define AI broadly. In certain cases, AI is described as any machine-based system that generates predictions, recommendations, content, or decisions based on input data. Such definitions could potentially encompass technologies and automated processes that businesses have used for years, well before the recent surge in generative AI tools.
Other insurers have taken a narrower approach while still imposing substantial coverage restrictions. Hamilton Insurance Group, for example, has used language designed to exclude claims connected to generative AI systems, including tools that create text, images, audio, or synthetic data in response to user prompts. Publicly referenced examples include platforms such as ChatGPT, Google Bard, Midjourney, and DALL-E.
For policyholders, these developments signal a broader shift in how insurers evaluate AI-related risk. Artificial intelligence governance, usage controls, vendor oversight, data protection practices, and employee training are increasingly relevant during underwriting reviews and post-breach investigations.
However, the existence of an AI exclusion doesn't automatically eliminate coverage. Insurance coverage determinations depend on policy language, claim facts, applicable law, and how courts interpret exclusionary provisions. Even broadly written exclusions may be subject to challenge when the connection between AI use and the underlying claim is indirect, limited, or disputed.
As AI adoption accelerates, companies should carefully review cyber, professional liability, and commercial insurance policies to understand how AI is addressed.
ISO AI Endorsements Signal Shift
The Insurance Services Office (ISO), which develops standard policy forms used throughout the insurance industry, has introduced optional endorsements addressing generative AI within commercial general liability policies.
CG 40 47: A broad AI exclusion that may remove coverage for bodily injury, property damage, and personal or advertising injury claims arising from generative AI.
CG 40 48: An exclusion focused specifically on personal and advertising injury claims connected to generative AI.
CG 35 08: An exclusion that may eliminate coverage under products and completed operations liability for bodily injury or property damage claims involving generative AI.
Taken together, these endorsements reflect a broader effort by insurers to reduce exposure to AI-related claims. Depending on how they're applied, the language could significantly narrow coverage when generative AI is connected to an incident, product, service, or business activity.
That said, policy exclusions aren't always as absolute as their titles suggest. Coverage disputes are evaluated based on the specific facts of a claim, the wording of the policy, applicable state law, and the causal connection between the alleged harm and AI use. Courts often interpret exclusions narrowly, particularly when broad language could eliminate coverage beyond what policyholders reasonably expected when purchasing the policy.
Understanding how AI is defined, where exclusions apply, and whether endorsements have been added at renewal can help identify potential coverage gaps before they become costly surprises.
Where AI Development Adds Underwriting Risk
Shadow AI also appears in AI development, where teams move quickly to build prototypes, integrate public models, or automate workflows without a mature security review. Developers may connect proprietary data to third-party models, use unvetted APIs, or deploy AI features before legal, compliance, and security have agreed on controls.
A company that deploys AI without governance may look like avoidable risk to an insurer. If that risk contributes to a breach, privacy incident, or outage, the carrier may argue the business failed to use reasonable safeguards or misrepresented its readiness for AI-driven operations. For underwriters, the real test isn't whether AI caused the incident. It's whether the business can show it managed AI responsibly enough to keep its coverage intact.
Why Standard IT Tools Can't Prove Compliance
Traditional IT and security tools are built to find installed software, managed endpoints, and traffic on the corporate network. Shadow AI often bypasses all of that. Employees can open a browser-based chatbot, sign up for a free account, install an extension, or turn on an AI coding assistant in minutes, without a ticket or a procurement review. Staff can also consult the AI tools on their personal phones, home computers, and tablets.
While most corporate IT teams lack the tools to identify and stop Shadow AI, STACK Cybersecurity does not. We have tools to identify Shadow AI use and lock it down.
How AI Guardian Helps Protect Your Coverage
STACK Cybersecurity built AI Guardian to help businesses discover what's happening with AI before an insurer, auditor, or incident responder asks. AI Guardian is a managed AI service providing continuous discovery of AI tool usage and helps establish governance policies. It also supports secure AI adoption and gives leaders a clearer view of where data may be exposed.
Documentation is part of risk reduction. The more clearly a business can show approved tools, enforced policy, employee training, and monitored AI usage, the stronger its position when defending a claim.
Businesses need visibility, governance, and proof that AI is used in a controlled way. Our AI Readiness Evaluation is a starting point for understanding where your business stands today.
Cyber Insurance Research Report
Delinea's cyber insurance report, referenced above, shows cyber insurance is no longer viewed as a simple financial safety net. Instead, insurers increasingly evaluate claims based on the maturity of cybersecurity programs. The survey of more than 750 security leaders found that nearly all companies must demonstrate security controls, processes, and governance practices to qualify for coverage.
The study also found companies overestimate what their cyber insurance policies cover. Coverage for lost revenue, ransomware negotiations, legal support, and incident recovery is often limited. At the same time, policies may be voided if firms fail to maintain required security controls, follow compliance procedures, properly configure systems, or report incidents within required timeframes.
Identity security has become one of the most important factors in determining cyber insurance premiums and coverage terms. Controls such as Privileged Access Management (PAM), Identity Governance and Administration (IGA), multifactor authentication (MFA), and third-party access controls play a significant role in insurer evaluations. The report also highlights the growing impact of AI. Companies using AI-powered security tools are often receiving premium discounts, while insurers are simultaneously adding exclusions related to AI misuse, model failures, third-party AI services, and prompt injection risks.
Cyber Insurance Study Findings
- 99.5% of businesses said security controls are required to obtain cyber insurance coverage.
- 72% filed a cyber insurance claim in the previous 12 months.
- 70% reported higher cyber insurance costs.
- 45% said their policy could be voided because of inadequate security controls.
- 97% reported identity-related controls influenced premiums or coverage terms.
- 86% received premium reductions or credits for AI-powered security controls.
- Only 33% reported coverage for lost revenue resulting from cyber incidents.
- 98% were confident they could obtain the same or better coverage at their next renewal.
Frequently Asked Questions
Why would a cyber insurance claim be denied because of Shadow AI?
An insurer may argue the incident involved unauthorized software, violated policy conditions, fell under an AI-related exclusion, or happened because the company failed to maintain required security controls. In those cases, the carrier may deny part or all of the claim.
What is Shadow AI?
Shadow AI is the use of AI tools, models, or services inside a business without IT and security approval. It includes consumer chatbots, browser extensions, embedded AI features, coding assistants, and third-party AI services that employees use on their own.
How does AI development create insurance risk?
AI development can introduce unapproved data flows, third-party model dependencies, and weak governance around how information is collected, trained, stored, or processed. If those practices aren't documented and controlled, they can become grounds for coverage disputes after an incident.
Why do standard IT tools miss Shadow AI?
Standard IT tools are built for installed software, managed devices, and network traffic. They often don't see browser-based AI use, free account signups, extensions, or third-party AI services adopted outside procurement.
What can businesses do to protect their coverage?
Businesses should inventory AI usage, set written governance policies, approve secure tools, train employees, document AI development practices, and continuously monitor for unauthorized AI activity.
Need Help Governing AI Inside Your Business?
STACK Cybersecurity helps businesses discover Shadow AI, establish governance policies, and deploy AI safely through AI Guardian. Email info@stackcyber.com or call (734) 744-5300.