06/05/2026
A few years ago, your cyber insurance carrier asked if you had MFA. This year, they're asking who owns AI in your business.
The questionnaires changed. Most SMB leaders haven't noticed.
In the past 12 months, we've watched carrier renewal questionnaires quietly add new sections. Sometimes one question. Sometimes ten. All of them about AI.
Who in your organization owns AI policy. What data is permitted in AI tools. Whether AI-generated client communication has documented review steps. Whether you track shadow AI usage at all.
Most leaders we work with can't answer these in real time. Some can't answer them at all.
Carriers aren't asking because they're worried about AI in the abstract. They're sitting on early claims data — and the pattern is consistent.
Employee uses AI on a personal account. Sensitive data goes in. Output goes out. Something downstream breaks. A wrong figure in a contract. An exposed client record. A deepfake email that worked because nobody questioned the tone.
The claim gets filed. Underwriting pulls the questionnaire. The gap between what you said you were doing and what was actually happening decides whether you're covered.
Insurance used to be your safety net for what you couldn't prevent. It's becoming an audit of what you should have been governing.
If your answer to "who owns AI here" is still "we're figuring that out," your carrier already has an opinion about your risk profile.
You just haven't seen the premium yet.
We put together a checklist of what carriers are actually asking now.
➔ The cyber insurance checklist most SMBs should have run through before their next renewal: https://hubs.la/Q04hNzX80