AI Adoption Is Changing Cyber Insurance Reviews. Here's How IT Leaders Can Prepare
As insurers begin evaluating AI-related risks, midmarket IT leaders may need new answers at cyber insurance renewal time.
Recent reports have exposed how artificial intelligence can amplify offensive cyber capabilities. While public debate centers on whether to throttle AI development, businesses face a more immediate pressure: cyber insurers are beginning to factor AI adoption into underwriting decisions, forcing organizations to explain how increasingly autonomous systems affect their security posture.
For midmarket organizations, this shift could create new challenges during cyber insurance renewals. Companies that spent the past year embedding AI across their operations may increasingly face questions about governance, controls and risk management as insurers evaluate how those technologies may affect coverage and risk.
MES Computing spoke with cybersecurity and insurance experts to examine what underwriters are beginning to scrutinize as AI adoption accelerates, and where midmarket IT leaders should focus their efforts ahead of their next renewal.
How Insurers Could Adapt To AI Risk
The growing use of AI in businesses is beginning to complicate how cyber risk is presented to insurers, although underwriting practices have not changed uniformly across the industry.
[RELATED: AI Is Making Cyber Insurance More Complex: Here's What Midmarket IT Leaders Can Do]
Dara Gibson, owner and CEO of Cybersecurity Readiness Advisors, expressed concern about emerging complexities in the insurance industry regarding AI.
Gibson told MES Computing that she recently reviewed an insurance renewal application that did not address AI. "This concerns me as a certified cyber insurance specialist that some insurance companies may still not understand the risks involved in agentic AI usage," she said.
Tom Cloud, CEO of Vertex CIO Advisory, a firm working with midmarket companies on technology risk, said the questionnaires he sees remain largely focused on traditional controls, including multifactor authentication, endpoint protection, admin rights, email security, patching, backups and incident response. However, Cloud said he expects that to change quickly as more AI-driven attacks become prominent.
Gibson said insurers also need evidence to validate what businesses report in their applications.
“As a broker, I not only require the application questions to be answered, but validation as well. This ensures accuracy for the client and the insurance company,” she said.
That emphasis on validation could become increasingly important as insurers develop more specific ways to assess AI-related exposure.
Insurability Still Relies On Traditional Security Controls
AI may introduce new questions into the insurance assessment, but insurability still rests heavily on established security controls, according to Cloud.
What matters, he said, is whether a business can demonstrate that those controls work when put to the test. Cloud recalled working with one organization that had made significant security upgrades but initially struggled to explain exactly what was installed, how it was configured, and who owned each piece. Once those details were clearly documented, the business stood on far firmer ground during its coverage review, he said.
Cloud's benchmark for any security control is simple:
“If one of your security controls stopped working tomorrow, would anybody know? And if so, how long would it take them to find out?”
[RELATED: 5 Cyber Insurance Options For The Midmarket]
For businesses preparing for cyber insurance renewal, Cloud's question touches on a broader operational challenge: accountability. A control can easily exist on paper, yet still leave gaps around who monitors it, who responds when it fails, and whether the business can produce hard evidence of its daily performance.
That distinction will only become more critical as insurers evaluate emerging AI-related risks alongside the foundational security controls that traditionally define an organization's cyber posture.
What to Do Six Months Before Renewal
Cloud recommends obtaining the renewal questionnaire early and using it as a checklist. “Don't wait until renewal is right on top of you. Get the questions early and use them as a punch list,” he said.
[RELATED: Cyber Insurance: Here Are 10 Pitfalls To Avoid]
Organizations should focus on identity-related controls like MFA exceptions, old service accounts, and unnecessary administrator privileges, while stressing recovery capability as another critical priority. “Don’t just assume your backups work — restore the data, time how long it takes, and document the process,” he said.
AI-specific controls also need attention, starting with clear decisions on approved employee platforms, data boundaries, and proper administrative logging. Insurance experts also advise that discovery and permissions are equally vital, and that maintaining a strict inventory of AI tools and agents helps prune standing permissions and establish independent activity logging.
To bring order to these competing priorities, Gibson recommends mapping existing security foundations directly against what she calls the "14 Insurability Controls," a framework her firm uses to evaluate cyber insurance readiness.
Cloud also suggests organizations should audit the security tools they already own but have yet to fully configure or deploy, ahead of their next insurance renewal.
While insurers have not yet reached an industry consensus on how to evaluate AI risk, experts expect scrutiny to increase as AI becomes more deeply embedded in business operations. For midmarket IT leaders, ensuring AI governance, security controls and operational accountability can strengthen their organization's posture when it comes time for cyber insurance renewal.