Cyber Insurers Are Drawing a Line on Shadow AI
We’re now beginning to see that some carriers are adding affirmative AI coverage, while many others are carving AI risk out of traditional policies…and Shadow AI is at the center of the shift.
The gap between AI adoption and protection is widening fast.
Most businesses are already running AI in production.
Fewer than half have a real risk framework around it and, as a result, insurance professionals are already seeing client losses tied to AI, and only about half of those claims are getting covered.
What the Data Shows
IBM’s Cost of a Data Breach Report found that 20% of breached organizations experienced incidents tied to employee use of Shadow AI (unsanctioned generative AI tools). Those incidents added roughly $670,000 to the average breach cost.
At the same time, underwriters are changing their questions. Applications and AI supplements increasingly ask about:
An AI acceptable-use policy
An inventory of AI tools (including shadow tools)
Monitoring of employee and Shadow AI usage
Controls that prevent confidential data from entering AI tools
Organizations that cannot demonstrate these controls face higher premiums, narrower terms, or outright exclusions.
The Insurance Market Split
Two opposite moves are happening at once:
Cyber carriers (Coalition, AXA XL, Cowbell, and others) are adding affirmative AI coverage or writing AI risks into base forms.
Traditional lines - Commercial General Liability, Directors & Officers (D&O), and Errors & Omissions (E&O) — are moving the other direction. Verisk/ISO introduced optional generative AI exclusion endorsements effective January 2026. Carriers such as W.R. Berkley have filed absolute AI exclusions that can bar coverage for losses related to any use of AI.
The result: the same incident can be covered under a cyber policy, excluded under a D&O or E&O policy, and disputed under a third. Coverage is no longer assumed — it depends on specific policy language and the organization’s ability to prove governance.
Why Shadow IT and Shadow AI Matter to Insurers
Shadow IT and Shadow AI create exactly the conditions underwriters now scrutinize:
Unmonitored tools outside approved channels
Sensitive data leaving controlled environments
Lack of inventory and access controls
Difficulty proving “reasonable security” after an incident
When an employee pastes customer data, source code, or internal documents into an unapproved AI tool, the resulting exposure can trigger claim scrutiny or denial if the organization lacked documented and enforced controls.
How Sting Helps Close the Gap
Sting Software was built for this moment. Our on-prem, browser-based platform delivers real-time visibility and proactive prevention of Shadow IT and Shadow AI:
Discovers unauthorized SaaS and AI tools at the moment of intent
Blocks high-risk actions before sensitive data leaves the environment
Provides the inventory, monitoring, and enforcement evidence insurers increasingly require
Supports governed adoption instead of driving activity underground
In short, Sting helps organizations turn “we have a policy” into “we can prove we enforce it.”
Actionable Takeaways for Leaders
Review current cyber, D&O, and E&O policies for AI exclusions or affirmative language.
Inventory AI and SaaS tools in use (approved and shadow).
Implement technical controls that detect and prevent unauthorized data flows to AI tools.
Document governance so underwriters and claim adjusters can see evidence of control.
Treat Shadow AI visibility as both a security and insurability priority.
The organizations that will secure better coverage and fewer claim disputes are those that can demonstrate they see and govern AI use in real time.
Ready to strengthen both your security posture and your insurability? Contact us to see how Sting provides the visibility and controls cyber insurers now expect.