The Underwriter Is the New Auditor
By Yuri Bobbert
ScienceSoft released proprietary research on 10 September on how midsize US insurers plan to treat artificial intelligence risk through 2028. The headline number is stark: by 2028, AI risk is expected to factor into underwriting for 60 to 80 percent of new policies and renewals across errors and omissions (E&O), directors and officers (D&O), employment practices liability (EPL) and cyber insurance.
The number that matters more sits a paragraph later. ScienceSoft does not expect dedicated AI insurance to become mainstream. The segment is projected to grow from roughly 40 million dollars in 2024 to 4.8 billion dollars by 2032, an eighty percent compound annual growth rate that still leaves it at around 0.34 percent of commercial property and casualty premiums. Unclear liability attribution, accumulation risk, thin loss history, and regulatory uncertainty are all slowing a standalone AI policy market from forming. My personal observation is also that so-called "oops" missers originating from AI somewhere in the supply chain are increasing.
Read those three findings together, and the actual shift comes into focus. Insurers are not waiting for a bespoke AI product to catch up. They are folding AI exposure into the underwriting of the policies companies already carry, through affirmative wording, exclusions, specialized endorsements, and closer questioning at renewal.
The trigger is losses, not hype
A steep rise in publicly documented AI incidents between 2022 and 2025, is the kind of curve that moves an actuarial table faster than any conference keynote does. Insurers who spent the last two years writing AI as a silent, unpriced feature of existing cover are now under pressure to make that exposure explicit, either by pricing it in, carving it out, or requiring evidence that it is controlled.
That last option is the one worth watching. ScienceSoft's research team expects underwriters to look past the simple question of whether a business uses AI and toward how those systems are governed: what level of autonomy they operate with, what controls sit around them, and how incidents are detected and reported. Those factors are expected to increasingly set premiums, coverage conditions and risk control requirements through 2028.
An underwriter's question is a supervisor's question in different clothes
This is a familiar pattern to anyone tracking how AI oversight has developed this year. When the EU AI Office sent its first requests for information to frontier model providers, it did not ask for a policy or a charter. It asked for dated evidence: security testing, external evaluation, post-market monitoring. The same shift is now showing up on the other side of the Atlantic in a renewal questionnaire instead of a regulatory letter.
The mechanism is different; the ask is the same. A broker asking for an AI risk control narrative, a regulator asking for a monitoring log and a board asking its D&O carrier why premiums moved are all pulling on the same thread: can this organization show, with dates attached, what its AI systems do and how they are watched. A written AI policy answers none of those questions on its own. The Financial Stability Board telling G20 finance ministers that frontier AI is now a top cyber risk is the same signal arriving through yet another channel.
Why this reaches beyond insurance buyers
For C-level leaders, this turns AI governance from a compliance line item into a number on the income statement. A weak answer at renewal does not just invite a difficult conversation, it can mean a higher premium, a narrower cyber sublimit, or an exclusion that leaves a real gap in cover exactly where an AI-related claim would land. For investors evaluating a target's risk posture, insurability is becoming a fast, external proxy for AI governance maturity: a company that cannot get affirmative AI cover on reasonable terms is telling the market something about its controls that a pitch deck will not.
For GRC and AI-risk teams, the practical implication is that the evidence an insurer wants overlaps heavily with the evidence a regulator wants: a current inventory of AI systems, a record of what each one was tested for and when, and a log of what has happened since deployment. Complemented with a risk quantification in local currency to determine the single- and annual loss exposure per AI and accumulated. Building that once and keeping it current supports both the renewal conversation and the supervisory one.
That is the case for treating AI governance as a maintained record rather than a project that gets reconstructed whenever someone asks. Anove's insAIght platform is built around exactly that idea: every AI system in the register carries its own risk profile, the controls in place around it, and the dated history of what has been tested and observed. When a broker or underwriter asks how an AI system is governed, the answer comes from an existing record rather than a scramble to assemble one. Teams that want a fast read on what their current AI tools disclose about themselves can start with ExplAIn, which is free and takes minutes to run.
Learn more
- insAIght, Anove's AI governance and risk platform, for keeping an AI system inventory, its risk controls and its evidence current instead of assembling them on request.
- "We Have an AI Policy" Is Not Enough for the Supervisor, on why regulators are asking for dated evidence instead of governance documents.
- The FSB Just Told G20 Finance Ministers That AI Is Now Their Top Cyber Risk, on why frontier AI capability has become a standing item for financial supervisors.
- ExplAIn, our free tool for checking what an AI system actually discloses about itself.
If your organization would struggle to show an underwriter or a regulator dated proof of how your AI systems are controlled, book a demo, and we will show you what that record looks like when it is maintained rather than rebuilt.