Why AI risk management starts with a written policy

Carriers are excluding generative AI from standard policies. A risk expert explains how to close the gap before a claim hits

Why AI risk management starts with a written policy

Risk Management News

By

Corporate adoption of artificial intelligence has outpaced the governance structures designed to manage it. Fewer than half of organizations have a formal AI risk management framework in place, according to Gallagher's 2026 AI Adoption and Risk Survey. This gap is already producing tangible consequences in the form of D&O claims, coverage disputes, and insurance exclusions attached quietly at renewal.

Tim Davis (pictured), chief operating officer of POWERS Insurance & Risk Management, sets out what businesses should do before their next policy renewal.

Start with a written AI policy

The first requirement is also the most basic: a written policy that defines how AI may be used inside the organization. Without it, Davis argues, there is no foundation from which to assess exposure.

"The exposure to AI will be almost impossible to identify without a written AI policy and proper barriers in place for an organization," Davis said. "The policy should clearly state which tools are acceptable, which ones aren't, and also needs to have detailed restrictions on what is allowed within the AI system."

Governance, Davis adds, requires an internal feedback mechanism. The policy should, in his words, "encourage employees to contact IT if they are aware of a mistake or improper usage of AI, so that the IT department can investigate and correct the error."

The question of which platform employees use matters more than many organizations recognize. Consumer-facing AI tools do not offer the data protections that enterprise environments provide.

"If a business isn't using an enterprise instance of AI, the information that they're typing in to their favorite platform is visible to the public," Davis said. "We recommend most businesses set up a closed enterprise-level instance with an AI tool and share that with associates. This way, your business can have proper guidelines and guardrails already set in place for any use of AI."

With that infrastructure in place, a business can begin to assess its actual AI exposures. Davis recommends that all current employees sign the policy, and that it be incorporated into the onboarding process for new hires.

What AI gets wrong and what that costs leadership

The liability implications of AI errors are not well understood at board level. Most business owners are aware that AI systems can produce inaccurate outputs. Fewer have examined how those inaccuracies can expose directors and officers to legal claims.

"Many business owners don't realize that allowing AI can increase the risk of a D&O claim," Davis said. "AI usage has resulted in D&O claims for a myriad of reasons: negligence, product liability, material misrepresentation, legal liability, or even failure to disclose the use of AI for the work product."

The specific failure mode is AI hallucination: the generation of false or misleading information by AI systems that present it without qualification.

"AI still reports on everything it reads at this point," Davis said. That characteristic, he argues, makes human review of AI outputs not merely advisable but obligatory before material is shared or relied upon.

The litigation record bears this out. According to a February 2026 white paper from Techné AI on AI governance and D&O liability, AI-related securities class actions doubled between 2023 and 2024, with 12 filings recorded in the first half of 2025 alone. The pattern across those cases is consistent: plaintiffs do not need to demonstrate that the AI system itself failed, only that leadership neglected to govern its use.

Davis applies what he describes as the 80 percent rule. "It's critical to think of AI as a tool to help you get 80% of the way done with a task," he said, "but it's still critical for a human to review the material for accuracy." The principle extends, he adds, to routine AI-assisted tasks, including drafting a standard email.

Where standard policies fall short

The assumption that existing insurance programs extend to generative AI liability is, in most cases, no longer accurate.

The counterintuitive entry point is the cyber policy, according to Davis. "Whether a cyber policy will respond depends on the facts of the claim, but it generally would not respond to a typical generative AI liability fact pattern." 

The commercial general liability market has moved with unusual speed. Effective January 1, the Insurance Services Office (ISO) released three new endorsement forms permitting carriers to exclude generative AI losses from standard CGL policies. By April 2026, W.R. Berkley, Chubb, Travelers, Berkshire Hathaway, and AIG had each filed to adopt these endorsements or proprietary AI exclusion language. Errors and omissions coverage is tightening along comparable lines.

Davis said his team structures the renewal conversation around getting ahead of these gaps rather than discovering them after a claim. "We're focusing on having the conversation with our clients at renewal to better understand how they plan to utilize AI within their company," he said. From that assessment, the team determines the appropriate risk management approach and whether a standalone generative AI policy is warranted.

Taking AI risk seriously before renewal

The period between deploying AI and establishing the governance structures to manage it is where most liability accumulates. A written policy, an enterprise-level platform, and a structured coverage review at renewal represent the minimum reasonable response for any organization using AI in its operations today.

"Implement a formal written plan that clearly addresses which AI tools are considered acceptable, what work is allowed to be performed with the use of AI, and ensure that someone is reviewing the accuracy of information prior to sharing it with others," Davis said.

The insurance market has already adjusted to reflect the risk. Standard policies are narrowing in scope, exclusions are being added at renewal with limited notice, and D&O exposure linked to governance failures is rising. Organizations that defer action on AI risk management are making a decision, whether or not they intend to.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!