Retail brokers frequently turn to the wholesale market when a cyber account exceeds their in-house expertise. But that handoff does not guarantee the client will receive specialist advice on artificial intelligence exposures or the policy wording intended to cover them.
Jennifer Wilson (pictured), senior director of cyber at WTW, said expertise remains uneven across both retail and wholesale brokerages as the insurance industry tries to keep pace with AI adoption.
“There are varying levels of expertise regarding what is needed to capture the exposure,” Wilson told Insurance Business. “Some wholesalers are well ahead of the issue and are negotiating broader language. Others think the definition of technology products and services adequately addresses the risk. Some feel you need affirmative language on cyber policies but not on technology E&O, which is not accurate.”
Wilson stressed that the knowledge gap is not unique to wholesalers. Expertise also varies within retail firms, including among brokers working with technology-focused clients.
Wilson primarily works with technology developers and tech-focused businesses, where AI exposures are already embedded in products and operations.
For technology companies, an AI-related claim could involve inaccurate output, failure of a product to perform, privacy violations, intellectual property allegations or a security incident. Depending on the circumstances and the wording, those allegations could implicate cyber, technology E&O, media liability or another policy.
However, the insurance market has not settled on widely available affirmative language addressing those risks. “Insurance has not quite caught up with AI risk,” Wilson said. “Right now, we’re relying on silent AI coverage in our cyber and technology policies.”
The term echoes the “silent cyber” problem the market worked through over the past decade. Where a policy neither expressly affirms nor excludes an exposure, a claim must be tested against existing insuring agreements, definitions and exclusions. That leaves insurers and insureds without certainty over how the policy will respond.
In cyber, market requirements — including Lloyd’s mandate that policies clearly affirm or exclude cyber coverage — have reduced some of that ambiguity. No equivalent market-wide requirement has standardized how policies address AI exposure.
Where a client wants protection beyond existing wording, Wilson said brokers may have to negotiate amendments carrier by carrier and underwriter by underwriter. Insurers continue to differ on definitions and appetite, creating a patchwork of potential coverage responses for businesses developing or deploying AI.
“We’re trying to secure the coverage while our clients already have the exposure,” she said. “We’re effectively patchworking language into these policies.”
The surplus lines market plays a central role in cyber placements. AM Best reported that surplus lines carriers now account for nearly two-thirds of US cyber premium, increasing the importance of the expertise available when brokers navigate non-admitted capacity.
The same analysis found that the first quarter of 2026 marked the eighth consecutive quarter of declining US cyber pricing. Softening gives brokers greater scope to improve terms, limits and retentions, but it can also encourage placement decisions centred primarily on price.
A wholesaler able to obtain several quotes may still add limited value if those options are not compared at the level of definitions, exclusions and intended claims response.
Longer-term claims trends also provide a warning against allowing pricing to dominate the decision. The National Association of Insurance Commissioners, in its 2025 Cybersecurity Insurance Report covering the 2024 year, said US cyber direct written premium fell 7% to approximately $9.14 billion while the number of reported claims increased by almost 40% to nearly 50,000.
For retail brokers, Wilson said the wholesale handoff should prompt another round of questions rather than end the coverage analysis. Brokers should establish how the client’s AI activities were mapped, which cyber and technology E&O provisions were reviewed, what amendments were requested and how the insurer expects its wording to respond to plausible claim scenarios.
“We’re all learning as we go,” she said. “It’s that adage about building the plane in flight.”