AI governance isn't keeping pace with AI adoption, AXA XL warns
Nearly nine in 10 organisations now use AI in at least one business function. Most haven't built the governance to match
AI governance isn't keeping pace with AI adoption, AXA XL warns
DIGITAL TRANSFORMATION
By Josh Recamara
23 Sep 2026

AI is becoming embedded in critical business processes faster than many organisations can adapt their governance, security and incident-response capabilities, according to AXA XL and cyber security consultancy S-RM. 

Their report, Building Resilient AI: Managing AI Risk Through Governance, Security and Resilience, called on business leaders to treat AI risk as an enterprise resilience issue rather than solely a technology or compliance concern. 

According to McKinsey's 2026 State of AI survey, 88% of organisations now report using AI in at least one business function, up from 78% the year before. AXA XL and S-RM said that scale of adoption is creating more potential entry points for cyber threats while introducing new forms of operational, regulatory and third-party risk.

Five priorities the report sets out

As AI systems gain greater access to sensitive data, business applications and decision-making processes, the report identified five priorities for business leaders: establishing clear accountability for AI across the enterprise, covering formal deployments, embedded software features and shadow AI; protecting sensitive data and strengthening identity and access controls as AI systems become more autonomous; managing AI risk across its full lifecycle, from data collection and model development through deployment, monitoring and incident response; applying rigorous governance and due diligence to AI vendors and other critical third parties; and preparing for AI-related loss scenarios that may cut across cyber, fraud, liability, business interruption and other areas of insurance cover simultaneously.

Jonathan Salter, head of risk consulting at AXA XL, said AI is moving from experimentation into the systems and processes organisations rely on every day, but governance is not always keeping pace.

"The organizations best placed to capture AI's value will be those that know where it is being used, understand the business consequences when it fails and build security and resilience into deployment from the outset," he said.

Meanwhile, Rebiah Bardot-Girard, head of cyber risk consulting services at AXA XL, said AI risk rarely emerges in isolation.

"It amplifies existing weaknesses in identity management, data governance, supplier oversight and incident readiness," she said. "A practical inventory of where AI is used, what data it can access and where it can take or influence action is now a fundamental starting point for resilience."

Some organisations are responding

The report covered risks including data leakage, model manipulation, prompt injection, unreliable outputs, shadow AI and overly autonomous agents, and set out five foundations for secure AI by design: strong data governance, secure models and applications, ecosystem resilience, robust access controls and continuous monitoring.

There are signs some organisations are responding. According to the World Economic Forum's Global Cybersecurity Outlook 2026, 64% of business leaders now assess the security of AI tools before deployment, up sharply from 37% a year earlier, a finding the same WEF survey frames against 94% of respondents who say AI will be the most significant driver of cybersecurity change in 2026, and 87% who believe AI-linked vulnerabilities have increased more than any other threat type.

AXA XL and S-RM cautioned that pre-deployment assessment alone isn't enough. As AI gains access to sensitive data and decision-making processes, organisations remain exposed unless oversight continues throughout deployment and ongoing operation, not just at the point a system goes live.

A gap the wider insurance market has also flagged

This report's central warning, that insurance products and enterprise governance are both struggling to keep pace with AI risk, echoes findings published earlier in 2026 by Gallagher Re in its own report, Smart Systems, Blind Spots: Rethinking Insurance for the AI Era.

That report found generative AI-related litigation in the US grew 978% between 2021 and 2025, arguing that hallucinations, algorithmic discrimination, model drift and supply-chain compromises create liability through mechanisms traditional policies were never designed to address.

Notably, Gallagher Re's report specifically named AXA XL, alongside Hiscox and Beazley, as one of the carriers already working to clarify coverage boundaries through endorsements and sector-specific products, suggesting this new governance-focused report sits alongside AXA XL's own parallel efforts to adapt its product wordings to the same risk.

What distinguishes this report from a general AI risk warning is its insistence that AI exposure doesn't sit neatly inside any single insurance line, a data leak might trigger a cyber claim, a flawed automated decision might trigger a liability claim, and a vendor's AI failure might trigger a business interruption claim, sometimes all from the same underlying incident.

For brokers and risk managers, the report's core message is less about picking the right AI insurance product and more about first building the internal visibility, knowing where AI is actually deployed across an organisation, including the shadow AI usage no formal governance process ever approved, without which no insurance conversation can accurately reflect the risk actually being carried.

Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB US.