In November 2025, the Financial Times reported that three major US insurers — AIG, Great American and W. R. Berkley — had asked regulators for permission to exclude all AI-caused damages from their corporate policies. The reasoning is simple, and unsettling for anyone who understands insurance: nobody really knows what the risk is.
The insurance business runs on calculating risk. AI breaks that. A single failure in a language model can hit thousands of client companies at the same time. An algorithm that "hallucinates" can produce a false accusation and trigger a cascading defamation claim. Google found that out the hard way: its AI Overview generated a false accusation against a solar energy company that led to a USD 110 million lawsuit. Air Canada had to honor a discount its chatbot invented. An engineering firm nearly lost USD 25 million when fraudsters used a deepfake on a video call.
Meanwhile, startups like Armilla — backed by Y Combinator — launched specialized policies for AI errors in 2025, underwritten at Lloyd's. The company offers coverage when an AI model performs worse than expected: if a chatbot's accuracy falls from 95% to 85%, the policy covers the damages.
But to get one of those policies — or to keep AI errors from falling through the cracks of a standard one — there is now a requirement insurers ask for: proof that you actually control how that AI gets used.
Why insurers started saying no
An insurer classifies a risk as "uninsurable" when it cannot answer three questions. AI fails all three.
The first: what is the maximum possible loss? With traditional risk (a factory fire, a bank robbery), insurance can picture the worst case. With AI, one model error can hit clients across hundreds of companies at once. The potential loss is incalculable because it is systemic.
The second: what does the cost pattern look like? Recent AI cases range from just over CAD 800 — what a court ordered Air Canada to pay for the discount its chatbot invented — to USD 1.5 billion, the settlement Anthropic reached in a copyright lawsuit. Six orders of magnitude apart, according to a CSIS analysis. Insurance needs a pattern: a probability distribution, a claims history. AI does not have enough track record for that yet.
The third: how do you know the client is telling the truth? With a factory, an adjuster shows up and sees how much burned. With AI, how does an insurer verify how a company was actually using the model? The client can hide, intentionally or not, how many failed experiments it ran, how many people had access, whether anyone was reviewing the outputs. That is what the industry calls information asymmetry: the company knows far more about its own risk than the insurer can ever verify.
That is why AIG, Great American and W. R. Berkley formally asked US regulators for the right to sell policies with a broad exclusion for any damage tied to generative AI use — from chatbots to autonomous agents. AIG later said it does not plan to implement those exclusions right away, but the request is already on the table: the market is positioning for the worst case before it can even price it.
Banning use does not work, and the insurer knows it

The obvious reaction for a company is to ban AI. But insurers already know that a ban does not reduce use — it reduces visibility of it.
When a five-person startup needs to draft a contract, summarize an annual report or reply to an email, most people will use AI even if policy says "banned". Given a choice between breaking a rule and missing a deadline, most break the rule. What changes is that nobody reports it to IT.
Research shows a consistent pattern: when a policy bans AI, a significant share of employees work around it anyway, because the benefit of using the tool outweighs the cost of breaking the rule. In practice, a large share of connections to AI tools happen through personal accounts, outside company control.
For the insurer, the real question is different: if an output came from unauthorized AI, using data that should never have been fed into it, who is liable for the failure? If the company's policy said "AI banned" but the work was done with AI anyway, coverage can be denied for "policy violation" or "failure to disclose the real risk".
What has to be in place
When an insurer decides to cover AI use — or declines to exclude it — it needs to be convinced the company is running the tool under governance. There are four verifiable mechanisms.
Corporate identity tied to the directory. Anyone using AI signs in with the same Active Directory login. When an employee is let go, AI access ends along with it, without depending on someone remembering to revoke an account. Everything logged, everything traceable.
Access role by role. An HR manager cannot see product development data. A developer cannot see payroll. Permission is granted function by function, and each one is audited — because yes, the insurer can ask to see it.
Approval matching the risk. A summary of an email? Goes straight through. A contract headed to a client? Stops and asks a person to confirm before it goes out. A critical document — an internal policy, a compliance procedure — goes through two-step review and approval, with the reviewer kept separate from whoever wrote it. That answers the question nobody used to be able to answer: who authorized this content to become official information the AI will use?
Detailed audit trail. Creating an agent, changing a permission, running a sensitive action, approving a document: all of it logged. Model and version used, the input, the time elapsed, who clicked what, what the outcome was. In an audit or an incident investigation, that is the difference between reconstructing events in minutes and spending months trying to piece them together. Regulators (the European Union, NIST, ISO/IEC 42001) converge on the same point: an audit trail is now mandatory.
That is how Skyller was designed: sign-in through corporate identity, role-based access, risk-based approval, audit trail by default.
From improvisation to something the insurer can defend

When everything happens on a personal account or with no record, whatever works stays locked to whoever figured it out. That perfect prompt it took weeks to get right? It only exists in that one person's history.
In a governed environment, agents, scripts, conversations and flows can be reused — within a scope defined by role and permission. Someone on the team creates it; the whole company moves forward. And, most important for the insurer: everything gets documented. If an action led to an error, the insurer can reconstruct why it was approved that way, who authorized it, and on top of what information.
There is a budget gain too. Without governance, everyone buys their own AI license — underused subscriptions pile up on one side, people hit their limits on the other. Shared credits fix both: visible consumption, no waste.
Three questions to bring to your next meeting with the insurer
Before renewing a policy, it is worth answering these three with IT:
-
If an employee is let go today, how many AI tools can they still log into tomorrow? If the answer depends on someone remembering to cancel an account, the insurer will read that as uncontrolled risk.
-
When AI produces something — a summary, a recommendation, a decision — where did that content come from, and who authorized it to be used that way? With no trail, the insurer cannot defend the coverage in a dispute.
-
What does the company know about who used AI, with what data, in what context, over the last quarter? If the answer is "nothing", the risk is not lower. It is just invisible — and that is worse for the insurer.






