- Global Benefits Vision - https://www.global-benefits-vision.com/ -

The 30 Point AI Governance Gap Is an Insurance and Board Issue

Daily use has moved ahead of formal control

The 2026 Travelers Risk Index published in September 2026 reports that 89% of surveyed US business insurance decision-makers see artificial intelligence used day to day in their workforce, while only 59% say their organisation has formal practices governing that use. The 30-point difference is a useful indicator of unmanaged adoption, although the survey does not establish the quality or completeness of the policies reported.

The same survey places cyber threats at the top of business concerns and says 70% of respondents have purchased cyber insurance. Insurance penetration has increased, but a policy does not answer the basic governance questions: which tools are in use, what data they receive, which external systems they can reach and who is accountable when an output becomes an action.

An inventory is more useful than a policy alone

Many organisations begin with an acceptable-use policy. That is necessary, but it may not reveal the actual flow of information. A practical inventory should identify each approved and material unapproved tool, its owner, user group, data classes, model provider, retention terms, integrations and level of autonomy. It should distinguish drafting or search from decisions, transactions and changes to records.

The inventory should also capture shadow use discovered through expense records, browser controls, identity systems and interviews. The purpose is not to punish experimentation. It is to understand which uses need stronger controls, migration to an approved service or immediate suspension.

Insurance evidence should reflect operating reality

Cyber, technology errors and omissions, professional liability, employment practices and directors and officers policies can all be relevant to an AI-related event. Coverage depends on wording and facts, and the market is still developing affirmative grants and exclusions. Buyers should therefore map important use cases to possible loss pathways and ask how policies would respond.

Underwriters will increasingly need evidence of identity controls, data classification, vendor diligence, testing, monitoring and incident response. A generic statement that the company has an AI policy is unlikely to be enough for complex agents. The evidence should show that controls operate, exceptions are recorded and people can stop or reverse consequential actions.

Boards should ask for a short control scorecard

Board reporting can remain concise. It should show the number of material AI use cases, the share with an accountable owner and completed risk review, exceptions overdue, significant incidents, validation results and changes in delegated authority. These measures connect adoption to risk rather than treating the number of users as success.

For AI-based software products, the Travelers gap supports an offer that combines a specialised assistant with implementation controls. Clients need the corpus and workflow, but also access rules, provenance, evaluation, human review and audit records. Adoption and governance should be designed together.

Test governance through realistic incidents

Policies become credible when they are tested against events that could happen in the organisation. A tabletop exercise might involve an employee uploading confidential benefits data to an unapproved tool, an assistant producing a false country rule, or an agent sending a message without the intended approval. Participants should trace detection, containment, legal assessment, insurer notification, correction and communication to affected users.

The exercise should expose whether logs are complete, owners can be reached and the organisation can suspend a model or integration quickly. It should also test third-party cooperation. Findings belong in the same register as other control weaknesses, with deadlines and accountable owners. Repeating a small number of scenarios after remediation provides better assurance than issuing a policy and assuming that daily practice has changed.

The scorecard should be reported by risk level rather than as one corporate average. A drafting assistant with no confidential data should not receive the same attention as an agent connected to payroll, claims or customer communications. Segmenting use cases allows management to apply proportionate controls and helps the board focus on the small number of deployments capable of causing material harm.

Sources : Travelers – 2026 Risk Index press release ; Travelers – 2026 Risk Index