The Underwriter in the Room: How Cyber Insurers Are Already Scoring Your AI Program
About This Session
Most CISOs know AI introduces new risk. Far fewer know they're already being evaluated on it, or that the evaluation is happening quietly, every insurance renewal cycle, by people who set your premiums and write your policy exclusions.
Cyber insurance underwriters are rapidly building AI-specific risk assessment frameworks. They’re asking new questions, pulling new signals, and increasingly categorizing enterprise risks into preferred, standard, and high-risk AI tiers. The decisions they're making are affecting coverage availability, pricing, and even whether a claim gets paid when something goes wrong.
This session gives enterprise security and risk leaders an inside look at how AI programs are actually being underwritten today.
Drawing on data from CyRisk’s AI risk analytics platform used by cyber insurers to assess organizational AI posture at scale, attendees will learn which AI governance controls underwriters weight most heavily, which gaps trigger sublimits and exclusions, how agentic AI deployments are changing the assessment picture, and how to use the insurance market’s emerging AI pricing signals as a practical benchmark for your own risk quantification.
A key theme is how underwriting criteria both align with and diverge from familiar frameworks like NIST AI RMF and the EU AI Act. Where NIST and the Act define what good governance looks like in principle, insurance underwriting criteria are calibrated by actual loss data. They reflect what has already gone wrong and what it cost. The result is a more adversarially grounded view of AI risk that cuts through compliance theater and surfaces the controls that matter when a claim is on the table.
Attendees will leave with a concrete, insurer-tested framework for evaluating their AI program. One that satisfies both the boardroom and the underwriter, and that holds up when a loss actually occurs.
Cyber insurance underwriters are rapidly building AI-specific risk assessment frameworks. They’re asking new questions, pulling new signals, and increasingly categorizing enterprise risks into preferred, standard, and high-risk AI tiers. The decisions they're making are affecting coverage availability, pricing, and even whether a claim gets paid when something goes wrong.
This session gives enterprise security and risk leaders an inside look at how AI programs are actually being underwritten today.
Drawing on data from CyRisk’s AI risk analytics platform used by cyber insurers to assess organizational AI posture at scale, attendees will learn which AI governance controls underwriters weight most heavily, which gaps trigger sublimits and exclusions, how agentic AI deployments are changing the assessment picture, and how to use the insurance market’s emerging AI pricing signals as a practical benchmark for your own risk quantification.
A key theme is how underwriting criteria both align with and diverge from familiar frameworks like NIST AI RMF and the EU AI Act. Where NIST and the Act define what good governance looks like in principle, insurance underwriting criteria are calibrated by actual loss data. They reflect what has already gone wrong and what it cost. The result is a more adversarially grounded view of AI risk that cuts through compliance theater and surfaces the controls that matter when a claim is on the table.
Attendees will leave with a concrete, insurer-tested framework for evaluating their AI program. One that satisfies both the boardroom and the underwriter, and that holds up when a loss actually occurs.
Speaker
Ben Goodman
Founder & CEO - CyRIsk
Ben Goodman is Founder & CEO of CyRisk, an AI-powered cyber and privacy risk analytics platform used by leading insurance carriers to assess organizational AI and cyber risk posture at scale. He also founded 4A Security & Compliance, advising enterprises on cybersecurity strategy, AI risk governance, and regulatory compliance. This dual practitioner perspective working with both the underwriters who price cyber coverage and the security leaders who must satisfy them gives Ben a ground-level view of where AI risk governance is maturing and where it's falling short. He served on the CAS Cyber Risk Task Force and the SOA Expert Panel on Catastrophic Cyber Risk; his paper The Cyber Risk Ecosystem won first prize for Applied Enterprise Risk Management at the joint CAS/CIA/SOA competition.