Time for a quick Q&A with Philip Otley, Global Managing Partner, HTEC

Gartner predicts a 60% industry-wide boost in AI governance controls by 2030 as insurers tighten conditions for cover. Why is AI risk so much harder to insure than the enterprise software organisations are used to?
Enterprise software has always been deployed deliberately, with specific licences, specific users, specific use cases, all mapped and controlled. AI doesn’t work that way. It’s available to almost anyone in an organisation, from a receptionist drafting an email to a CFO modelling forecasts, often without IT ever provisioning it directly. This is already happening inside most organisations right now, not just a hypothetical risk, whether or not anyone has written it down.
Insurance frameworks were built around bounded, procedural tools with a known population of users. AI has neither, and that mismatch is the reason why some carriers are choosing to exclude AI-related risk from existing policies rather than try to price it.
Insurers still can’t reliably price risks like hallucination or bias. Why is that gap so hard to close, and is there anywhere risk scoring is starting to mature?
There is not yet enough historical loss data to underwrite hallucination or bias risk generically, the way insurers underwrite fire or flood risk. What is starting to happen is narrower: some underwriters can price risk tied to a specific business process or model, because that’s a contained enough problem to build a dataset around.
A broad, transferable framework for AI liability across use cases doesn’t exist yet, and it’s worth being honest about that rather than pretending the market is further along than it is. Risk scoring methodologies are emerging, but they are bespoke and slow to generalise. The exposure is scaling faster than the market’s ability to measure it.
Insurers are increasingly expected to treat governance controls as a condition of cover rather than a nice-to-have. What does “insurable” AI governance actually look like in practice?
Underwriters want the basics documented, not assumed: which AI tools are approved, who has access, how that access is granted, what the sanctioned use cases are, and how usage is monitored on an ongoing basis. Most organisations haven’t written any of it down.
Even something as granular as whether a tool like Copilot has access to the open web needs to be defined, communicated and enforced, not left to individual discretion. Underwriters are asking for a paper trail that shows AI use is governed rather than improvised, and organisations that can produce it will be in a materially stronger position as carriers tighten requirements.

Where do you see insurers pulling back hardest right now, and why?
Two areas stand out. The first is IP liability. Large language models have ingested enormous volumes of third-party content, and rights holders (particularly in media and music) are increasingly testing that through litigation. The outcomes are still unfolding, but the exposure is real enough that underwriters are already factoring it into how they approach coverage, rather than waiting for the legal picture to fully settle.
The second is healthcare and personal data. In the US, HIPAA creates strict liability around health information, while in Europe, GDPR does the same more broadly. Any AI application that touches health records or operates in a regulated sector will face the most underwriting scrutiny.
2030 is being floated as the point mandated controls arrive. Realistically, how much sooner should IT and legal leaders expect that pressure to hit, and what should they be doing today rather than waiting for the mandate?
Treat 2030 as a ceiling, not a target. Expect meaningful movement well inside a six-to-36-month window, particularly among public companies, which carry higher risk exposure and tend to move first.
The starting point is explicit alignment at C-suite level: that AI governance is a formal, boardroom-level commitment, rather than something that will happen eventually. A lot of organisations are still in a bit of a gold rush phase: pushing AI adoption hard without the guardrails to match. From there, it’s about treating AI policy the way organisations already treat cybersecurity or mandatory conduct training: documented, communicated, actively monitored, with individual functional leaders held accountable.
If underwriters are going to scrutinise governance this closely, who inside an organisation needs to own getting it right?
IT, legal, and the wider business all have a stake here. AI doesn’t just sit neatly inside IT’s traditional footprint – its usage extends well beyond any conventional IT boundary. Legal needs to stress-test the guardrails, and senior leaders across every function need to actually apply them day to day, not just sign off on a policy document once and move on.
Leaving governance siloed in one department is how it becomes inconsistent and, ultimately, unenforceable, which is exactly the outcome underwriters are now pricing against. This has to be company-wide policy, not just departmental ownership. Organisations that act now will be the ones ready when insurers come asking for the paperwork.

Be the first to comment