Mist rising off still water at the edge of a dense treeline

Governance

The AI policy your insurer is about to ask about.

The renewal application added a line this year. It asks whether your firm maintains a written AI acceptable use policy. It is a yes or no field, and there is no space for context.

Most firms answering that question for the first time do one of three things. They answer no and hope it does not matter. They answer yes on the strength of a template somebody downloaded and never circulated. Or they leave it, come back to it, and eventually submit whichever answer feels least likely to generate a phone call.

All three are understandable. Only one of them survives a follow up question, and follow up questions are becoming standard.

Why this appeared, and why it is not going away

Insurers do not add questions for interest. They add them when a category of claim starts showing up in the data.

Two findings explain the timing. Sixty three percent of breached organisations had no AI governance policy in place. Incidents involving unsanctioned AI added an average of six hundred and seventy thousand dollars to the total cost of a breach. From an underwriting perspective that is a straightforward risk signal, and the cheapest way to price it is to ask a binary question on the application.

The same question is now arriving through three other doors. Client security questionnaires ask it. Due diligence packets in transactions ask it. Professional bodies have begun issuing guidance that presumes a policy exists. What started as one line on a renewal form has become the thing a firm gets asked about routinely.

The document is the easy half. What makes it defensible is everything attached to it.

Why a downloaded template usually fails

A template is better than nothing and it will get you past the checkbox. It tends not to survive contact with someone who reads it.

The weakness is specificity. A generic policy does not name the tools your firm actually uses, so it says nothing about the three services that are genuinely in circulation. It does not match your data classifications, so staff cannot tell whether a client trial balance falls inside or outside the rule. And it carries no evidence of enforcement, which is the second question anyone asks after the first one.

An underwriter or a client is not really asking whether you have a document. They are asking whether your firm has made a decision about AI and can demonstrate it. A template answers the first question and not the second.

The four parts of an answer that holds

1. Tool tiering, with names in it

Three tiers is enough. Sanctioned, meaning approved for use including with client information under stated conditions. Permitted, meaning allowed for internal or non client work only. Prohibited, meaning not to be used in connection with firm work at all.

The tiers must contain actual product names. A policy that describes categories without naming anything leaves every practical decision to the individual, which is the situation you started in.

2. Data classification in plain language

This is where most policies quietly fail. The controlling question is never which tool, it is which data. Write out the categories your firm handles and give each one an explicit rule. Client identifying information. Financial records. Health information if you touch it. Privileged or litigation material. Internal working documents that contain no client data at all.

Write it so a new hire reads it once and knows what to do. If a policy requires interpretation, it will be interpreted generously by whoever is under deadline pressure.

3. Acknowledgement, signed and filed

A policy nobody signed is a draft. Every member of staff acknowledges it in writing, the acknowledgements are stored somewhere retrievable, and the document joins your onboarding pack so the next hire signs it in week one without anyone having to remember.

This is the part that converts a claim into evidence. When someone asks how the policy is enforced, the signature file is the answer.

4. A named owner and a review date

Tools change faster than documents. A policy written this quarter describes a landscape that will be partly wrong within two. Name a person, set a review interval, and put the next review on a calendar rather than in an intention.

This is also the part that turns a document into governance, which is the word the people asking the question are actually using.

On legal review. An operational AI policy is not legal advice and should not pretend to be. It covers which tools are sanctioned, what data may enter them, and how staff acknowledge the rules. Your attorney should read it. Write it well and that review is quick and inexpensive rather than a rewrite.

The mistake worth avoiding

The most common failure is not a weak policy. It is a prohibition policy.

Banning AI outright is the easiest document to write and the fastest to be ignored. Your staff are using these tools because they make the work finish, and a rule that makes their week longer will lose to the deadline every time. What a ban actually produces is the same activity, relocated to personal devices where the firm has no visibility at all.

The objective is not less usage. It is usage that is visible, bounded, and written down. A tiering that says yes under conditions gets followed. A blanket no gets worked around, and the workaround is worse than what you were trying to prevent.

What to do this week

  • Find the renewal application or client questionnaire that asked the question and read the exact wording. The specific phrasing tells you what standard you are being measured against.
  • List the AI tools you can name from memory. Then confirm it against what your team reports, because those two lists differ in almost every firm.
  • Write your data categories down before you write any rules. The categories are the hard part and the rules follow from them quickly.
  • Decide who owns the document. Without a name, the review never happens and the policy is stale within six months.

None of this is a large project. It is a few focused hours and one team conversation. What it buys is the ability to answer a question that is going to keep being asked, without the pause that currently precedes your answer.

Where this goes next

The full policy engagement is described under AI use policy. Most firms run a shadow AI exposure review first, because the findings become the tiering list. Related reading: shadow AI is already in your firm.

Answer the question properly.

Book a first call