Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Business

Shadow AI Drives New Insurance Rules and EU Disclosure Mandates

Unapproved AI tools caused 43% of last year's security breaches, prompting insurers to add AI exclusions and the EU to enforce disclosure rules.

According to IBM's Cost of a Data Breach Report 2026, shadow AI appeared in 43% of security incidents, double the previous year, and 68% of breached firms had no AI governance. Four days after the report, the EU AI Act's Article 50 became enforceable, demanding clear disclosure when users engage with AI systems, a step that requires firms to map their AI usage. Experts like Yakir Golan of Kovrr contend that usage risk far outweighs model risk, emphasizing gaps in permissions, data flows, and vendor exposure.

Insurance markets have responded with generative-AI exclusions in commercial liability policies and niche products such as Munich Re's aiSure, while broader coverage remains limited. Surveys from UpGuard reveal widespread employee use of unsanctioned AI tools, underscoring the visibility problem. Companies are now turning to telemetry and asset mapping to quantify exposure and satisfy both insurers and regulators, though full-scale AI insurance is still years away.

Why it matters

Untracked AI use raises breach costs and forces new regulations and insurance practices for businesses.

In this story

shadow AIAI riskEU AI Actinsurance exclusiondata breachusage riskmodel riskvisibilityquantification
Get the beta ↗