1. Introduction: The AI Savings Trap
Many companies are using Artificial Intelligence (AI) to save money. AI can help reduce labor costs, speed up software development, and answer customer questions faster.
These savings sound great. But there is a hidden risk.
Many companies believe their current security systems and insurance will protect them if something goes wrong with AI. In many cases, that is no longer true.
This is the "Cybersecurity Illusion." It is the gap between how safe a company thinks it is and how much risk it really has.
For finance leaders, the challenge is no longer just paying for new technology. It is understanding the new financial risks that come with using AI.
2. Takeaway #1: Insurance Is Changing
In the past, many business insurance policies covered AI-related problems because the policies did not clearly exclude them.
That is changing.
Large insurance companies, including Travelers, Chubb, and Berkshire Hathaway, are adding rules that remove AI-related coverage from many standard business insurance policies.
More than 80% of requests to approve these new rules have already been accepted.
This means companies may have to pay for AI-related lawsuits and damages themselves instead of relying on insurance.
The risk is growing. Between 2021 and 2025, lawsuits involving generative AI increased by 978%.
Companies could now face large costs from AI mistakes, including copyright claims and other legal problems.
3. Takeaway #2: New Insurance Rules Create Coverage Gaps
In early 2026, the Insurance Services Office (ISO) introduced new insurance endorsements. Today, these endorsements are used in about 70% of U.S. commercial insurance policies.
These changes allow insurance companies to remove AI-related coverage from standard policies.
Here are three examples.
ISO Endorsement | What It Excludes | Simple Example |
|---|---|---|
CG 40 47 | Injuries or property damage caused by generative AI | A customer chatbot gives bad medical or financial advice that causes harm. |
CG 40 48 | Copyright and advertising claims involving generative AI | AI creates marketing content that copies someone else's work. |
CG 35 08 | Damage caused by AI-controlled products | An AI-controlled warehouse robot damages equipment or injures a visitor. |
Some insurers have gone even further.
For example, Berkley has added an "Absolute AI Exclusion" to some policies. This means it may refuse to cover almost any claim connected to AI.
4. Takeaway #3: Governments Are Paying Close Attention
Companies also face growing pressure from regulators.
One problem is called "AI-washing." This happens when a company claims its products use AI in ways that are not true.
The U.S. Securities and Exchange Commission (SEC) has already fined companies for making false claims about their AI technology.
In one case, Delphia (USA) Inc. and Global Predictions Inc. paid a total of $400,000 in penalties.
The European Union is also introducing strict AI rules.
The EU AI Act will begin enforcement in August 2026.
Any company that does business in Europe or serves European customers must follow these rules.
If a company breaks them, it could face very large fines. Because many insurance policies now exclude AI claims, companies may have to pay those fines themselves.
Keeping accurate records and making honest statements about AI is becoming more important than ever.
5. Takeaway #4: Small Security Problems Can Become Big Financial Problems
Security experts use the term "security debt" to describe security problems that have not been fixed.
As companies use more AI, this debt is growing.
AI coding tools can help programmers work faster, but they can also create unsafe computer code.
Studies show that nearly 33% of AI-generated Python code contains security weaknesses.
In addition, about 70% of serious software security problems now come from third-party code.
Another growing problem is "Shadow AI."
This happens when employees use AI tools without company approval.
They may accidentally upload private company or financial information into public AI systems.
A small security mistake can become a much bigger business problem.
A data breach can cost millions of dollars, hurt a company's reputation, lower its stock price, and reduce customer trust.
As one industry report stated:
"With the record average cost of a breach reaching $5 million in 2026, security debt is no longer a technical liability. It is a severe threat to operating margins and shareholder trust."
(2025 IBM / Recorded Future (Insikt Group) Report)
6. Takeaway #5: Finance and Security Teams Must Work Together
Managing AI risk is no longer just the job of the IT department.
Finance leaders and cybersecurity leaders need to work together.
Instead of thinking only about technology costs, companies should also estimate how much an AI failure could cost.
For example, they should ask:
What would happen if AI caused a data breach?
How much money could a lawsuit cost?
What would happen if operations stopped for several days?
Planning for these situations helps companies understand the real cost of AI risk.
It also helps leaders decide whether investing more in cybersecurity today could prevent much bigger losses later.
7. Conclusion: The Question Every Company Should Ask
AI can help companies save money and work more efficiently.
But those savings should not hide the growing financial risks.
Insurance companies are reducing AI coverage. Governments are creating stricter rules. Cybersecurity threats are becoming more expensive.
Companies that focus only on short-term savings may be taking on much larger risks without realizing it.
The Boardroom Question
Is your company saving money with AI today while taking on a much bigger financial risk tomorrow?
Sources
AI Exclusions in Insurance Policies: Broad Language, Uncertain Impact - Policyholder Pulse
Cyber risk is financial risk: Why CFO leadership matters more than ever - Microsoft
Does Your GL Policy Still Cover AI? The Exclusion Your Next Renewal May Already Have
Insurer Interest in AI Exclusions Growing as Risk Becomes Omnipresent - Claims Journal