How Insurers Are Handling AI Governance Ahead Of Regulators Still Stuck Writing The Standards
An insurance exclusion is a carrier's forecast of future loss. Dr. Danish Rafique of Munich Re explains why that makes standard policy language one of the earliest signals a board has on AI risk.

Make The Intelligence Record one of your go-to sources on Google
An underwriter has to make a judgment call on your potential losses and back that judgment with hard capital. When someone prices your risk using their own balance sheet, the conversation gets concrete fast.
The views and opinions expressed are those of Dr. Danish Rafique and do not represent the official policy or position of any organization.
Regulators are still writing the rules for AI, but insurers are already putting a price on weak governance. Some carriers have added AI exclusions to standard liability policies, while others have launched coverage written specifically for AI risk. The terms a company gets depend on the evidence behind its controls, which turns a governance program into a number on a renewal quote.
Dr. Danish Rafique is SVP, Chief Analytics Officer for Europe, UK, and LATAM LH at Munich Re. He leads data, analytics and AI work across underwriting, pricing and claims in more than 30 markets. He previously led digital commercial strategy for cell and gene therapies at Bayer and ran TerraLoupe, an autonomous mobility startup, through its exit. Before that, Rafique spent a decade in optical networking and telecom infrastructure at companies including Nokia Siemens Networks and ADVA. His current work is on the side of the market that has to price AI risk.
"An underwriter has to make a judgment call on your potential losses and back that judgment with hard capital. When someone prices your risk using their own balance sheet, the conversation gets concrete fast," says Rafique. An audit measures a company against a fixed standard, checking whether a control exists, is documented, and ran. Early AI regulations exist, but technology moves fast, and there's no living standard for AI controls yet, so an underwriter has to form their own view of the risk.
Governance with a price tag
Pricing moves governance questions to a different desk. A compliance finding stays with whoever owns the policy, but a premium increase reaches the CFO. "I've seen questions circling a governance committee for months get resolved in two weeks once there was a price tag attached," Rafique notes. Underwriters also ask for more specific evidence than an audit checklist does. "The question stops being 'do you maintain a model inventory?' and becomes 'show me how a model was approved last month,'" he explains.
The strongest evidence comes from the systems a company runs day to day. "An auditable screenshot of an automated pipeline gate tells a strong story," Rafique adds. Regulatory deadlines, by comparison, have been less predictable. The EU pushed its high-risk AI obligations back to December 2027, in part because the standards companies were meant to build against arrived late. "Regulatory timelines continue to evolve at pace, but insurance renewals have their own rhythm," he notes.
Pricing without a claims history
Rafique cautions against reading too much precision into how the market prices AI governance today. No carrier can yet say what a specific control is worth in basis points, since that would take historical claims data the market doesn't have. He expects this gap to last for years. "Right now, insurance is acting as a gate, not a fine-tuned mechanism. Bring solid evidence and you get coverage at a price. Bring anything less and you get hit with exclusions or sub-limits," says Rafique.
Fire insurers once helped build the standards they priced against. In 1894, with backing from fire insurance underwriters' organizations, the lab that became Underwriters Laboratories began testing electrical materials for fire safety. Rafique doesn't expect AI to follow the same path, since AI losses tend to surface through contested litigation, not visible property damage. He sees a patchwork of carrier-specific terms as the likelier outcome. "Fire insurers could enforce building codes because fire risk was local, physical, and contained. AI risk is highly correlated. The same handful of foundational models and software vendors sit behind thousands of businesses," he explains.
Concentration of that kind is what makes the pricing problem hard. An insurer underwriting a single company can study that company, and the exposure it takes on reaches past the company to whatever sits underneath it. "The biggest challenge is not assessing a single company's controls. It is understanding what happens when thousands of organizations rely on the same underlying models, vendors, or infrastructure providers. Insurance has traditionally benefited from diversified risks, and AI introduces a new degree of correlation," Rafique adds.
Renewal on the strategy calendar
Rafique's advice for strategy teams starts with the policies they already hold. Liability, D&O, E&O, and cyber endorsement schedules can carry generative AI exclusions or sub-limits, and terms often tighten without any headline change. A surprising number of companies do not know what coverage they hold. He also recommends tracking renewal dates on the strategy calendar as well as the finance calendar. "That renewal is the exact moment an outsider with capital at stake grades your controls," says Rafique.
A renewal comes once a year. The exposure it prices does not hold still for that long, since every model, vendor, and use case a company adds changes the thing being underwritten. An annual review describes a company at one moment, and the months between those moments are where the risk accumulates.
Rafique has seen smoother renewals at companies that built controls directly into how models get deployed. Their inventories update automatically when a model ships, and approval happens as a coded step in the technical pipeline that replaces the recurring meeting. That approach also proved faster, cutting approvals that took weeks in a manual queue to a day or less. "Evidence you have to manually hunt down is evidence you didn't really have," he explains.
Speed is the smaller half of what that buys. An inventory that generates on deployment records each model as it ships, so the evidence is a running account rather than a description of the company as it stood on the day someone assembled it. Rafique treats the need for that assembly as a diagnosis in itself. "If gathering evidence requires a major manual exercise, it is often a sign that governance activities are not yet fully embedded in day-to-day operations," says Rafique.
Guidance for the board
Insurers now bundle risk assessment and monitoring into AI policies, which echoes the move from hardware toward services that Rafique watched play out in telecom. He isn't convinced yet that the move is real, and he offers three tests to settle it: whether the software ever sells to companies that don't buy the policy, whether it survives a soft market, and whether it gets its own P&L. "It's real enough that I would advise a board to prepare for it, but far from settled enough to declare it a permanent shift," says Rafique.
What a board can read sooner is the pricing itself. Rafique suggests strategy teams read other companies' policy wordings alongside their own. "An insurance exclusion is ultimately a carrier's forecast of potential loss. That makes standard policy language a far better indicator of emerging risk than most published market research," he notes.
Where that reading stops matters as much as where it starts. An underwriter prices the downside of a company's controls, and a company's ambitions for what AI should do for it are a separate question that no carrier is being paid to answer. "A policy schedule sets a floor, and tells you the bare minimum required to operate. A strategy team that lets an underwriter define its ultimate ambition has handed over the wrong decision," Rafique concludes.




