The NAIC AI exam tool has a new name, and the comment window has closed ahead of a November voteThe NAIC's Big Data and Artificial Intelligence Working Group exposed version 5.0 of what is now called the AI Risk Evaluation Supplement, formerly the AI Systems Evaluation Tool, for a 30-day comment period that closed September 29th. The rename reflects language in the document itself, which now states more directly that the supplement adds to existing market conduct, financial analysis, and financial examination procedures rather than creating a standalone AI exam. The 12-state pilot that began in March ended with September, and a revised version is headed to the Fall National Meeting in November for a possible adoption vote. After adoption, any state insurance department can use it. What insurance leaders should care about: This series has tracked the tool from pilot launch through the August Summer Meeting. With comments closed, the window to shape the tool has largely passed, and the work shifts to being ready to answer it. Version 5.0 is the clearest preview yet of what examiners will ask, and the comments trade associations submitted will show where the industry pushed back. The rename should not be read as a softening. A supplement to existing exam procedures means AI questions will arrive inside exams you already sit for, on timelines you already know.
|
|
|
Carriers are writing AI into the cyber policy, because attackers already haveOn September 17th, Beazley confirmed affirmative AI cover in its cyber and technology E&O policies, wording that expressly addresses AI-related risks already covered under existing cyber cover. The same week, CFC upgraded its financial institutions suite to include its full cyber policy with affirmative AI cover, part of a wider program to put explicit AI language across its portfolio. The timing follows a Reuters investigation published at the end of August showing that a new ransomware crew, Aur0ra, used a commercial AI coding assistant to speed up intrusions at seven companies this spring. One of the organizations Reuters identified was a Louisiana title insurer, which the group listed on its leak site. What insurance leaders should care about: This matters to insurance organizations on both sides of the policy. As a buyer, you should know whether your own cyber and E&O programs treat an AI-assisted attack, or a failure of an AI tool you deploy, as affirmatively covered, silent, or excluded. Silent coverage tends to get resolved in litigation after the loss, not before it. As a writer of cyber or professional lines, the market is moving toward explicit AI wording, and brokers will start asking why your forms say nothing. The Aur0ra case also answers a question boards keep asking: AI-assisted intrusion is no longer theoretical, and a title insurer was on the victim list.
|
|
|
|
|
Federal threat-sharing protections got ten more weeks, and the incident reporting rule is still due The continuing resolution Congress cleared on September 1st, which the President signed shortly after, extends the Cybersecurity Information Sharing Act of 2015 only through December 11, 2026. That law provides the liability protections, antitrust exemption, FOIA exemption, and privilege safeguards that let companies share threat indicators with the government and with each other. It has now been extended in short increments since it first lapsed in September 2025. Separately, CISA's published target for the final rule under the Cyber Incident Reporting for Critical Infrastructure Act is this month. That rule will require covered entities across 16 critical infrastructure sectors, including financial services, to report substantial cyber incidents within 72 hours and ransom payments within 24 hours. What insurance leaders should care about: Insurers share indicators through FS-ISAC, vendor channels, and peer networks every week, often without thinking about the legal protection underneath. That protection now runs on a ten-week clock. Legal and security teams should agree now on what sharing continues, and under what review, if the December deadline passes without another extension. The reporting rule has a direct insurance angle too. A 24-hour federal ransom-payment report will sit alongside NYDFS's 24-hour extortion payment notice and whatever your cyber policy requires for insurer consent before payment. Those three clocks need to live in one runbook, not three.
|
|
|
The year's largest claims study shows who files cyber claims and who drives the costNetDiligence released its 2026 Cyber Claims Study on September 16th, drawn from 10,309 real cyber insurance claims from incidents between 2021 and 2025. Ransom demands reached as high as $500 million and payments as high as $90 million, both new highs for the study, with 59 payments of $10 million or more. Small and mid-sized enterprises, defined as under $2 billion in revenue, filed 97% of claims, while large companies filed just 3% of claims but accounted for 56% of incident costs. Ransomware and business email compromise remain the top causes of loss, together touching more than half of SME claims. What insurance leaders should care about: The soft pricing this brief tracked in July and August does not reflect what the claims data shows: the severity tail keeps getting longer. For most insurance organizations, the useful number is the 97%. MGAs, agencies, TPAs, and regional carriers sit squarely in the segment that files almost all claims, and ransomware and BEC are still what drive them. If you write cyber, the 3%/56% split is a reminder that a handful of large-account losses can swing a book's results in a single year. If you buy it, the controls that address both top causes, identity verification, payment verification, and tested recovery, remain the highest-return spend on the list.
|
|
|
|
|
Travelers' Q2 2026 Cyber Threat Report found business email compromise claims ran 57% higher in the first half of 2026 than in the same period of 2025, while ransomware claims showed no corresponding rise. Travelers ties much of the growth to token theft: an AI-assisted phishing kit tricks users into signing in on Microsoft's real login page, then captures the session token, bypassing passwords and MFA entirely and handing the attacker the victim's full email, files, and cloud workspace. Ransomware leak-site activity stayed near record levels at 2,274 victims, with 89 active groups, a new high. What insurance leaders should care about: MFA alone no longer closes the door. A stolen session token walks past it, and a password reset does not revoke it. Incident response plans need to include revoking active sessions and OAuth consents, not just resetting credentials. And the control this brief has pushed since January still matters most: independent, out-of-band confirmation of any payment or banking change, because a fraudulent transfer is where nearly every one of these takeovers is headed.
|
|
|
Priority Actions for Insurance Leaders (Next 60 Days)Priority 1 — Confirm your RRG, captive, or pooled-risk arrangement's security posture gets vendor-level scrutiny.
Pick three findings from your current assessment and trace each to a control, an owner, or a documented risk-acceptance decision. Then confirm the assessment names your cloud, MSP, and core-system concentration and addresses AI adoption explicitly. Anything that does not trace is what an examiner will find first. Priority 2 — Map your AI inventory to the supplement before the November vote. Walk through version 5.0 with compliance and your AI owners and map each AI use case to its four exhibits, including which systems you would classify as high risk and what documentation your vendors can actually supply. Ask your trade association what comments it filed and watch for any further revisions before the Fall National Meeting. Once adopted, any state can put these questions in front of you. Priority 3 — Put your AI coverage, threat-sharing, and ransom-reporting clocks in one place. Ask your broker how your cyber and E&O policies treat AI-related incidents. Have legal confirm how threat sharing continues if CISA 2015 protections lapse on December 11th. Then consolidate NYDFS, federal, and policy-consent payment notification timelines into a single incident runbook.
|
This month, regulators, Congress, and carriers all put their expectations in writing. The organizations that do well in the next exam, renewal, or incident will be the ones whose own documents already say the same thing.
|
|
|
→ If your risk assessment cannot show where each finding went, or your AI inventory is not ready to map to the NAIC supplement before it goes national in November, those are the first two gaps worth closing this quarter. FiveM helps insurers build, document, and continuously test regulator-ready governance programs, so the answer to an examiner's question is already on file.
|
|
|
|
|
|
|