AI

Cyber Insurers Ask About AI Now: What Burnaby Owners Say

September 28, 2026 · 7 min read · Autana Solutions, Vancouver
Cyber Insurers Ask About AI Now: What Burnaby Owners Say — Autana Solutions

Your cyber renewal packet shows up with a page that wasn't there two years ago. It asks which AI tools your staff use, who approved them, and what data goes into them. Most owners answer from memory in about ninety seconds. That's the one approach that can hurt you later, because an application is a document you sign.

Here is what the primary sources actually say, and what belongs in those boxes.

The market hasn't settled, so read your wording

The cleanest statement I found comes from the Lloyd's Market Association. In an April 13, 2025 piece by David Powell, the LMA's head of technical underwriting, the association notes that "most LMA model cyber clauses use defined terms to describe various cyber-related concepts and our definition of 'computer system' includes software, which by extension already includes AI systems" (LMA). The same piece says that if AI deployment changes risk profiles, "it may be necessary to amend our definition of 'computer system' in the future, to develop model definitions of AI systems, facilitating more nuanced coverage, limitations or exclusions as required by the market."

Read that twice. In a lot of standard wordings, AI isn't a separate thing yet. It's software, and software is already inside the definition. The exclusions and carve outs are being debated, not finished.

Some carriers have moved to name AI on purpose. AXA XL announced an endorsement on October 21, 2024 extending cyber cover to specific generative AI exposures including data poisoning, usage rights infringement from failing to obtain permissions for copyrighted training material, and liability tied to the EU AI Act (AXA XL).

One honest caveat. There are many blog posts claiming carriers now broadly exclude AI related losses. I could not verify a published, market wide AI exclusion in the primary wording sources I checked, and the LMA's own position as of April 2025 was that model definitions for AI systems still need developing. So don't take a blog's word for your coverage, and don't take mine. Ask your broker for the endorsement list and the definitions page of your actual policy.

What the Canadian numbers say

Statistics Canada's release of October 21, 2024 found that 16% of Canadian businesses were impacted by cyber security incidents in 2023, and that 22% carried cyber risk insurance, up from 16% in 2021. Only 26% had written cyber security policies in place. Total spending on recovery doubled to roughly $1.2 billion, with small businesses accounting for about $300 million of it (Statistics Canada).

Sit with that gap. More businesses buy the policy than write the policies. The application is where that shows up, because the form asks for documents you may not have.

The government is now asking the same style of question. The 2025 Canadian Survey of Cyber Security and Cybercrime questionnaire includes items on "Software or hardware using artificial intelligence (AI)", "AI-based cyber security tools" and staff "Experience with AI systems", alongside questions on cyber risk insurance renewals covering new exclusions, sub limits and baseline security thresholds (Statistics Canada questionnaire).

Six answers to have ready before you fill in the form

  • An inventory of AI tools. NIST's AI Risk Management Framework, released January 26, 2023, puts this in GOVERN 1.6: "Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities" (NIST AI RMF core). For a 12 person shop in New Westminster this is a spreadsheet: tool, owner, what data it touches, paid or free tier.
  • A written rule on what data goes in. The Canadian Centre for Cyber Security's guidance ITSAP.00.041, dated December 2025, says to "avoid providing PII or sensitive corporate data as part of the queries or prompts" and to "establish a plan that identifies policies on how AI should be used and the content that is allowed to be generated" (Cyber Centre).
  • A named accountable person. Canada's privacy commissioners, in joint principles published December 7, 2023, tell organizations to recognize "that they are responsible for compliance with privacy legislation, and should be able to demonstrate this compliance" through clear governance structures and defined roles (OPC).
  • Vendor answers in writing. NIST GOVERN 6.1 asks for "policies and procedures ... that address AI risks associated with third-party entities", and MAP 4.1 covers mapping the legal risks of third party data or software. The Cyber Centre says to ask providers about dataset origins and validation methods.
  • A human between the model and anything that leaves the building. The OWASP Top 10 for LLM Applications 2025 lists Improper Output Handling as LLM05 and Excessive Agency as LLM06, along with Prompt Injection at LLM01 and Sensitive Information Disclosure at LLM02 (OWASP). If a tool can send email or move money without a person approving it, the underwriter will care, and so should you.
  • A breach plan that names the law you report under. Under PIPEDA, an organization must report to the Privacy Commissioner where a breach "creates a real risk of significant harm to an individual", notify affected people "as soon as feasible", and keep breach records for two years (OPC breach guidance). BC's Personal Information Protection Act, in the consolidation current to September 2026, requires organizations to "protect personal information in its custody or under its control by making reasonable security arrangements" under section 34 (BC PIPA). Which act governs you depends on your business, so confirm that with counsel rather than with an application form.

Answer the way an underwriter reads it

Write dates and artifacts, not adjectives. "AI acceptable use policy, one page, approved March 4, 2026, acknowledged by all 14 staff" is an answer. "Yes, we have a policy" when the policy is a message someone posted in Slack is a problem, because the application sits in the claim file.

If the true answer is no, say no and add a date. Underwriters price unknowns worse than gaps. A plain "not yet, scheduled for the first week of November" is safer than a yes you can't evidence.

Where this doesn't apply

If you're a two person operation using a chat assistant to tidy up emails, and no client records ever go in, your honest answer is a one page rule and an inventory with two lines on it. Buying more is theatre.

Full certification is a different budget. ISO/IEC 42001:2023, the first AI management system standard, was published in December 2023, runs 51 pages, and the standard itself costs CHF 225 before any audit fees (ISO). That's a fit for firms with regulated clients or enterprise procurement, not for most trades and clinics.

I also could not verify any published evidence that AI governance documentation earns a premium discount. Vendor blogs assert it. I found nothing in a primary source that quantifies it, so don't buy tooling on that promise. The NIST framework is voluntary guidance, not law, and the commissioners' principles restate existing privacy obligations rather than creating new ones.

And there's a case for waiting. If you're considering an agentic tool with write access to your inbox, your invoicing or your payments, the control work that makes it insurable and safe can cost more than the hours it saves. OWASP flags exactly that pattern as Excessive Agency. Keeping the human approval step, even at the cost of speed, is often the correct answer this year.

If you'd rather not assemble the inventory, the acceptable use rule and the vendor answers yourself before your renewal date, book a free call with Autana Solutions. We work with owners across Metro Vancouver and we'll put together the paperwork your broker is asking for, in plain language, along with the controls behind it.

Sources

  • Statistics Canada. *The Daily: Impact of cybercrime on Canadian businesses, 2023*. October 21, 2024. Link
  • Statistics Canada. *2025 Canadian Survey of Cyber Security and Cybercrime, questionnaire 5244_Q1_V1*. 2025. Link
  • Lloyd's Market Association (David Powell). *Understanding artificial intelligence risk in insurance products, the challenges*. April 13, 2025. Link
  • AXA XL. *AXA XL unveils new cyber insurance extending coverage to help businesses manage emerging Gen AI risks*. October 21, 2024. Link
  • NIST. *AI Risk Management Framework 1.0, Core*. January 26, 2023. Link
  • OWASP GenAI Security Project. *OWASP Top 10 for LLM Applications 2025*. 2025. Link
  • Office of the Privacy Commissioner of Canada and provincial and territorial commissioners. *Principles for responsible, trustworthy and privacy-protective generative AI technologies*. December 7, 2023. Link
  • Office of the Privacy Commissioner of Canada. *What you need to know about mandatory reporting of breaches of security safeguards*. Link
  • Canadian Centre for Cyber Security. *Generative artificial intelligence (AI), ITSAP.00.041*. December 2025. Link
  • Province of British Columbia. *Personal Information Protection Act, SBC 2003, c. 63*, section 34. Link
  • ISO/IEC. *ISO/IEC 42001:2023, Information technology, artificial intelligence, management system*. December 2023. Link
cyber insuranceAI governancesmall businessBC privacyrisk management

Want an AI employee for your business?

We install a 24/7 AI worker for businesses in Vancouver, Burnaby, and beyond. Book a free Discovery Call.

Book a call →

Keep reading