AI GuardWorks
The Problem

AI is already inside your business

You did not approve most of it, you cannot see all of it - and you remain fully accountable for the work product and output.

An insurance agency at night. A sign on the awning reads we don’t use AI. A manhole in front of the door glows blue, and below the pavement a processor feeds Microsoft Copilot, Outlook, a vendor platform, personal ChatGPT, Gmail and a mobile device.

Why current recommended protocol is not enough

AI runs at the speed of light. Procedures, Human Review and Documentation never had a chance.

Human-in-the-loop (HITL) only works when the human knows what wrong looks like.

That is why verification starts by assuming the answer is wrong and forcing AI to prove it right.

A conveyor of AI-generated policy pages moving past a single overwhelmed reviewer, rejected pages stacking up beside her.
All three at once, and all three losing. The output does not wait for the procedure, the reviewer, or the record.

What organizations
are told

What happens in
the real world

Here’s what
is missing

  • AI Inventory
  • Decision-Point Map
  • Authorization Register
  • Enforced Boundary
Policies check the box. Controls create evidence to prove compliance.

And one gap none of the three closes on its own: the answer already exists, in a manual nobody can reach at the moment of decision. Standard advice says review AI outputs. It never says which ones.

Legacy and AI-native vendors claim control over AI

They say it. Can they prove it? Do they control it?

AI is worth adopting. That was never the problem. The problem is that the judgment calls now sit inside software you did not write and cannot inspect.

Can they identify it?

Every point in their product where AI selects, interprets, classifies, recommends, communicates, records or initiates. Not the feature list. The decision points.

Can they prove it?

An assurance is not evidence. What can they produce that shows what the model reviewed, what it changed, and who approved the result before it reached your client?

Do they control it?

A control that the vendor cannot demonstrate is a control you do not have - and the responsibility for the work product did not move to them.

The SaaSpocalypse effect

Homegrown AI tools are priced x-Security, x-Controls, x-Confidence.

Same category: AI enabled or built tools by vendors or individuals. Very different security, controls, E&O and business liability exposures. An established software vendor card in a safer zone lists enterprise security, formal controls, testing and QA, Technology E&O, support and continuity and contractual accountability. Two danger zone cards, agent in-house AI built tool and agent distributed AI built tool, list no or limited security, being overlooked for AI inventory, no separate developer coverage, rights and IP questions, higher E&O exposure, and for the distributed tool more agencies and users, more transactions, a multiplier effect and broader liability exposure.

Established software vendors must still identify AI decision points and controls.

The market priced the SaaSpocalypse exit. Nobody considered the risk.

Enterprise grade buys you confidence. Controls make the confidence real.

Real world impact

What changed is not the situation, but the coverage of it

Insurers are mitigating exposure by limiting or removing coverage through endorsements, separate policies and other restrictions or exclusions - due to these heightened exposures.

Financial exposure

Situation
A requested vehicle is never added to a policy and an accident occurs, resulting in $600,000 in medical bills.
Past
Likely covered. There were no AI exclusions.
Present
Insurers ask whether AI influenced the incorrect decision. Likely contested under a filed exclusion.

Regulatory compliance

Situation
An AI tool selects a policyholder for additional underwriting review. Documents are demanded under threat of cancellation, the policy is canceled, and she keeps driving uninsured.
Past
Likely handled as a cancellation dispute between the insured and the carrier.
Present
Resolved as a state settlement requiring governance improvements and adherence to the state’s AI guidance for insurers. The remedy was governance, not coverage.

Reputational risk

Situation
An AU$440,000 client report contains a fabricated court quote and citations to papers that do not exist. The firm returns part of the fee.
Past
Likely a professional liability matter, defended and covered.
Present
The error traces to generative AI, and E&O carriers are filing absolute AI exclusions. Likely contested under a filed exclusion.
This is not a forecast. Sixty-plus property and casualty groups have filed AI exclusions, approved by state insurance departments. More than twenty jurisdictions adopted the NAIC bulletin. The ISO generative-AI exclusion took effect January 2026.

Past and present outcomes above are illustrative of market direction, not the coverage under any particular policy.

We’ve heard AI Governance Experts say: Think of AI as the best administrative assistant you’ve ever had.

We say: Think of AI as the assistant who appears to be the best administrative assistant you ever had, is a people pleaser, and may confidently tell you exactly what you want to hear - not what you need to know. Your job is not to admire the answer. Your job is to find what is true.

AI does not have to invent the whole answer to create a loss.

It only has to miss the fact that changes the decision.

The risk is real. So is the answer

AI is here. The risk is real. Control is possible.

A structured conversation about where AI already operates in your business and where control is missing. No written assessment, no obligation, no cost.

Complimentary Pre-Assessment See the control system →