The Proposal Form Only Knows What The Insured Declares

Estimated reading time: 5 minutes

KYND has launched an AI detection capability aimed at silent AI exposure. It identifies AI technologies across an organization’s external footprint from a single domain, with no input from the business.

A cyber proposal form can ask about AI. The answer depends on what the applicant knows and chooses to say.

KYND says underwriters now have a second source. The cyber risk intelligence provider launched an AI discovery capability on 30 September. It identifies AI technologies across an organization’s external digital footprint from a single domain. The business does not have to supply anything.

The cyber insurance form’s AI questions “can only tell an underwriter what a business knows and declares,” said Melanie Hayes, KYND’s co-founder. “Underwriters have been pricing AI exposure on trust because there was nothing else to go on.

KYND describes the data as independently observed. It is meant to supplement self-declared information on proposal forms and in underwriting conversations.

Silent AI Exposure From A Single Domain

The capability identifies four kinds of AI on an organization’s infrastructure:

  • AI assistants and chatbots.
  • Generative AI tools.
  • AI built into marketing and commerce technology.
  • AI crawlers the organization’s infrastructure permits.

AI is one part of a wider detection capability. KYND also identifies payment and cloud services, analytics and tracking pixels, session-recording tools, identity and access management, and website platforms.

The gap between declared and observed technology has come up before. Nudge Security CEO Russell Spitler raised it with Cyber Insurance News. He has yet to see an insurer ask which SaaS apps a company uses. Cyber Tzar’s Andrew Horkan described scanning from the outside in on the CINI podcast.

Silent AI Exposure Across A Portfolio

The launch builds on KYND’s white paper on AI risk. It warned that businesses are adopting AI faster than they disclose it. KYND said that can leave silent AI exposure unidentified at underwriting. It can also let concentrations build across insurers’ portfolios.

Hayes said the bigger issue appears across a book. When the same AI technologies and dependencies recur across insureds, that can become an accumulation issue, she said. Insurers need to find those concentrations before losses reveal them.

KYND says portfolio and reinsurance teams can use the data to see where common AI technologies appear across multiple insureds.

The release cites IBM’s 2025 Cost of a Data Breach report. It found one in five organizations reported a breach involving shadow AI. Breaches at organizations with high shadow AI cost $670,000 more on average than at those with little or none.

Shadow AI And Silent Policy Wording

Silent AI carries a second meaning in this market. RAND’s study of insurance filings used it for policy wording. The largest group of carriers neither affirms nor excludes AI, RAND found.

KYND’s concern sits on the other side of the contract. Its focus is silent AI exposure, meaning AI use the insured has not disclosed.

The two meet at accumulation. RAND recommended accumulation scenario analysis focused on model dependency.

AI Risk Underwriting Through Existing Channels

KYND data already reaches underwriters through partnerships. Verisk expanded its partnership in December 2025 to embed KYND intelligence in its Rulebook platform. DUAL Group partnered with KYND in September 2025.

Cyber Insurance News also covered KYND’s study of UK retail cyber risk after the Marks & Spencer attack.

FAQ – Silent AI Exposure

What has KYND launched?

An AI discovery capability that identifies AI technologies across an organization’s external digital footprint from a single domain, without input from the business.

What AI does it detect?

AI assistants and chatbots, generative AI tools, AI within marketing and commerce technology, and the AI crawlers an organization’s infrastructure permits.

Does it replace the proposal form?

KYND describes the data as an independently observed source that supplements self-declared information on proposal forms and in underwriting conversations.

What is silent AI exposure?

In KYND’s usage, it is AI an organization uses but has not disclosed to its insurer. The term is also used for policy wording that neither affirms nor excludes AI, as in RAND’s study of insurance filings.

Why does it matter for accumulation?

If the same AI technologies and dependencies appear across many insureds, a single failure could reach many policies. KYND says the data can help portfolio and reinsurance teams find those concentrations.

How common is shadow AI?

IBM’s 2025 Cost of a Data Breach report found one in five organizations reported a breach involving shadow AI, adding an average of 670,000 dollars for those with high levels of it.

See also  Cyber Insurance Policy Insights: Measuring Breach Risk with The SecurityScorecard BSI

Related Cyber Insurance Posts

Leave a Comment

×