KYND tackles shadow AI blind spot in cyber underwriting

KYND tackles shadow AI blind spot in cyber underwriting

KYND has introduced AI detection functionality that lets cyber underwriters see which AI technologies a business is running across its public-facing digital estate, reducing insurers’ reliance on what clients choose to disclose.

Working from a single domain, the new AI discovery tool maps AI technologies visible across an organisation’s external footprint without any input from the business being assessed. Underwriters gain an independent, observed dataset to use alongside proposal forms and their discussions with prospective clients.

The tool arrives as fast-moving AI adoption places new pressure on insurers. Underwriters face rising expectations to grasp how companies deploy AI and what exposures follow, yet their judgement often rests largely on the information organisations volunteer about their own usage.

Businesses can also adopt AI faster than they can oversee or control it. The press release cites IBM figures showing that one in five organisations suffered a breach last year linked to “shadow AI”, meaning AI deployed without formal sign-off or governance. Organisations with high levels of shadow AI faced breach costs averaging $670,000 more than those with little or none.

The capability flags AI applications and features detectable across a company’s infrastructure. These include chatbots and AI assistants, generative AI tools, AI embedded in marketing and commerce platforms, and the AI crawlers that the organisation’s infrastructure allows.

The release follows KYND’s research into silent AI exposure building up within insurance portfolios. Its recent white paper, The Wild West of AI Risk, argued that companies are taking up AI more quickly than they report it.

As a result, exposures may go unnoticed at underwriting and concentrations may form across insurers’ books. Where that research set out the problem, the new tool aims to start tackling it by pairing self-reported details with independently gathered technology data.

When used consistently across an entire book, the data can help portfolio and reinsurance teams spot where the same AI technologies and dependencies recur among multiple policyholders, allowing them to investigate possible accumulations of risk.

KYND provides cyber risk intelligence to the insurance market. AI detection forms one element of its broader technology detection offering, which uncovers a range of technologies including payment and cloud services, analytics, tracking pixels, session-recording tools, identity and access management systems, and the platforms used to build websites. This helps insurers understand the technology dependencies behind each risk and possible concentrations across their portfolios.

KYND co-founder Melanie Hayes said, “Proposal forms and underwriting conversations remain essential, but AI use is changing rapidly and businesses themselves may not always have complete oversight of the technologies being used across their organisation.

“Giving underwriters independently observed information means the conversation can start with greater visibility of what is detectable on the risk, helping underwriters ask more informed questions and build a clearer picture of the exposure.”

Hayes added, “As AI becomes more deeply embedded across businesses, insurers will increasingly need to understand where common technologies and dependencies are appearing across their books.

“The industry is still building its understanding of how AI-related losses will develop. Being able to identify those dependencies now gives insurers a stronger foundation to understand and manage exposure as it evolves.”

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2026 RegTech Analyst

Investors

The following investor(s) were tagged in this article.