<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=8926796&amp;fmt=gif">

What Risk Pools Can Learn from the Insurance Industry’s AI Debate

Artificial intelligence has moved rapidly from experimentation into everyday operations.  

Across public entities, employees are already using AI to draft communications, summarize meetings, support customer service, assist with procurement and automate administrative work.  

At the same time, vendors are increasingly building AI into the software and services public entities already use. The opportunity is significant. But so are the questions around governance, cyber risk, data, liability and insurance.   For public entity risk pools, there is a relatively simple place to start.  

Pools do not need to become AI experts overnight. They do need visibility into where AI is being used, some basic governance around it, and a way to demonstrate that the risk is being managed responsibly.  

That matters because AI adoption is moving faster than many organizations' policies, controls and risk management practices. And while the insurance industry is still working out exactly how AI risk should ultimately be evaluated and insured, today's underwriting discussions can provide an early indication of tomorrow's expectations.  

Today's insurance debate may shape tomorrow's expectations  

Risk pools occupy a unique position. They are helping members manage risk while also working with brokers, insurers and reinsurers to secure sustainable coverage for the wider portfolio. Understanding where the insurance market may be heading therefore matters—even while that market is still developing its own thinking.  

KYND's recent research found broad agreement across insurers, brokers and specialty providers that AI introduces meaningful new exposures. There is considerably less agreement about how those exposures should ultimately be categorized, priced or insured.    

For pools, the important point isn't predicting where the insurance market ultimately lands. It's recognizing that expectations around AI risk are evolving—and using this period to build sensible governance and visibility before those expectations become more formalized.  

The public entity community itself is beginning to move in the same direction. AGRiP has incorporated the operationalization of artificial intelligence into its Advisory Standards for Recognition, while AI considerations also touch areas including data security, underwriting, claims, service provider contracts and business continuity.  

AI governance is therefore moving from an emerging technology discussion toward a practical risk management issue.

AI is bigger than an IT issue

One reason AI is difficult to manage is that it rarely creates one neat category of risk.  

An AI-supported recruiting process could create employment concerns. A chatbot could provide inaccurate information to a citizen. Sensitive information could be entered into an external AI platform. Generated content could create copyright or intellectual property questions.  

A single AI-related problem can therefore cross cyber, employment, professional, operational and other forms of liability. And those exposures are not confined to the IT department. Human Resources, Communications, Finance, Procurement, Legal and Customer Service teams can all adopt AI tools independently.  

That means the pool conversation needs to move beyond: “Is the IT department using AI?” toward: 

"Where is AI being used across the organization, what information is interacting with it, and who is accountable for the outcome?” 

The biggest AI risk may be the AI you don't know about 

Perhaps the most practical issue for pools is visibility.  

AI tools are remarkably easy to adopt. An employee can create an account with a public AI platform in minutes. A department can begin experimenting without going through a traditional technology procurement process. Existing vendors can also introduce AI-powered features into products already deployed within an organization.  

This creates a modern version of a familiar cybersecurity problem: shadow IT. Except now it is shadow AI.  

Imagine a relatively simple situation. An employee wants help drafting a response and copies information from a resident complaint, personnel matter or contract into a public generative AI tool.  

Does the organization know that happened? Was the employee permitted to do it? Do they know how that information may be processed or retained—or who is responsible for reviewing the AI-generated response?  

The purpose of asking these questions isn't to stop useful innovation. It is to establish enough visibility and governance that organizations can use AI deliberately rather than accidentally.  

For a risk pool supporting hundreds of members with widely varying resources and maturity, that distinction matters. You cannot meaningfully manage a risk you cannot see.  

What does sensible AI governance look like? 

There is unlikely to be one perfect governance model for every public entity. But pools can encourage members to establish some straightforward foundations.  

1. Know where AI is being used  

Start with visibility. Members should understand which AI tools employees and departments are using as well as where AI has been introduced into existing software or third-party services. Even a basic inventory provides a stronger starting point than having no centralized picture at all.  

2. Put some basic rules around its use  

An AI acceptable use policy can establish expectations around what employees may use AI for, what information should not be entered into public platforms, when human review is required, and who remains accountable for AI-assisted decisions.  

The objective is not to create bureaucracy around every AI interaction. It is to make responsible use clear.  

3. Help employees understand the risks  

Governance cannot live only in a policy document. Employees need practical guidance around sensitive information, the accuracy of AI-generated outputs, human accountability and appropriate use.  

Depending on state requirements and the circumstances involved, public records obligations may also need to be considered.  

4. Ask vendors about embedded AI  

AI exposure does not only come from tools employees deliberately adopt. Vendors may be adding AI capabilities to systems public entities already depend upon.  

Members should understand whether a service uses AI, what organizational data interacts with it, whether customer data is used to train models, how information is retained, and what controls or contractual protections apply. Third-party AI should increasingly form part of normal vendor risk conversations.  

5. Be able to show progress  

AI governance will not be a one-time exercise. Technology, member adoption, regulation and insurance expectations will continue to change.  

The aim should be continuous improvement rather than instant perfection: identifying AI use, establishing appropriate guidance, addressing obvious gaps and periodically reviewing the approach.  

Over time, that evidence may become increasingly valuable to management teams, boards, brokers and insurers.  

What should the risk pool do? 

The answer is not necessarily to build an AI governance program on behalf of every member.  

The pool's role can be much simpler: provide structure, help members ask the right questions, offer practical guidance and education, and encourage sensible minimum expectations. Over time, that can also give the pool a clearer picture of AI maturity and exposure across its membership.  

For an Executive Director, the starting point is straightforward: Do members know where AI is being used? Do they have basic guidance around its use? Are employees handling information responsibly? Are vendors being asked about embedded AI? And could members demonstrate how they're managing the risk if their board, broker or insurer asked tomorrow?  

A pool does not need perfect answers. Understanding where the gaps are is itself valuable.  

The insurance market is still writing the playbook 

One reassuring finding from KYND's research is that insurers do not have every answer either. The market is still deciding how AI-related risk should ultimately be categorized, assessed and insured. For pools, that creates an opportunity.  

Rather than waiting for a future insurance application or coverage requirement to dictate the conversation, pools can begin helping members develop sensible practices now.  

The same principle increasingly applies to cyber risk more broadly: maintain visibility, identify where support is needed, help organizations improve and be able to demonstrate what has changed.

Helping pools stay ahead of what comes next 

Public entity risk pools have always played an important role in helping their members respond to emerging risks. AI is another example.  

The goal is not to discourage adoption or pretend every organization can predict how the technology will develop. It is to make adoption visible, governed and accountable. As both technology and insurance expectations evolve, organizations that can demonstrate those qualities should be better positioned to respond.  

For risk pools, the practical message is therefore straightforward:

You don't need to predict exactly how insurers will ultimately cover AI. You do need to know where your members are using it, what governance surrounds it, and whether you can demonstrate that the risk is being managed.

That philosophy closely mirrors KYND's wider approach to public entity cyber risk: creating continuous visibility, helping identify where attention is required and building evidence of improvement over time.  

As AI becomes increasingly embedded across public entity operations, that visibility may become one of the most valuable foundations a pool can help its members establish. 

Want to explore the research behind these insights? 

Download the white paper to gain a deeper understanding of how AI is reshaping cyber risk and the insurance landscape.