Summary
- KYND says insurers can identify externally visible AI technologies from an organisation’s domain.
- The capability is intended to supplement proposal forms and underwriting conversations rather than replace them.
- Portfolio analysis can identify concentrations around common AI technologies and dependencies.
Cyber insurers are gaining another external signal for assessing AI exposure as KYND adds technology detection intended to show which AI services and features are visible across an organisation’s public digital footprint.
KYND said its new capability allows underwriters to start with a domain and identify externally detectable AI technologies without requiring the insured organisation to provide that information first.
The data is intended to sit alongside proposal forms and underwriting conversations rather than replace self-declared information. KYND says it can identify visible AI assistants and chatbots, generative-AI tools, AI features embedded in marketing and commerce technology, and AI crawlers permitted by an organisation’s infrastructure.
The launch addresses a growing underwriting problem: AI adoption can change faster than annual insurance submissions or internal technology inventories. Employees can introduce unsanctioned tools, software vendors can add AI features to existing products, and public websites can acquire new dependencies without a dedicated procurement event.
That creates uncertainty for insurers attempting to understand whether AI changes the frequency, severity, or concentration of cyber losses. The industry has extensive loss history around more conventional cyber incidents, but experience involving AI supply-chain dependency, autonomous agents, model compromise, and shadow AI remains comparatively limited.
External detection provides only part of that picture. Identifying an AI-related service on an internet-facing asset does not establish what information the system can access, how sensitive its workload is, whether it is governed internally, or whether any exploitable weakness exists.
Its value is therefore in providing another starting point for underwriting. A discrepancy between what a business declares and what can be observed externally may expose gaps in technology ownership or internal AI governance.
Melanie Hayes, KYND’s co-founder, said the additional evidence changes the starting point for that discussion: “Having something observed on the risk itself changes where the conversation starts.”
KYND is also positioning the technology for portfolio analysis. Used across multiple insured organisations, common AI platforms or dependencies can be identified as possible concentration points.
That is relevant to cyber insurance because aggregation risk can cut across policyholders that otherwise appear unrelated. A widely used cloud provider, identity platform, managed-service supplier, or software component can create correlated losses when it fails or is compromised. Common AI services could create a comparable dependency if adoption becomes concentrated around a small number of models, APIs, or infrastructure providers.
IBM’s 2025 Cost of a Data Breach research provides some evidence for the governance concern behind the launch. One in five organisations in the study reported a breach linked to shadow AI, while organisations with high levels of shadow AI experienced an average of $670,000 in higher breach costs than those with low or no shadow AI.
Those figures describe IBM’s study population rather than a loss forecast for an individual policyholder. They nevertheless illustrate why underwriters are seeking additional ways to test whether declared AI governance matches observable technology use.
KYND’s AI capability forms part of wider technology detection that includes cloud services, payment technology, analytics, tracking tools, identity systems, session-recording technology, and website platforms.
The wider direction is towards cyber underwriting based on independently observed technical information alongside questionnaires. More data can improve visibility, but the quality of underwriting still depends on interpretation. Detecting a technology is evidence of a dependency, not proof of weak controls or elevated loss probability.
As AI becomes embedded inside existing business software rather than deployed as a standalone system, that distinction will become increasingly important. Insurers may gain more technical signals while still needing organisational context to determine what the detected technology means for the risk.




