KYND, a provider of cyber risk intelligence for the insurance industry, has introduced new AI detection capabilities designed to give cyber insurers greater visibility into artificial intelligence technologies across organizations’ external digital infrastructure.
The AI discovery tool allows underwriters to identify AI applications and technologies associated with a business using a single domain, without requesting additional information from the insured.
It provides independently observed technology data to supplement proposal forms, underwriting discussions and information supplied directly by businesses.
The launch addresses a growing problem for cyber insurance underwriting as companies deploy AI across business operations. Insurers need to assess the technologies organizations use and the potential exposures associated with them, yet much of the information available during underwriting depends on what applicants know about their own systems and choose to disclose.
AI adoption is also moving faster than internal monitoring and governance practices at some organizations. As employees introduce new applications without formal approval, insurers face additional uncertainty over the technologies operating within an insured business.
According to IBM, one in five organizations reported a breach involving shadow AI last year. Shadow AI refers to artificial intelligence applications used without formal authorization or governance.
Organizations with high levels of shadow AI recorded average breach costs $670,000 higher than businesses with little or no unauthorized AI activity.
“Every AI question on a proposal form can only tell an underwriter what a business knows and declares,” said Melanie Hayes, co-founder of KYND. “Underwriters have been pricing AI exposure on trust because there was nothing else to go on. Having something observed on the risk itself changes where the conversation starts.”
The new detection capability examines an organization’s externally visible digital assets to identify AI applications and features. These include AI assistants, chatbots, generative AI tools and AI functionality embedded in marketing and e-commerce systems. It also identifies AI crawlers permitted by the organization’s infrastructure.
Rather than relying exclusively on customer declarations, underwriters receive an independent view of technologies detectable through the company’s online presence.
This gives insurance teams another source of evidence when reviewing submissions, assessing cyber exposures and discussing technology use with prospective or existing policyholders.
The distinction matters because an organization’s declared AI inventory doesn’t necessarily match the technologies visible across its digital operations. New applications and embedded AI functions might appear before they are formally documented, leaving insurers with an incomplete picture when reviewing risk.
KYND’s latest release follows its research into what the company describes as silent AI exposure within insurance portfolios. Its white paper, The Wild West of AI Risk, examined how businesses are adopting AI technologies faster than they report their use to insurers.
The research warned that incomplete disclosure creates the potential for unidentified exposure during underwriting. Similar technologies appearing across multiple insured businesses also raise questions about how widely certain AI dependencies are distributed within an insurance portfolio.
KYND’s AI discovery capability is intended to address part of this information gap by adding externally observed technology findings to existing underwriting data. The tool focuses on technologies detectable from an organization’s digital footprint, providing another basis for examining AI adoption alongside information obtained directly from the insured.
Beyond individual risk assessment, KYND is positioning the technology for portfolio monitoring and reinsurance analysis. Applying the same detection approach across multiple insured organizations allows insurers to examine where particular AI applications, service providers and technology dependencies repeatedly appear.
Repeated use of the same technologies across unrelated businesses creates potential accumulation exposure. Insurers assessing a portfolio need visibility into those shared dependencies to understand how an incident affecting one technology provider might influence several insured organizations.
The bigger issue is what happens when you look across the book. If the same AI technologies and dependencies are showing up repeatedly across insureds, that can quickly become an accumulation issue. Insurers need to be able to identify those concentrations before losses reveal them.
Melanie Hayes, co-founder of KYND
This portfolio perspective extends the application of AI discovery beyond individual policy submissions. Underwriting teams receive technology information for specific organizations, while portfolio managers and reinsurers gain a consistent dataset for examining common dependencies across groups of insured businesses.
AI detection forms part of KYND’s existing technology identification offering, which examines a broader range of services and applications associated with an organization’s online infrastructure.
The company’s detection capabilities cover payment services, cloud platforms, analytics technologies, tracking pixels and session-recording tools. They also identify identity and access management technologies and the platforms used to build and operate websites.
These findings provide insurers with additional information about the third-party services and digital technologies associated with individual businesses. When assessed across a portfolio, the same data supports analysis of shared technology providers and potential concentrations of cyber exposure.









