AI is already in your business. Is it in your insurance programme?

29 Jul 2026
By Richard Hood Chief Executive Officer | OLEA South Africa
Tags:
Archives:
2026 2025 2024 2023 2022 2021

AI RISK & INSURANCE
AI is already in your business. Is it in your insurance programme?

According to recent industry surveys, most organisations didn't roll out AI through a formal programme - employees simply started using it. A large majority of staff now use AI tools in their daily work, often without their employer's knowledge or approval. This is what's known as ‘Shadow AI’, and it’s changing how work gets done, while quietly creating new pockets of risk along the way.

‘Shadow AI’ by definition is, the unsanctioned use of any artificial intelligence (AI) tool or application by employees or end users, without the formal approval or oversight of the information technology (IT) department.’

Although the name may suggest something slightly sinister, it is not necessarily so. It is the lack of visibility or activity that is difficult to monitor which is a hidden risk.

The reason employees turn to these tools is understandable - saving time, reducing errors, cutting out repetitive tasks. The problem is that this happens outside any monitored framework, which makes the exposure hard to spot and even harder to measure.

For example: Any one of these can turn into a regulatory, reputational or operational problem long before anyone in the business notices.

  • A contract extract pasted into a public AI tool
  • Source code shared with a third-party platform
  • Client data processed in a way that falls outside POPIA or similar regulation

Blocking access outright is tempting, but it rarely works - it just pushes the usage further underground. A more workable approach combines a clear usage policy, secure approved tools and ongoing staff education. In fact, the same internal discipline most organisations already apply to cybersecurity.

Where insurance fits - and where it doesn't (yet)

From a risk and insurance perspective, the real question is what happens once AI itself causes the loss. Industry surveys point to an interesting tension here: Most executives are embracing AI, but not without reservations. They see the real value but admit they only have low to moderate trust in the technology itself.

Some AI-related exposures are probably already covered, even if unintentionally, under existing Cyber and Director and Officers (D&O) policies. Think of a privacy breach caused by an AI tool or a mismanagement claim linked to a decision to deploy AI.

Other exposures sit in a grey area: Professional Indemnity cover may or may not respond to a discrimination claim or an error or omission claim, stemming from AI-enabled advice. It will depend on how the policy is worded.

Then there's a third category that is often left completely exposed - the business's own financial loss when a model simply gets something wrong. For example, an undetected fraudulent transaction that slips through or an incorrect refund paid out at scale, where AI agents are deployed.

A new generation of cover

AI-specific insurance is still a young market in South Africa, but it is starting to take shape. A policy has recently been introduced locally for enterprises who provide both AI solutions and applications to their customers. The policy provides liability coverage for any legal defence costs should a loss occur in both the distribution and delivery of AI products and advice.

The takeaway

AI risk isn't hypothetical anymore it will have an impact on most businesses. Although insurance has a role to play, it is important that organisations identify their own AI risks properly and mitigate these proactively. Reviewing your existing insurance programme against how AI is genuinely being used in your business is a sensible place to start.

Speak to your OLEA account executive to find out where your current cover responds to AI-related risk - and where it doesn't yet.

Richard Hood - Chief Executive Officer | OLEA South Africa