[nonimo]
EN
Download

Cyber insurance questionnaire: the AI questions, answered

· Updated · Written and maintained by Joaquín Trapero, Nonimo

Your broker sends the renewal pack with its cyber insurance questionnaire, or a client sends its supplier security questionnaire, and somewhere inside there is a line about artificial intelligence. You have to answer it, the answer goes into something you sign, and nobody has told you what a good answer looks like.

So on 16 September 2026 I opened seven insurer and broker forms and read every question in each of them. Two ask about AI. Both of those are professional liability forms rather than cyber forms, and both of them ask for the same thing: a description, not just a yes. This guide is built around that one fact, and the question bank below is what a description looks like.

Copy it, change every answer so that it describes what your organisation actually does, and keep it with the form. Most of the evidence it asks for comes from one document, and the policy template is where that document starts. If you are here because somebody already sent a file to a chat window, that is a different question with a different clock.

AI QUESTIONS ON INSURANCE AND CLIENT QUESTIONNAIRES
A bank of real questions, a model answer and the evidence to attach.
Every question below is quoted from a form or a published question set.
Edit each answer so that it matches what your organisation actually does.

 1. "Allow the use of Artificial Intelligence software to draft documents.
    If checked, please attach description."
    AmTrust, Lawyers Professional Liability Application, LPLPRO-APP-01 0523, Section III.
    Say: yes, if anyone drafts with an AI tool, including the one inside your
    office suite. Attach: the written AI policy and the list of approved tools.

 2. "Does the firm allow for the use of Artificial Intelligence software to
    draft documents? If Yes, please describe."
    AmTrust, Lawyers Professional Liability Renewal Application, LPLPRO-APP-02 0523, 11.b.
    Say: what is allowed, what is forbidden, on which accounts, and since when.
    Attach: the policy, dated, and the signed acknowledgements.

 3. "Do you have an AI Governance Framework with Board/Management oversight,
    which includes specific use cases, restrictions and authorization policies?"
    Aon, AI Fact Sheet 2026, sample of application questions carriers are developing.
    Say: name the document, its date, who approved it, where staff can read it.
    Attach: the policy and the register of approved use cases.

 4. "Is the Insured developing and providing Generative AI solutions to
    customers, or is the use for internal purposes only?"
    Aon, AI Fact Sheet 2026.
    Say: internal only, if you do not sell or embed an AI feature. If a client
    facing tool drafts or scores anything, say so. Attach: the use case register.

 5. "Does a human need to verify accuracy before AI takes action?"
    Aon, AI Fact Sheet 2026.
    Say: yes, and name the step. No AI output leaves the firm unreviewed.
    Attach: the clause of the policy that says it, by number.

 6. "Are AI actions logged so potential errors can be reviewed and remediated?"
    Aon, AI Fact Sheet 2026.
    Say: what is logged and where. If your only record is the account history
    of the tool, say that. Attach: nothing you cannot produce on request.

 7. "Are you confirming whether any key vendors are utilizing AI, and if so,
    what safeguards are in place to prevent errors or bias?"
    Aon, AI Fact Sheet 2026.
    Say: which suppliers you asked, when, and what they answered. Attach: the
    replies. If you have not asked yet, say so and give a date.

 8. "Who owns and has what rights to use the prompts (inputs) and outputs?
    Are the prompts and outputs subject to confidentiality obligations?"
    Aon, AI Fact Sheet 2026, contracting questions.
    Say: quote your supplier terms, do not summarise them. Attach: the clause.

 9. "Are the policies and procedures on the acceptable use of AI technologies
    within the organization established, documented, and communicated to all
    personnel?"
    Cloud Security Alliance, AI-CAIQ v1.0.2, 15 October 2025.
    Say: yes only if all three are true. Attach: policy, date, acknowledgements.

10. "Are data inventories created and maintained at least for any sensitive,
    regulated, and personal data?"
    Cloud Security Alliance, AI-CAIQ v1.0.2, 15 October 2025.
    Say: what categories you hold and where. A short list beats a claim.
    Attach: the annex of your policy that names the data that never goes in.

BEFORE YOU SIGN
Read the declaration on the form itself. One asks you to confirm a fair
presentation of the risk. Another states that the application is attached to
and made part of the policy. A third states that underwriters rely on every
statement made. The answers above are worth writing carefully for that reason.

What a cyber insurance questionnaire actually asks about AI

Very little, so far. The five cyber forms I opened do not contain the words artificial intelligence, machine learning or generative anywhere in them, and that includes the forms from Beazley and from Chubb.

Of the 7 forms opened for this guide, only 2 ask about AI, and both are professional liability forms. What the forms do ask about is stable, almost word for word across insurers, and it is worth knowing because it shows where an AI question will eventually be filed.

2 of 7
insurance application and renewal forms opened on 16 September 2026 asked about AI. Both were professional liability forms

The seven forms, and which ones ask

FormLine of businessAsks about AI
Beazley, Cyber Insurance Questionnaire, revenues under £20Mcyberno
Chubb, Cyber Enterprise Risk Management, Singaporecyberno
Chubb, Cyber ERM Standard Proposal Form, UK8244-MD 08/22cyberno
Chubb, Privacy Protection Renewal Application, Canadacyberno
Apogee, Cyber Liability Insurance Questionnairecyberno
AmTrust, Lawyers Professional Liability Applicationprofessional liabilityyes
AmTrust, Lawyers Professional Liability Renewal Applicationprofessional liabilityyes

The cyber forms all ask about the same handful of controls. All five ask whether you have had a claim or know of a circumstance that might become one. Four of the five ask about multifactor authentication, and the same four ask about backups and about security awareness training.

Beazley is the one that spells out what it means by both: backups are copies kept offline that you regularly test to confirm they can be restored, and training means training for everyone with access to your network or to confidential information. It even prices them, telling applicants that satisfactory answers to its optional control questions “may discount the base premium offered by up to 20%”.

Prior claims5
Multifactor authentication4
Backups4
Artificial intelligence0
How many of the five cyber forms ask about each topic. Counted on 16 September 2026

None of that touches what your staff paste into a chat window, which is the risk you are probably worrying about. That gap is the reason the question of whether pasting client data into a chat window is a breach has to be answered on its own terms, and why a written policy is doing more work here than any control on the form.

“If checked, please attach description”: the question is a request for a document

The two forms that do ask are both AmTrust lawyers professional liability forms, and neither of them wants a yes.

On AmTrust’s application for new business, form LPLPRO-APP-01 0523, the question is the last checkbox in a list under Section III, Internal procedures. The list is question 13, “Check all that apply”, and it runs through engagement letters, docket controls, procedures for conflicts of interest, declination letters, background checks on prospective clients. The final line reads: “Allow the use of Artificial Intelligence software to draft documents. If checked, please attach description.”

Where the renewal form files it

AmTrust’s renewal form, LPLPRO-APP-02 0523, puts it somewhere more revealing. Its Section III is headed Changes to internal procedures, and the AI question is 11.b, immediately after a question asking whether anything has changed in the firm’s docket procedures or its procedures for conflicts of interest in the last twelve months. It reads: “Does the firm allow for the use of Artificial Intelligence software to draft documents?”, followed by “If Yes, please describe.”

The same form asks, among the documents you may be asked to supply, for a “Copy of your in-house corporate privacy policy(ies) currently in use by your organization”. The pattern is consistent: the renewal wants paper, not opinions.

Read those two AmTrust questions together and the underwriter’s model is clear. Drafting with AI is treated as a change to how the firm produces work, not as a technology purchase, and it sits in the same list as who checks a conflict and who signs off a settlement letter.

Why a checkbox is harder than it looks

Both versions of the question ask for prose. People deciding between yes and no tend to miss that. A firm that checks the box and attaches nothing has answered worse than a firm that checks the box and attaches one page.

It also dates the question. The form code 0523 puts both versions at May 2023, which means AmTrust was asking lawyers about AI drafting about six months after ChatGPT was released to the public, and long before most of what has since been written about it.

May 2023
the date on the AmTrust form code 0523, which already asks whether the firm drafts with AI

So this is not a question that arrived with the last news cycle, and it is not one your broker invented to be difficult. If your renewal pack has never carried it, that is a fact about your line of business and your insurer, not a sign that it is optional. The policy you write now is the answer to the version that arrives later.

The broker’s question bank is years ahead of the form

While the forms stay quiet, the brokers are building the questions. Aon’s AI Fact Sheet 2026 states it plainly: “To test whether organizations are implementing risk management best practices related to AI liability and insurance coverage, insurance carriers are developing AI insurance application questions”, and then prints a representative sample of about fifteen of them.

Aon does not present that sample as any named insurer’s form. It shows what a broker expects to be asked, which for planning purposes is better than a form, because it tells you what is coming before it arrives.

The four families in Aon’s sample

FamilyWhat it wants to knowTypical question
Governancewho authorised what, and in writingis there a framework with board oversight and named use cases
Oversightwhether a person checks the outputmust a human verify accuracy before AI takes action
Supply chainwhether your vendors use AI toohave you conducted diligence before contracting
Contractingwho owns the prompts and the outputsare inputs and outputs subject to confidentiality obligations

Three of those four have nothing to do with buying software and everything to do with writing things down. The fourth, contracting, is answered by reading the terms of the tools you already pay for, which nobody enjoys and everybody can do.

The two a small firm tends to get wrong

The first is disclosure. Aon’s sample includes a question about whether notices are provided to consumers on the use of AI, and for a firm that has never been asked to publish one, the correct answer is no. Saying no is fine. Saying yes because it sounds better is the mistake, and it is the kind of statement the EU AI Act’s transparency duties will eventually make checkable.

The second is the vendor question. Aon’s sample asks, “Are you confirming whether any key vendors are utilizing AI”, and that is a question about your practice management system, your billing platform and your outsourced typing service, and the point is that you probably do not know which of them now uses AI. If you have not asked them, the answer is that you have not asked them yet, with a date by which you will.

The client questionnaire usually arrives before the insurer’s

For most firms the first AI questionnaire is not from an insurer at all. It comes from a customer, attached to a renewal of work, and it is a supplier security assessment with a new section in it.

The reference version is public and free. The Cloud Security Alliance publishes the AI Consensus Assessments Initiative Questionnaire, the AI-CAIQ, which maps to its AI Controls Matrix, 247 control objectives in 18 domains, and downloads as a spreadsheet without an email address.

247control objectives
18domains
320questions in the AI-CAIQ
Cloud Security Alliance, AI Controls Matrix v1.1, 14 July 2026

What 320 questions means for a firm of twelve

Mostly that the file was not written for you. Read the AI-CAIQ and the intended respondent is obvious: it asks whether models are signed cryptographically to prove provenance when they change hands, whether training data is validated for consistency, whether measures exist to prevent data poisoning. Those are questions for whoever builds the model.

The useful move is to answer the handful that apply to an organisation that uses AI rather than one that ships it, mark the rest as not applicable, and say why in one line. A questionnaire returned with three hundred honest “not applicable” answers and twenty careful ones reads far better than one returned with three hundred and twenty yeses.

The one question that decides the other nine

The Cloud Security Alliance puts it like this: “Are the policies and procedures on the acceptable use of AI technologies within the organization established, documented, and communicated to all personnel?”

Three conditions, and you need all three. Established means somebody decided. Documented means it exists as a file with a date on it. Communicated means staff have seen it and you can show that they have.

Answer that one with a yes and an attachment and most of the questions further down the sheet become easy, because they are asking for pieces of the same document. A template with fifteen clauses and four annexes is the shortest route to that yes, and there is nothing to buy to use it.

What you are signing when you answer

Every one of these forms carries a declaration, and that wording is why an awkward, accurate answer beats a tidy, optimistic one.

FormWhat the declaration says
Beazley cyber questionnaireyou confirm a fair presentation of the risk under the Insurance Act 2015
Chubb Privacy Protection renewalthe application is attached to and made part of the policy
Chubb Privacy Protection renewalunderwriters will rely on all statements made in this application
Chubb Cyber ERM, Singaporeyou must disclose every matter material to the insurer’s decision, or the policy may be void

Section 3 of the Insurance Act 2015 is headed the duty of fair presentation, and its first line reads: “Before a contract of insurance is entered into, the insured must make to the insurer a fair presentation of the risk.”

The other forms set out their own version of the same demand, in their own words and under their own law. Chubb’s Canadian renewal form goes further and names who has to sign: “the CEO, CFO, President, Risk Manager or General Counsel”.

That signature line is the practical argument for writing your answers down before the form gets filled in. The person signing is rarely the person who knows which tools the team is using, and they are the one whose name goes on it.

It is also why the evidence matters more than the wording. A signed declaration supported by a dated policy and an acknowledgement sheet is a fair presentation that you can show. The same declaration supported by memory is not, and if your systems are run by an external IT provider, they hold half the facts you are signing for.

How to answer “do you use AI?” without overstating it

There are three bad answers, and each of them fails differently.

The answer that works is narrow and dated. What is allowed, what is forbidden, on which accounts, who reviews the output, and since when. Five clauses, roughly, and you should be able to point at the document each one came from. If somebody on the team put client data somewhere it should not have gone, that is a separate assessment and it does not belong in this box.

The four answers side by side, with the question on the forms that will test each one:

AnswerWhy it fails or worksThe question that will test it
The flat noan AI feature is already switched on in the office suite or the transcription toolAmTrust: does the firm allow AI software to draft documents?
The enthusiastic yesinvites every further question and answers noneAon: is there an AI governance framework with board oversight?
The yes with a purchase ordera claim about what the product doesclient questionnaire: do you block uploads to public AI services?
The narrow, dated answereach clause points at a dated documentCloud Security Alliance: is the policy established, documented and communicated?

The three documents you attach, and where they come from

Every version of the AI question, on both AmTrust forms and across Aon’s sample, is satisfied by the same three attachments.

  1. The written policy. What staff may do with AI, what is never permitted, and which accounts are approved. Dated and approved by a named person. Our acceptable use policy template is fifteen clauses and takes an afternoon to adapt.
  2. The proof that people read it. An acknowledgement sheet with names and dates. This is the piece firms skip, and it is the one that turns “communicated” into a fact rather than a claim.
  3. The list of accounts and tools. Which products are approved, on which plan, and under whose account. Free consumer accounts and paid business accounts are different legal positions, and underwriters know it.

Here is what the attachment itself can look like. It is short on purpose.

AI USE: DESCRIPTION ATTACHED TO THE APPLICATION
Firm: [name]          Prepared: [date]          Approved by: [name, role]

1. What we use. Drafting and summarising assistance inside our office suite,
   on organisation accounts only. No consumer accounts are permitted for
   client work. Policy clause 4, dated [date], attached.
2. What is never entered. Client identifiers, financial account numbers and
   health information, as listed in Annex A of the policy.
3. Who checks. No AI output leaves the firm without review by the fee earner
   responsible for the matter. Policy clause 9.
4. Who has been told. All [n] staff acknowledged the policy on [dates].
   Acknowledgement sheet attached.
5. Suppliers. We asked our [n] key suppliers whether they use AI in
   delivering services to us on [date]. Replies attached.

“Do you have DLP?” and “do you block uploads?”

These two appear on client questionnaires constantly, and they are the questions where an honest small firm is tempted to stretch.

Data loss prevention means a control that inspects what leaves the network and can stop it. Blocking uploads means the same thing at the browser. If you have neither, the answer is no, followed by what you do have: organisation accounts rather than personal ones, a written rule, a review step, and a named person who checks.

Underwriters and security reviewers see that answer often and can price it. What they cannot price is a yes that turns out to mean a policy document.

No redaction tool answers either of these questions, ours included. A tool that strips identifiers out of text before it is sent is a minimisation control, not a blocking control, and calling it DLP on a questionnaire would be a statement about what we actually ship that we could not stand behind. If your IT provider tells you otherwise, ask them which of the two functions they mean.

Silent AI: what your current policy probably says about AI, which is nothing

The question behind the questionnaire is usually whether the policy would respond at all. Aon’s answer is the most useful number in this whole area: over 90 per cent of any cover for AI perils sits in policies that do not mention AI at all.

over 90%
of any cover for AI perils sits in policies that do not mention AI. Aon, AI Fact Sheet 2026

Aon calls that position silent AI, and defines it as a policy that “neither affirmatively covers AI nor excludes AI”. It draws the parallel with silent cyber, when losses were argued into property and liability policies that had never mentioned computers, until Lloyd’s required every policy either to grant cyber cover or to exclude it. It sets out three ways the market is now responding to AI: silence, affirmative cover added by endorsement, and specific exclusions.

Which of those three applies to you is a question for your broker, with your policy wording in front of both of you. It is not something a guide can tell you, and it is not something to infer from a headline.

What you can do before that call is have the answers to the questions above written down, so the conversation starts from facts rather than from a shrug. An hour reading up on the regulatory deadlines is worth it too, though none of it decides your cover.

What a tool can do here, and what no tool can do, including ours

Software helps with exactly one family of these questions: the ones about what is in the text. If identifiers are removed from a document before it is sent to a model, you can answer a minimisation question honestly. Nonimo does that on the computer rather than in a cloud service. Name the result carefully on the form, because masked, pseudonymised and anonymised are different claims to whoever reads it.

With the desktop app alone, the honest answer to enforcing a rule, blocking an upload and keeping a central record is no. The browser extension, installed by policy and active only in the AI tools you authorise, changes two of those answers: IT can set it to block, and a panel in your own infrastructure keeps a central record of counts per device, pseudonymous by default, never the text.

Anyone who tells you a redaction tool answers all three on its own is selling you a sentence you will have to withdraw. Written out for the form, because a no with a reason is an answer and a no on its own is a gap:

THREE QUESTIONS WHERE OUR ANSWER IS NO
Q. Do you operate data loss prevention on endpoints?
A. No. We run no control that inspects or blocks outbound content. We use
   organisation accounts, a written rule and a review step before output leaves
   the firm. Policy clauses 4 and 9 attached.
Q. Do you block uploads of confidential files to public AI services?
A. No technical block. The rule is written and acknowledged by all staff; there
   is no enforcement agent installed. Policy clause 5 and the acknowledgement
   sheet attached.
Q. Do you keep a central log of AI use across the organisation?
A. No central log. Each approved account keeps its own history and we can
   produce it on request. Account list attached.

What the app keeps on your disk, encrypted, is on the security page.

The governance half, which no software touches

That half is most of Aon’s sample, and no tool does any of it. A framework, board oversight, named use cases, supplier diligence, a human verification step. Those are decisions, written down, and the firm has to make them.

If you buy nothing at all, do these six things

  1. Find the form before the deadline. Ask your broker for the questionnaire now rather than the week it is due, and read the declaration first.
  2. Write the policy. Fifteen clauses, one page of annexes, one date, one signature. Start from a template rather than a blank page.
  3. Collect the acknowledgements. Names and dates on one sheet. This is the cheapest evidence in the whole exercise.
  4. List the accounts. Every AI tool in use, which plan, whose account. Include the ones nobody thinks of, like transcription and translation.
  5. Ask your five biggest suppliers. One email: do you use AI in delivering services to us, and if so where. File the replies.
  6. Give it to whoever signs. The person whose name the form demands should read your answers before, not after. If an external IT provider manages your systems, they hold half the facts and should see it too.

That is the whole exercise, and none of it needs a purchase order. It is also, not by coincidence, most of what an underwriter is trying to find out.

Two things you will read elsewhere that are wrong today

The first is that insurance renewals cluster into the last quarter of the year, so you have until then to deal with this. I could not find a primary source for that claim, and none of the seven forms I opened carries a season. Renewal dates are set by the policy you bought, and yours is on your schedule.

The second is that insurers are now excluding AI, so using ChatGPT could void your cover. Nothing in the forms or the broker material I read supports that as a general statement about the market.

What Aon documents is a market in three states at once, with over ninety per cent of exposure still silent. The only way to know which state your policy is in is to read your own wording with your broker. A guide that tells you your cover is gone, ours included, is guessing about a document it has never seen.

Sources

Checked 16 September 2026. Every form below was opened and read in full, including the pages that are stored as encoded text rather than plain text.


This page is for information and is not legal or insurance advice. For your own policy, ask your broker or a qualified adviser.

Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.

Common questions

Does a cyber insurance questionnaire ask about AI?

Usually not yet. Of seven insurer and broker forms opened on 16 September 2026, the two that asked about AI were both professional liability forms from AmTrust. None of the five cyber proposal forms mentioned artificial intelligence anywhere.

What do I write when a form asks whether we use AI?

Answer yes if anyone drafts, summarises or translates with an AI tool, including one built into your office suite. Then attach a description: the written policy, the list of approved tools and the signed acknowledgements. Both AmTrust forms ask for that description.

Can I answer no if only one person uses ChatGPT now and then?

Not if the question asks whether the firm allows it or whether it happens. Your answer sits inside a declaration you sign, and the forms say the insurer relies on it, so an answer that is later shown to be incomplete is worse than an awkward yes.

Does my cyber policy cover AI?

Most likely it neither covers nor excludes it. Aon's AI Fact Sheet 2026 states that over 90 per cent of any cover for AI perils sits in policies that do not mention AI at all, a position it calls silent AI.

What is an AI security questionnaire?

A supplier assessment with a section on artificial intelligence. The Cloud Security Alliance publishes a free one, the AI-CAIQ. Version 1.1 runs to 320 questions mapped to a matrix of 247 controls, and most of them are written for an AI vendor rather than a small firm.

What evidence do I attach to the answer?

Three documents usually cover it: the written acceptable use policy for AI, the record that staff have read it, and the list of accounts and tools you approve. None of the three requires buying software, and all three can be produced in an afternoon.

Do I have to say that we have DLP?

Only if you do. Data loss prevention means a control that inspects or blocks what leaves your network. If you have none, say what you do have instead, say how you check it, and let the underwriter price the difference.

Will a redaction tool let me answer yes to more questions?

To some of them, not most. A tool that strips identifiers before text is sent speaks to data minimisation. It says nothing about blocking uploads, board oversight, logging or supplier diligence, which is where most of the AI questions actually sit.

Is a careless answer really risky?

The forms say so in their own words. One asks you to confirm a fair presentation of the risk under the Insurance Act 2015. Another states that the application is attached to and made part of the policy. A third states that underwriters rely on every statement.

Who should sign the questionnaire?

Whoever the form names, and it often names someone senior. Chubb's Canadian cyber renewal form requires the CEO, CFO, president, risk manager or general counsel. That is a good reason to hand them your answers in writing before they sign.