Insurancebusinessmag iconInsurancebusinessmagSep 24, 2026 ~5 min source read

AXA XL: AI adoption outruns governance, creating enterprise resilience gaps

AXA XL and S‑RM find most organisations now use AI but lack matching governance, calling for enterprise-level resilience planning across data, access, vendor oversight and incident readiness.

AI governance isn't keeping pace with AI adoption, AXA XL warns

Share this story

Send the public story page.

Useful takeaways from this story.

Five leader priorities: assign enterprise accountability, protect sensitive data and identities, manage AI across the full lifecycle, apply rigorous third‑party due diligence, and prepare for multi‑line AI loss scenarios.

Secure AI foundations: strong data governance, secure models and applications, ecosystem resilience, robust access controls and continuous monitoring.

Pre-deployment security checks are increasing but must be complemented by continuous oversight during operation and incident readiness.

The useful part

Managing AI Risk Through Governance, Security and Resilience, called on business leaders to treat AI risk as an enterprise resilience issue rather than solely a technology or compliance concern. AXA XL and S-RM said that scale of adoption is creating more potential entry points for cyber threats while introducing new forms of operational, regulatory and third-party risk. Meanwhile, Rebiah Bardot-Girard, head of cyber risk consulting services at AXA XL, said AI risk rarely emerges in isolation.

How it works

  • "It amplifies existing weaknesses in identity management, data governance, supplier oversight and incident readiness," she said.
  • SIGN UP IB+ Data Hub The Ultimate Data Intelligence Platform for Insurance Professionals Unlock powerful dashboards and industry insights with IB+ Data Hub—your essential subscription for data-driven...
  • AXA XL and S-RM cautioned that pre-deployment assessment alone isn't enough.

What to take from it

A gap the wider insurance market has also flagged This report's central warning, that insurance products and enterprise governance are both struggling to keep pace with AI risk, echoes findings published earlier in 2026 by Gallagher Re in its own report, Smart Systems, Blind Spots:

Details worth keeping

Most haven't built the governance to match DIGITAL TRANSFORMATION By Josh Recamara 24 Sep 2026 Share AI is becoming embedded in critical business processes faster than many organisations can adapt their governance, security and incident-response capabilities, according to AXA XL and cyber security consultancy S-RM. There are signs some organisations are responding. That report found generative AI-related litigation in the US grew 978% between 2021 and 2025, arguing that hallucinations, algorithmic discrimination, model drift and supply-chain compromises create liability through mechanisms traditional policies were never designed to address.

Related coverage

  • Infosecurity Magazine: A new report by ISACA found that 71% of orgs have not run AI incident response exercises as teams face rising pressure
  • Insurancebusinessmag: Insurance leaders rate their AI progress highly, but spending remains fixed on back-office savings rather than the broker-facing parts of the business.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app