D&O and AI: How Governance Is Entering the Underwriting Conversation
Forward-looking analysis and opinion — not a description of current law or a regulatory requirement. Verify against primary sources before relying on it for a board decision.
D&O and AI: How Governance Is Entering the Underwriting Conversation
BoardSight Analysis · Reading time: ~8 minutes Category: Thought Leadership · Published April 16, 2026 · Updated July 2026 · Author: James Waddell, Cognitive Corp
This is BoardSight's analysis of a developing market. It is not legal, insurance, or financial advice. The figures, cases, and market data below are drawn from the public sources listed at the end; where the direction of the market is uncertain, we say so.
Abstract
Directors and officers (D&O) insurance is a lagging indicator of governance expectations. As of 2026, the broad D&O market is soft — premiums have fallen for four consecutive years — so AI has not produced across-the-board rate increases. What has changed is the underwriting conversation: brokers report that underwriters are beginning to ask about a company's “AI maturity” at renewal, and the litigation and enforcement record now contains real, named AI-related securities cases and the first SEC “AI-washing” penalties. This brief separates what is documented from what is still speculative, and sets out what boards should prepare so they can answer the AI-governance questions underwriters are starting to ask.
1. What has actually changed — and what hasn't
Two things are true at once, and it matters not to collapse them.
The market is soft, not hard. Through 2025 and into 2026, D&O pricing has been flat to declining. Marsh's Global Insurance Market Index put financial and professional lines (which include D&O) down about 5% in the first quarter of 2026, and AM Best has described 2025 as the fourth consecutive year of premium decline. So any claim that AI is driving “15–40% premium increases” is not supported by the market data — the opposite is closer to the truth. AI is a forward-looking pressure on a soft market, not a current price driver, and we have removed earlier figures that suggested otherwise.
The underwriting conversation is shifting. At the same time, brokers report that AI governance is entering renewal diligence. Willis Towers Watson has advised that underwriters “may inquire more into a corporation's AI governance practices, sometimes referred to as its ‘AI maturity,’ during upcoming renewal cycles,” and Woodruff Sawyer (now part of Gallagher) has said D&O underwriters “will scrutinize the board's oversight of AI risk.” This is not yet a standardized questionnaire across every carrier — underwriters themselves are still working out what can reliably be assessed — but the direction of travel is clear.
2. Why the litigation record matters more than the rate
The stronger signal is not in pricing; it is in the claims record.
AI-related securities litigation is real and countable. DLA Piper counted 14 AI-related securities class actions filed in 2024 and 12 more in 2025. The named defendants are not hypothetical — they include Innodata, Evolv Technologies, CrowdStrike, GitLab, UiPath, Oddity Tech, and Super Micro, among others catalogued by WilmerHale. The recurring theory: a company's public statements overstated its AI capabilities or understated AI-related risk, and the stock fell when reality surfaced.
“AI-washing” enforcement has begun. In March 2024 the SEC brought its first AI-washing settlements, penalizing two investment advisers — Delphia ($225,000) and Global Predictions ($175,000) — for false or misleading statements about their use of AI. Modest sums, but they establish that regulators will treat AI overstatement as a disclosure problem.
The Caremark / fiduciary strand is emerging, not settled. Commentators increasingly argue that AI is a “mission-critical” risk that triggers the board's oversight duty under the Caremark line of Delaware cases — In re Caremark (Del. Ch. 1996), sharpened by Marchand v. Barnhill (Del. 2019) and In re Boeing Co. Derivative Litigation (Del. Ch. 2021). But we are not aware of a landmark, fully-litigated AI-specific Caremark decision yet. Boards should treat this as an anticipated frontier, not established case law.
3. What the real discrimination cases actually show
The headline “AI bias” exposure is often quoted at eight or nine figures. The documented settlements are far smaller, and the marquee case is still unresolved — so we state the real numbers:
- iTutorGroup / EEOC — $365,000 (2023): recruiting software automatically rejected older applicants; settled under the ADEA.
- Louis v. SafeRent Solutions — about $2.2 million (settlement approved November 2024): a tenant-screening algorithm alleged to disadvantage applicants by race and income.
- Mobley v. Workday — no settlement: an ADEA collective action over an AI hiring tool; the court granted conditional certification in May 2025. It is ongoing, and no dollar figure exists.
The pattern that matters for boards is procedural, not the dollar amount: in each matter, the governance record — who tested the model, who signed off, what was documented — became evidence early. An absent record is the exposure.
4. The state-law layer is moving
Underneath the federal picture, the state layer is redrawing itself. Colorado repealed its pioneering AI Act (SB 24-205) in May 2026 (via SB 26-189) in favor of a narrower automated-decision-technology transparency regime, with enforcement pushed to January 2027. Connecticut's CART Act (SB 5, Public Act 26-15, signed May 29, 2026) sets employment-related AI obligations effective October 1, 2026, making it the current hard-dated US state anchor. New York City's Local Law 144 (bias audits for automated employment decision tools) remains in force. The practical effect: an AI-governance gap is increasingly a disclosable and actionable fact somewhere.
5. The AI questions a board should be ready to answer
Whether or not your carrier asks all of these this year, they track the diligence that is emerging and the evidentiary record any AI claim would later seek. A board should be able to answer, with documents in the room:
Governance structure. Is there a board-approved AI policy? Which committee has oversight, and when did it last review AI risk? Is AI on the risk register, and at what tier?
Management system. Has the organization mapped its AI governance to a recognized framework (ISO/IEC 42001, NIST AI RMF, or equivalent)? Who owns the review cycle?
AI system inventory. Is there an inventory of AI systems built, deployed, and consumed from third parties, with risk classification?
Impact assessment. Is an AI impact assessment required before deployment? Who signs off, and what triggers reassessment?
Incident response. Is there an AI-specific incident protocol, and has it been exercised? How many AI-related incidents were logged in the past 12 months?
Third-party AI. Are AI-vendor contracts reviewed for governance terms (data provenance, model documentation, audit rights, bias testing, termination)?
Disclosure. Have public disclosures been reviewed for AI materiality, and does the audit committee receive AI-related disclosure briefings?
6. On ISO 42001 and the NIST AI RMF as “pricing shortcuts”
It is tempting to say carriers now reward ISO 42001 or NIST AI RMF conformance with better pricing. As of 2026, that is not established: governance-industry analysts report they are not aware of insurers offering discounts tied specifically to either framework. What is true is narrower and still useful — a company that has mapped its AI governance to a recognized framework can answer underwriter questions faster and produce a cleaner evidentiary record if a claim ever comes. Treat these as emerging benchmarks insurers may reference over time, not as current pricing levers.
7. Individual director exposure (Side A)
Side A of the D&O program is the personal backstop for individual directors when the company cannot indemnify. Carriers have not broadly excluded AI claims from Side A, but a prudent board checks that indemnification and advancement provisions are current, that director education on AI is documented, and that Side A limits are sized for correlated-incident scenarios. Asking these questions is board hygiene — and it surfaces the board's actual governance posture quickly.
8. What boards should document before their next renewal
The 2026–2027 renewal cycle is a useful forcing function. Boards with runway should assemble: a dated, board-adopted AI policy; a scope statement for the AI management system; a current AI system inventory with risk classification; the most recent management-review record with findings and corrective actions; a controls-to-framework mapping (e.g., an ISO 42001 Statement of Applicability); the AI incident log for the past 12 months; the AI third-party-contract review status; and the AI-materiality review for 10-K risk factors and Item 1C. This is the same record discovery would later request — producing it for the renewal produces it for the adversary too.
9. What BoardSight delivers against this environment
BoardSight's 90-day Board AI Oversight Audit maps to the diligence described above: a documented governance posture against ISO 42001 Clauses 4–10 and Annex A, a NIST AI RMF profile mapping, an AI system inventory with risk classification, and an impact-assessment methodology. The benefit is not a promised premium discount — the market gives none for this today — but readiness: boards enter renewals able to answer underwriter questions with documents, and hold the evidentiary record a claim would later seek.
Sources
- Marsh, Global Insurance Market Index (Q1 2026): https://www.marsh.com/en/services/international-placement-services/insights/global-insurance-market-index.html
- AM Best via Insurance Journal (D&O premium decline): https://www.insurancejournal.com/magazines/mag-features/2026/07/13/877106.htm
- Willis Towers Watson, “AI governance gap — D&O considerations”: https://www.wtwco.com/en-us/insights/2026/03/sarbanes-oxley-and-the-ai-governance-gap-d-and-o-insurance-considerations
- Woodruff Sawyer / TheCorporateCounsel.net (AI's impact on D&O): https://www.thecorporatecounsel.net/blog/2025/03/do-insurance-ais-impact.html
- DLA Piper, AI-related securities class-action filings: https://www.dlapiper.com/en-us/insights/publications/2025/09/ai-related-securities-class-action-filings-are-on-the-rise-key-observations
- WilmerHale, 2024 AI securities litigation year-in-review: https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20250331-year-in-review-2024-ai-securities-litigation-trends
- Mayer Brown, SEC first AI-washing enforcement (Delphia; Global Predictions): https://www.mayerbrown.com/en/insights/publications/2024/04/securities-and-exchange-commission-brings-first-enforcement-actions-over-aiwashing
- EEOC, iTutorGroup $365,000 settlement: https://www.eeoc.gov/newsroom/itutorgroup-pay-365000-settle-eeoc-discriminatory-hiring-suit
- Cohen Milstein, Louis v. SafeRent (~$2.2M): https://www.cohenmilstein.com/class-action-lawsuit-on-ai-related-discrimination-reaches-final-settlement/
- Holland & Knight, Mobley v. Workday (conditional certification): https://www.hklaw.com/en/insights/publications/2025/05/federal-court-allows-collective-action-lawsuit-over-alleged
- StackAware, cyber insurance & AI governance frameworks: https://blog.stackaware.com/p/cyber-insurance-ai-governance-iso-42001-nist-rmf
- Case law: In re Caremark Int'l, 698 A.2d 959 (Del. Ch. 1996); Marchand v. Barnhill, 212 A.3d 805 (Del. 2019); In re Boeing Co. Derivative Litig., 2021 WL 4059934 (Del. Ch. 2021).
Claim status: qualified
Facts checked: 2026-07-22
Reviewed by: BoardSight Editorial Review (editorial)
Scope: US D&O market commentary; carrier-practice specifics are illustrative and not attributed to a named carrier.