The situation
The renewal package arrives from your broker six weeks before the policy expires. Most of it looks familiar: multi-factor authentication, backups, endpoint protection, phishing training. Then there is a new page. Does the organization maintain an inventory of AI tools used by employees? Is there a written policy governing their use? Are there technical controls that prevent confidential or personal information from being entered into them? Has staff been trained?
The finance director who owns the renewal forwards it to IT with a short note: can we say yes to these? The honest answer depends on what the organization can show, not on what it intends.
What the rules actually say
There is no Canadian regulation that dictates what a cyber insurer may ask about AI, and no standard AI questionnaire shared across carriers. Each insurer writes its own application, and wording changes from year to year. What can be described is the shape the questions tend to take. They usually fall into six groups:
- Inventory. Which AI tools are in use, which are sanctioned, and whether staff use personal accounts for work.
- Policy. Whether a written AI acceptable use policy exists, who approved it, and whether staff have acknowledged it.
- Data controls. Whether technical measures stop sensitive data (personal information, client records, financial data, source code) from being entered or uploaded into AI tools, as opposed to relying on instructions alone.
- Training. Whether staff receive AI-specific awareness training, and how completion is tracked.
- Vendor review. Whether AI features in third-party software are assessed, including what the vendor may do with your data.
- AI-enabled threats. Whether you have procedures against deepfake voice or video fraud and AI-generated phishing.
These groups line up closely with public Canadian guidance, which is useful when you need a reference point for what reasonable looks like. The Canadian Centre for Cyber Security's top 10 AI security actions include mapping sanctioned and unsanctioned AI use, writing an acceptable use policy, training staff, minimizing personal information in prompts, and putting data use and audit terms in vendor contracts. Its generative AI guidance advises against including personal information or sensitive corporate data in prompts. The federal, provincial, and territorial privacy commissioners' joint principles on generative AI encourage organizations to use anonymized or de-identified information in prompts rather than personal information. Underneath all of it sits the safeguards principle in PIPEDA Schedule 1, clause 4.7, which expects protection appropriate to the sensitivity of the information, including technological measures.
None of this guidance is written for insurers, and none of it is a coverage rule. It is simply the most defensible benchmark available when an underwriter asks what you do.
Why policies and bans fall short
The data controls question is where most organizations struggle. According to IBM's Cost of a Data Breach Report, 63% of organizations have no AI governance policy, and only 17% have technical controls that block or redact sensitive data at the point of entry (IBM, 2025). A policy answers the second question on the form. It does not answer the third.
A ban does not answer it either. When a tool is blocked on the corporate network, staff who rely on it tend to move to personal accounts and personal devices, which removes the organization's visibility without removing the behaviour. Our piece on getting visibility into shadow AI without banning every tool covers this in more depth.
There is also a practical reason to be careful. Insurers rely on application answers when they price and issue a policy. An answer that cannot be supported may surface only when a claim is being examined, which is the worst moment to discover it. Ask your broker how your policy treats application statements, and never answer yes to a control you cannot demonstrate.
What a practical control looks like
- Read the application early. Find every AI-related question, including ones folded into data protection or training sections, and note exactly what each one asks.
- Build the inventory. List the AI tools in use across the organization, which are sanctioned, and where personal accounts are involved.
- Adopt a short, specific policy and collect acknowledgements. The AI acceptable use policy generator is a reasonable starting point.
- Train with records. Run AI-specific awareness training and keep completion data by date.
- Put a technical control at the point of entry so that sensitive data is caught before it is submitted, and keep summary records that show the control operating.
- Review AI vendors. For each sanctioned tool, record its data retention and training terms and who approved it.
- Assemble an evidence file before you answer: one folder per question group, dated. If you are federally or provincially regulated in financial services, the same file often serves your partners too; see our guide on OSFI B-10 and B-13 and employee AI use.
Sanitized Ai is a browser extension that addresses the data controls and training questions directly. When someone pastes or uploads personal information, client identifiers, financial data, or source code into an AI assistant, it redacts or blocks the sensitive content before submission and tells the person in plain language what was flagged and why. Coverage spans the major AI assistants and keeps growing. Because content submitted to a public AI tool cannot be recalled and becomes subject to the provider's terms, stopping it first is what matters.
For the evidence file, administrators see a dashboard of flagged-event metadata (which tool, what type of data, which policy, when) without ever seeing prompt content. Those records can show an underwriter that the control exists and operates, as evidence of reasonable safeguards rather than a guarantee of any underwriting or claims outcome. Learn more on our security awareness page.