Carriers including Verisk, W.R. Berkley, AIG, Great American, and Coalition have added AI-governance questions to renewal applications. A written acceptable-use policy no longer satisfies them — they want evidence: what AI tools have touched your data, and who approved it.
On what underwriters now require: organisations must document "the data that every AI tool, SaaS product with embedded AI and internal model can access and who approved it." A written policy alone no longer clears underwriting — carriers want "training records, access logs and exception documentation."
The same piece puts the share of GenAI users accessing tools through personal accounts at 47% — a separate data point, from a separate source, arrived at a different way than the 71% figure on our homepage, pointing at the same gap from the underwriting side instead of the security side.
Unlike a due-diligence scan of a company you don't yet own, this is your own fleet. No NDA, no target-company cooperation, no negotiation to run it.
The scanner runs locally on machines you already control. No one has to grant you anything.
Your renewal date is fixed. This isn't a someday project — it's due when the policy is.
An inventory of which AI tools currently have local data on your machines, and what that vendor's documentation says about access and retention.
Run our collection script across your fleet, preview and remove anything you choose, then send it to us. You get back: every AI service currently present, what that vendor's own documentation states about training and retention at that tier, and who has access to what — formatted to answer the questions your renewal application is actually asking.
More than 5 laptops? That's scoped individually.