Artificial intelligence is becoming part of everyday banking operations, whether through tools employees use directly or AI capabilities introduced by technology vendors.
That creates an increasingly important question for community and regional banks:
Does your cyber insurance conversation reflect how AI is actually being used across your bank?
The Independent Community Bankers of America brought that question directly into focus on September 22, 2026, when it released Safeguarding Resilience: Navigating Cyber Insurance in the Age of Artificial Intelligence.
The resource was developed by members of ICBA's Cyber and Data Security Subcommittee to help community banks consider cyber insurance in the context of artificial intelligence. It also includes recommendations and a checklist of questions bankers can raise with insurers to identify potential coverage gaps before an incident occurs. Read ICBA's Safeguarding Resilience resource
For bank leadership, the takeaway should not be that AI automatically creates an insurance problem.
The better takeaway is this:
As AI changes your bank's technology risk, your understanding of that risk needs to change with it.
And that is where AI governance, cybersecurity, vendor risk management, and cyber insurance begin to overlap.
How Does AI Governance Affect Cyber Insurance for Community Banks?
AI governance helps a bank understand and control how artificial intelligence is being used across the organization.
That includes questions such as:
- Which AI applications are employees using?
- Which tools have been formally approved?
- What information can those tools access?
- What information are employees entering into AI systems?
- Which vendors have introduced AI capabilities?
- What can AI agents access or do?
- What technical controls support the bank's AI policies?
- What activity is being logged and monitored?
- How would the bank respond to an AI-related security or data incident?
Those are primarily governance and cybersecurity questions.
But they can also matter when the bank evaluates whether its insurance program reflects its actual technology environment.
A cyber insurance policy is not a replacement for AI governance. And AI governance does not determine whether a particular insurance claim will be covered.
Instead, the connection is about understanding the exposure well enough to have an informed conversation with the bank's insurer, broker, leadership team, and risk professionals.
AI Has Created More Than One Kind of Bank Risk
It is easy to think of bank AI risk as employees using public tools such as ChatGPT, Claude, Gemini, or other generative AI platforms.
That is only part of the picture.
AI can enter the banking environment through several paths.
An employee may use a public AI tool.
The bank may license an enterprise AI platform.
Microsoft 365 or another existing technology platform may introduce new AI functionality.
A bank vendor may add an AI assistant or automated workflow.
A third-party application may connect to an outside AI model or additional subprocessors.
An AI agent may eventually have permission to interact with business systems rather than simply answer questions.
That means AI governance cannot focus only on the tools the bank intentionally purchased.
AvTek recently explored this distinction in our guide to AI governance for community banks. A defensible AI governance program should give a bank visibility into how AI is actually being used, not merely what the written policy says should be happening.
That visibility becomes valuable when cyber insurance enters the conversation.
Before a bank can evaluate whether its insurance program reflects its AI exposure, leadership first needs a reliable picture of that exposure.
Why AI Inventory Matters Before the Insurance Conversation
One of the first practical steps in AI governance is knowing what exists.
The Conference of State Bank Supervisors reinforced that point with its September 2026 Artificial Intelligence Supervisory Framework.
The framework is a discretionary tool for state examiners and does not create a new regulatory requirement. However, CSBS says financial institutions can use it to assess their own AI programs, establish sound AI governance and risk management, and prepare for examinations.
Its Core Examiner Guide includes procedures involving AI inventories and use cases, governance and oversight, and generative and emerging AI use. Review the CSBS Artificial Intelligence Supervisory Framework
That same inventory can help bank leadership have a better cyber insurance discussion.
Consider the difference between telling an insurer:
We allow some employees to use AI.
and being able to explain:
- Which AI applications are approved
- Which departments use them
- What business purposes they support
- What categories of information they can access
- What controls restrict inappropriate data use
- How activity is monitored
- How AI-enabled vendors are assessed
The second conversation starts from evidence instead of assumptions.
Vendor-Embedded AI Belongs in the Conversation Too
Some of the most important AI activity at a bank may not come from an application with "AI" in the product name.
It may come from a vendor the bank has used for years.
A vendor can introduce an AI assistant, connect to an outside model, add a new subprocessor, change what information its system accesses, or automate a business process that previously required more direct human involvement.
None of those changes automatically means the vendor has become unsafe.
But the bank's risk profile may change when the underlying technology changes.
Federal Reserve guidance on third-party risk management notes that third-party relationships can provide banks with valuable technology and services while also introducing or increasing operational, compliance, financial, and strategic risks. The guidance emphasizes identifying, assessing, monitoring, and controlling those risks throughout the relationship. Read the Federal Reserve's Third-Party Risk Management Guide for Community Banks
That is why AI vendor risk should not live in a completely separate process.
AvTek's guide to AI vendor risk management for community banks looks specifically at why changes in vendor AI capabilities may need attention between formal review cycles.
For cyber insurance discussions, bank leaders should consider whether significant AI dependencies inside important vendors are understood alongside the bank's direct AI use.
An AI Policy Does Not Tell You Whether the Policy Is Working
Many banks have already started creating acceptable-use policies for artificial intelligence.
That is an important foundation.
But there is a difference between:
having an AI policy
and
having evidence that the policy is being followed.
Suppose the policy says certain customer, financial, confidential, or internal bank information should not be entered into an unapproved large language model.
Can the bank tell whether that is actually happening?
Can it identify the application involved?
Can it identify the user?
Can it apply a warning or restriction when defined activity violates policy?
Can it document that activity afterward?
These are the types of questions that move AI governance from policy into operational control.
They also create a clearer picture of the bank's risk environment.
AI Governance Should Connect Policy to Technical Controls
Traditional access controls answer an important question:
Is this person authorized to access this information?
AI introduces another question:
Is this person authorized to give this information to this AI system?
Those questions are not necessarily identical.
A bank employee may legitimately need access to sensitive information to perform a job function. That does not automatically mean every AI platform the employee can open should receive that information.
Effective AI governance therefore requires coordination among policy, data governance, security controls, employee behavior, and monitoring.
NIST's voluntary AI Risk Management Framework approaches AI risk as an ongoing process rather than a one-time technology review. Its core functions are Govern, Map, Measure, and Manage, with governance designed to operate across the AI lifecycle. Explore the NIST AI Risk Management Framework
For community banks, that lifecycle approach fits naturally alongside existing cybersecurity and risk-management processes.
AI Agents Add Another Layer to the Risk Conversation
Generative AI introduced a relatively familiar interaction:
A person asks AI to create, summarize, analyze, or explain something.
AI agents can introduce a different model.
An agent may be able to interact with other applications, retrieve information, execute multiple steps, or initiate activity within a workflow.
That changes the governance question from:
What can employees tell AI?
to:
What authority are we giving AI?
Bank leadership should understand:
- Which AI agents are operating in the environment
- What data they can access
- Which systems they can interact with
- What actions they are permitted to perform
- Where human approval is required
- How activity is logged
- How the bank can restrict or stop unwanted activity
These questions belong in the broader technology-risk conversation because the risk changes as AI moves from assisting a user to accessing systems and potentially acting within them.
What Should Banks Ask Their Cyber Insurer About AI?
ICBA's September 2026 resource provides community bankers with a dedicated checklist for discussing AI and cyber insurance with their insurers. Banks should consult that resource directly rather than assume every insurer, policy, exclusion, or endorsement treats AI-related incidents the same way. View ICBA's cyber insurance and AI checklist
At a broader level, leadership should make sure the insurance conversation reflects the bank's actual technology environment.
Topics worth discussing with the bank's insurance professional include:
- How the policy addresses incidents involving AI-enabled systems
- Whether the policy language distinguishes between the bank's AI and third-party AI
- How incidents involving vendors or subprocessors are handled
- Whether relevant exclusions or definitions affect AI-related events
- What security and governance information the insurer expects from the bank
- What notification obligations apply following an incident
- How the policy interacts with business interruption, incident response, privacy, and third-party events
These are questions for the bank's qualified insurance professionals to answer based on the actual policy.
The IT and cybersecurity team's role is different.
Its job is to help leadership understand the technology environment well enough that those questions can be asked accurately.
What Does AI Governance Have to Do With Cyber Insurability?
At its core, both conversations depend on understanding risk.
A bank that cannot identify its AI use may have difficulty explaining that risk accurately.
A bank that cannot see vendor-embedded AI may be working from an incomplete technology inventory.
A bank that has an AI policy but cannot see whether employees are following it may have a policy-control gap.
And a bank that cannot explain what its AI agents can access or do may not yet have a complete picture of its AI environment.
That does not automatically mean the bank is uninsurable.
It means there are important questions the bank should answer before assuming its cybersecurity controls, governance program, and insurance program are all working from the same understanding of risk.
AI Governance, Cybersecurity, Compliance, and Insurance Should Not Live in Separate Silos
Community banks already manage overlapping responsibilities involving cybersecurity, regulatory expectations, vendors, business continuity, incident response, insurance, and operational risk.
AI touches many of those areas simultaneously.
Creating a completely separate AI bureaucracy can make governance harder rather than easier.
A better approach is to connect AI governance to the bank's existing risk-management processes.
That may include:
AI governance: What AI exists, how it is used, and what controls apply?
Cybersecurity: What information and systems can AI access?
Vendor risk: Which third parties and subprocessors introduce AI dependencies?
Compliance: What governance, documentation, and evidence can the bank produce?
Incident response: What happens if an AI-related security or data event occurs?
Business continuity: What happens if an important AI-enabled service becomes unavailable?
Cyber insurance: Does the bank understand how its actual technology environment relates to the coverage it purchased?
AvTek's compliance and cybersecurity support for regulated organizations is designed to help financial institutions connect risk, documentation, controls, and ongoing governance rather than treating them as isolated annual exercises.
For institutions that need additional security leadership, AvTek also provides vCISO services focused on cybersecurity risk management, security strategy, policies and documentation, audit readiness, vendor-risk discussions, and executive and board guidance.
Frequently Asked Questions About AI Governance and Cyber Insurance for Banks
Does cyber insurance cover AI-related incidents?
There is no single answer that applies to every bank or every cyber insurance policy.
Coverage depends on the specific policy language, definitions, exclusions, endorsements, circumstances of the incident, and other factors. Community banks should discuss AI-related scenarios directly with their insurer, broker, and appropriate advisors rather than assume an incident is covered or excluded.
ICBA's September 2026 resource was created specifically to help community bankers ask those questions.
Can AI use affect a community bank's cyber insurance?
AI can change a bank's technology environment, data flows, vendor dependencies, and cyber-risk profile.
Whether those changes affect a particular bank's insurance terms or coverage is a question for its insurer or insurance professional. From a technology-risk perspective, the bank should be able to accurately describe how AI is being used and what controls surround it.
Why does an AI inventory matter for cyber insurance?
An AI inventory gives bank leadership a clearer picture of which AI applications, agents, use cases, users, vendors, and data access exist within the environment.
That information can support internal risk management and help the bank provide more accurate information during conversations with insurance professionals.
Should vendor AI be included in a bank's AI governance program?
Banks should consider AI embedded within important third-party services as part of their broader AI and vendor-risk picture.
A vendor's use of AI may change data access, technology dependencies, subprocessors, permissions, workflows, or operational risk even when the underlying vendor relationship remains in place.
Is an AI acceptable-use policy enough?
An acceptable-use policy is an important component of AI governance, but it does not by itself provide visibility into actual AI use or enforce how information is handled.
Banks should also consider discovery, inventory, data governance, technical controls, monitoring, vendor oversight, documentation, and ongoing review.
What should bank leadership do first?
Start with visibility.
Before the bank can make informed decisions about AI governance, vendor risk, cybersecurity controls, or insurance questions, leadership needs to understand what AI is actually being used across the environment.
That means looking beyond the approved software list and identifying actual AI applications, agents, users, and data activity.
Know Your AI Risk Before Someone Else Asks You to Explain It
The conversation around AI in banking is changing quickly.
CSBS is giving state examiners a framework for understanding AI use and governance. ICBA is helping community banks bring AI into their cyber insurance discussions. NIST continues to frame AI risk management as an ongoing lifecycle. And the technology itself is becoming more deeply embedded in the applications and vendors banks already depend on.
The common denominator is visibility.
You cannot effectively govern AI risk you cannot see. And you cannot have a complete cyber insurance conversation if you do not understand the technology risk you are carrying.
AvTek Solutions helps community and regional banks move from assumptions about AI use to a clearer picture of what is actually happening.
Our two-week AI governance assessment is designed to identify AI applications and agents being used across managed endpoints, provide visibility into usage and data activity, and help the bank understand where its current policies and controls may need attention.
From there, AvTek can help apply AI policies that allow, warn, or block defined activity and provide reporting that supports ongoing governance and evidence.
If your bank is reviewing its cyber insurance, preparing for an examination, or trying to understand how much AI has already entered the environment, this is the time to get a clear baseline.
Don't wait for the insurance application, examiner, auditor, or incident to be the first time someone asks what AI is doing inside your bank.

