There is an unusual dynamic playing out in enterprise security right now. The organizations with the clearest, most current view of corporate cyber risk are not the security teams. They are not the boards. They are the underwriters at cyber insurance firms — the people pricing risk for a living, whose financial exposure depends directly on how accurately they assess it.

And they are increasingly ahead of the security programs they are insuring.

Pentera's AI Security and Exposure Benchmark 2026 documents this gap with precision. 99.7% of enterprise CISOs report that securing their AI ecosystem is already driving increased cybersecurity spend in 2026. Yet only 1% have a dedicated AI security budget line — the vast majority fund it through existing broader security budgets. The investment is happening. The governance around it has not caught up.

Meanwhile, the insurers are moving faster. 44% of cyber insurance providers already require proof of AI ecosystem pentesting from the enterprises they cover. Nearly all enterprises — 99.7% — report that their insurer has either recommended or directly influenced the adoption of cybersecurity tools. 48% have integrated one or more security solutions specifically due to insurer requirements.

How Insurers Got Ahead

The mechanism is straightforward. Cyber insurers price risk based on evidence of security posture — and they have gotten progressively more sophisticated about what evidence they accept. Early cyber policies were priced largely on self-reported questionnaires. Insurers learned, expensively, that self-reported security posture and actual security posture are frequently different things.

In response, underwriting requirements evolved. MFA became a standard requirement. Then endpoint detection. Then regular penetration testing. Each wave of requirements reflected what the claims data showed was actually driving breach costs — and insurers moved their requirements to match the threat landscape faster than most internal security governance processes could.

IBM's 2025 Cost of a Data Breach report put the average breach cost for US companies at a record $10.22 million — a 9% jump from the prior year. When breach costs rise at that rate, insurers have a direct financial incentive to get the risk assessment right. They cannot afford to price on assumption. They require evidence.

44%
of cyber insurers already require proof of AI ecosystem pentesting
99.7%
of enterprises report their insurer has influenced their security tool adoption
$10.22M
average US breach cost in 2025 — a 9% increase year over year

The AI Pentesting Requirement Is Already Here

The 44% figure on AI ecosystem pentesting requirements deserves to be read carefully. This is not a future requirement being discussed in policy documents. It is a current requirement already being enforced by nearly half of cyber insurance providers surveyed.

At the same time, Pentera's data shows that 52% of enterprises are already incorporating AI-related scenarios into their adversarial testing programs — slightly exceeding the 44% insurer requirement rate. This suggests that leading security teams are moving ahead of the formal requirements, driven by genuine risk awareness rather than compliance obligation alone.

But the gap between the 52% doing some AI security testing and the 1% who are very confident in their AI security posture is significant. Incorporating AI scenarios into an existing annual pentest is not the same as having a validated, continuously tested AI security program. The insurer requirement is a floor, not a ceiling — and many organizations are meeting the floor without being close to genuinely prepared.

The coverage gap risk: Cyber insurance policies increasingly contain exclusions and coverage limitations tied to security control requirements. An organization that cannot demonstrate adequate security validation — including AI ecosystem coverage — at the time of a claim may find their coverage disputed. The insurer's requirement is not just a procurement hurdle. It is a coverage condition.

What Insurers Are Actually Asking For

The nature of insurer security requirements has shifted from binary to evidential. It is no longer sufficient to say "we have a penetration testing program." Underwriters increasingly want to see the outputs — findings, remediation evidence, retest confirmation. They want to understand the scope of testing: what was covered, at what cadence, against what adversary model.

For AI security specifically, the emerging questions mirror what mature security validation programs already ask: What AI systems are in scope? What data can those systems access? Have you tested for prompt injection and model manipulation? Are your AI identities and permissions validated against least-privilege principles? Can you demonstrate that an attacker who compromised your AI infrastructure could not pivot to your broader environment?

Most enterprises cannot currently answer these questions with evidence. They can answer them with policy documents and architectural diagrams. The insurers who are moving toward evidence-based underwriting are creating a forcing function for security programs to close that gap.

The Strategic Reframe

There is a way to read the insurer influence data as a threat — an external party adding compliance requirements on top of an already stretched security program. That reading misses the strategic opportunity.

Insurers are, in effect, doing the risk quantification work that most internal security programs struggle to complete. When an insurer says "we require proof of AI ecosystem pentesting," they are translating a threat intelligence judgment — AI systems are a material attack surface that is not yet consistently validated — into an actionable requirement. That is useful signal, not just compliance overhead.

The organizations that will be best positioned as AI security requirements mature are the ones building continuous validation programs now — not because their insurer is requiring it yet, but because the threat environment already justifies it. The insurer requirement is a lagging indicator of what the threat data already shows. The breach data, the attack surface data, and the confidence data all point in the same direction: AI security validation is not optional for organizations operating AI at scale, and the gap between having AI systems and knowing whether those systems are secure is a material business risk regardless of what any insurer requires.

A practical check: Pull your current cyber insurance policy and underwriting questionnaire. Find every question that relates to penetration testing, adversarial validation, or security control verification. Now ask: can you answer those questions with documented evidence, or with assumptions? The difference between those two answers is your coverage risk.

Your cyber insurer is pricing your risk based on what they know about how breaches actually happen. They are requiring AI ecosystem validation because the claims data tells them it matters. The question is not whether to take that signal seriously. It is whether to act on it before a claim — or after.

Source: Pentera AI Security & Exposure Benchmark 2026. Survey of 300 US CISOs and senior security executives, conducted December 2025 by Global Surveyz Research. IBM Cost of a Data Breach Report 2025.

See what continuous testing finds in your environment.

Tadpole deploys autonomous agents that simulate real adversaries — 24/7, across your entire attack surface.

Request early access →