Axa XL report gives tips on managing AI risk
Axa XL and S-RM have called on businesses to treat artificial intelligence risks as an enterprise resilience issue, warning that AI adoption is outpacing governance, security and incident-response capabilities.
The property and casualty insurer and global intelligence and cybersecurity consultancy have published Building Resilient AI: Managing AI risk through governance, security and resilience, which outlines five priorities for organisations integrating AI into critical business processes.
The report comes as AI adoption expands across business functions, with 88% of organisations reporting AI use in at least one business function, according to McKinsey & Company’s 2026 State of AI survey.
The Axa XL and S-RM report identifies clear accountability, data protection, lifecycle risk management, third-party oversight and insurance preparedness as five priorities for business leaders.
“From an insurance perspective, organisations that can show strong data governance, robust access controls and clear oversight of AI systems are far better positioned to reduce exposure”, it says.
It calls for organisations to establish responsibility for AI across formal deployments, embedded software features and unauthorised or “shadow AI” use. Businesses should also strengthen identity and access controls as AI systems become more autonomous.
The report highlights risks including data leakage, model manipulation, prompt injection, unreliable outputs and overly autonomous AI agents. It recommends managing risk from data collection and model development through to deployment, monitoring and incident response.
“AI risk rarely emerges in isolation,” head of cyber risk consulting services at Axa XL Rebiah Bardot-Girard said. She said organisations need to understand where AI is being used, what data it can access and where it can take or influence action.
According to the World Economic Forum, 64% of organisations now assess the security of AI tools before deployment, up from 37% a year earlier. However, Axa XL and S-RM say pre-deployment assessment alone is insufficient, with ongoing monitoring required as AI systems evolve.
The report identifies five foundations for secure AI adoption: strong data governance, secure models and applications, ecosystem resilience, robust access controls and continuous monitoring.
The report is available here.