Home › Blog › Half the People Using AI at Work Had No Training. The Exclusion Is Already Written.
AI Governance

Half the People Using AI at Work Had No Training. The Exclusion Is Already Written.

By Leon Kopelev · Sep 28, 2026 · 6 min read
Half the People Using AI at Work Had No Training. The Exclusion Is Already Written.

Two documents landed within a few months of each other this year. One is an insurance endorsement most people will never read. The other is a survey of 25,000 workers. Put them side by side and they describe the same problem, which happens to be a problem no piece of software fixes.

The exclusion is real, and narrower than the rumor

ISO, the Verisk business that writes the standard forms most US commercial policies are built from, released three generative AI exclusion endorsements carrying a January 2026 edition date. CG 40 47 removes generative AI from both halves of a commercial general liability policy, the bodily injury and property damage cover and the personal and advertising injury cover. CG 40 48 is the lighter version and touches only the second. CG 35 08 applies the same idea to products and completed operations.

All three run on one definition of the thing being excluded: "a machine-based learning system or model that is trained on data with the ability to create content or responses, including but not limited to text, images, audio, video or code."

Two details get lost in the retelling, and both matter if you are the one answering questions about it. These are general liability forms. They are not cyber exclusions and they are not errors and omissions exclusions, and a broker will notice immediately if you call them that. They are also optional. Nothing changed automatically in January. A carrier now has the option to attach one, and attaching one takes away cover that was never specifically excluded before.

Adoption so far is partial. John Farley, who runs Arthur J. Gallagher's cyber practice, described it in April as "a few carriers that are starting to adopt those exclusions." W.R. Berkley, Chubb, Travelers, Berkshire Hathaway and Cincinnati Financial have all been reported as using some form of AI exclusion. This is a door opening, not a wall arriving.

The question sitting underneath the form

The more interesting shift is in what underwriters ask before they decide. Jeff Kulikowski of Westfield Specialty described the change to Business Insurance:

"It used to be, 'Do you use AI and how do you use it?' Now it's, 'What models are you currently utilizing? How did the business decisions get made to utilize these models? What checks and balances are in place to make sure the AI models produce accurate and verifiable results?'"

Read that last clause again. Checks and balances that make sure the output is accurate and verifiable. That is not a question about your model inventory, and you cannot answer it with a vendor list. It asks what happens in the gap between a model producing something and a human acting on it. Whatever sits in that gap is a person, and the question is whether that person knows to look.

Deloitte went and measured the person

In September, Deloitte UK published the first edition of its GenAI Workforce Survey: 25,000 workers, fieldwork run by Ipsos through May and June. Three findings from it belong in any conversation about that gap.

Of the people using generative AI for work, 31% say they use it without their employer's knowledge. Half have had no training at all. And UK workers are spending an estimated £958 million a year of their own money on AI tools for work, which Deloitte rounds up in its own headline to nearly a billion pounds.

Paul Lee, Deloitte UK's head of industry insight, drew the causal line himself: "The story here isn't that workers are using GenAI, it's that they are using it despite limited training, patchy guidance and, in some cases, without their employer's knowledge."

The denominators deserve care, because they are what makes the number meaningful. These are shares of people who already use generative AI, not shares of the whole workforce, and the sample is British. Your own percentages will differ. The mechanism will not.

Unapproved AI use is a training gap in a policy costume

The reflex when a third of your AI users turn out to be invisible is to treat it as a discipline problem. Write the acceptable use policy. Block the domains. Send the memo with the word "reminder" in the subject line.

Deloitte had the data and read it the other way, and I think they are right. People paying out of their own pocket to use a tool at work are not rebelling. They are filling a vacuum. The sanctioned option is missing, or it is bad, or nobody showed them how to use it properly. Blocking the tool does not remove the behavior. It relocates the behavior somewhere you cannot see, which is the version that eventually produces the claim your carrier is now thinking about excluding.

What I cannot tell you, and will not pretend

I went looking for evidence that carriers are asking what a workforce can actually demonstrate about AI. Specifically that: not governance, not policies, not bias testing, but trained human judgment. It is not there. I could not find a renewal questionnaire, a broker advisory or an on-record quote that asks for it. The broker material about AI training turns out, on a close read, to be about brokers training their own staff.

So treat "your underwriter will start asking about workforce training" as a forecast. It is mine, and I have an obvious interest in it being right. What is documented today is narrower and still useful: they ask which models you run, how you decided to run them, and what checks and balances make the output verifiable. We sell the discipline of not accepting confident claims without checking them, so it would be a poor look to publish one.

What a strong answer to that question looks like

Three things, in order. Name the moment in a workflow where a human is required to verify AI output before it goes anywhere. Show that the specific person standing in that moment is capable of it. Then put a date and a name on the showing.

Most AI training programs handle the first and skip the second entirely. A completion record proves a video was assigned. It cannot tell you, or an underwriter, or the lawyer reading your file two years from now, whether the underwriter on your own team would catch a fabricated policy exclusion an AI tool handed them. That is a different measurement, and it requires watching someone reason rather than watching them click.

It is the same evidence gap that EU AI Act Article 4 has been quietly asking about since February 2025, arriving through a different door. The regulator asks a procedural question. The underwriter asks an evidentiary one. One artifact answers both, provided it records what a person did rather than what they attended.

That artifact is what our Defensible AI course produces: a scored Coaching Session Report after every lesson, naming which sub-skill the person demonstrated, which one fell short, and the evidence for both.

So here is the question worth taking into your next renewal conversation. When you are asked what checks and balances make your AI output verifiable, can you point at one person and show what they actually caught?

Leon Kopelev Founder of Cogito Coach. Builds the Defensible AI course used by L&D and risk teams in regulated industries to turn AI consumers into AI evaluators.

The checks and balances question has an evidence answer.

Cogito's Defensible AI course produces a scored Coaching Session Report after every session, per person, anchored to the cases your risk team already cites. A record of judgment with a name and a date on it, rather than a completion log.

Request a briefing

One practical thinking tip every week.

Takes 2 minutes to read. No spam, no fluff.

← Back to Blog