08/14/2026
Where does your organization stand? A 90-day roadmap by maturity.
Not every organization is starting from the same place on AI governance. Identify your current stage below, then focus your next 90 days on the actions listed for that tier.
Stage 1: Early-Stage. AI is in use, but governance is absent or informal. You're here if employees are using AI tools without centralized tracking, no one owns AI risk formally, and there's no written policy on acceptable use.
Your priorities: build an AI inventory (a spreadsheet is a fine starting point), name one risk owner, draft an acceptable use policy, and fold AI-specific scenarios into your incident response plan.
Stage 2: Developing. Governance exists, but it operates in silos. You're here if you have an inventory and a named owner, but security and governance aren't aligned and you haven't adopted a recognized framework.
Stage 3: Advanced. Governance is established. The goal now is continuous and defensible. You're here if security and governance are aligned and a framework is in place, and the challenge is keeping the program audit-ready.
Your priorities: define what triggers a formal reassessment, build executive-level reporting so leadership has a real dashboard view, and run the 48-hour test. Could your organization produce a complete AI risk artifact within 48 hours if a regulator or insurer asked for one? If not, that's the gap to close.
Our team wrote an article with more details on how to update your cyber coverage with the rapidly changing AI landscape, no matter what stage your company lands in.
Wherever you land on this, it's worth a conversation with your broker about whether your coverage reflects where you actually are.
Which stage is closest to where your organization sits today?