top of page

AXA XL AI Governance Warning: Adoption Is Outrunning Oversight

1 day ago
13 min read

AXA XL says AI adoption has crossed a dangerous threshold: systems are entering critical workflows while governance, security, and incident response remain several steps behind.

The AXA XL AI governance warning arrived on September 23 through a joint report with intelligence and cybersecurity consultancy S-RM. It argues that organizations must stop treating AI risk as a narrow compliance project. AI now touches sensitive information, software access, business decisions, and relationships with outside vendors.

That creates a conflict between deployment speed and operational control. Companies want agents and generative AI inside everyday workflows, yet many cannot reliably identify every system, owner, data source, or downstream dependency.

The warning carries added weight because AXA XL sees the issue through insurance and risk consulting. Insurers must understand how failures happen, how severe they can become, and whether different losses are connected. AI complicates all three questions.

The central problem is therefore larger than whether a model occasionally produces an incorrect answer. Businesses are giving AI systems more access and authority before they have established continuous oversight around that access.

AXA XL AI Governance Warning Moves Risk Beyond Compliance

The report’s most important shift is its treatment of AI failure as an enterprise resilience problem, not simply a model-quality problem.

AXA XL is the property, casualty, and specialty risk division of AXA. S-RM advises organizations on cybersecurity, intelligence, and corporate risk. Their joint resilient AI report connects AI deployment to cyber incidents, fraud, liability, business interruption, and failures involving third parties.

The timing reflects how quickly AI has moved into normal operations. AXA XL cites research saying 88% of organizations use AI in at least one business function. Adoption now extends beyond controlled experiments and isolated chatbots.

Employees use generative systems to summarize records, draft communications, analyze documents, and support decisions. Software providers are also embedding AI into products that customers already use. An organization can therefore acquire a new AI dependency without approving a separate AI project.

Agentic systems raise the stakes further. An AI agent is software that can pursue a goal through multiple steps, sometimes using external tools or modifying other systems. Its risk depends on what it can read, what it can change, and whether a person reviews its actions.

AXA XL identifies five priorities for organizations facing this transition. Leaders need clear accountability for sanctioned systems, embedded AI features, and shadow AI. They must protect sensitive data while strengthening identity and access controls.

Organizations also need lifecycle governance covering data collection, development, deployment, monitoring, and incident response. Vendor due diligence must account for AI dependencies inside external services. Finally, companies should prepare for losses that cross conventional insurance categories.

That last point matters. A single event might begin with a manipulated model, expose confidential information, interrupt operations, and trigger a liability claim. The same incident can involve cybersecurity, privacy, professional services, and management decisions.

Jonathan Salter, AXA XL’s head of risk consulting, summarized the conflict directly. AI is moving into systems that organizations depend upon, he said, while governance does not always keep pace.

His framing shifts the question from “Is this model accurate?” to “What happens to the business when this system fails?” That question demands owners, escalation paths, tested controls, and recovery plans.

The report also rejects a common shortcut. A security review before launch does not provide ongoing control after deployment. Models change, vendors update their services, employees discover new uses, and access permissions expand.

AXA XL says 64% of organizations now assess AI tool security before deployment, compared with 37% one year earlier. That improvement still addresses only the entry point. Risk continues after a tool passes its first review.

This is the first major implication of the AXA XL AI governance warning: approval cannot serve as a permanent certificate of safety. Oversight must follow the system through its working life.

AI Adoption Creates an Inventory and Accountability Crisis

A business cannot govern AI systems that it cannot find, classify, or assign to an accountable owner.

The inventory problem begins with fragmentation. Some AI applications arrive through formal technology programs. Others appear as features inside customer-service platforms, productivity suites, security products, or developer tools.

Employees may also use consumer services without authorization. This practice, often called shadow AI, can expose business information outside approved controls. The risk is not limited to deliberate policy violations.

A worker may reasonably believe that an ordinary software feature is covered by the company’s existing approval. Yet the feature might send data to a different model provider, retain prompts under different terms, or generate content through an external service.

An effective inventory therefore needs more than a list of model names. It must connect each use case to a business owner, technical owner, purpose, data sources, permissions, vendor, affected users, and recovery process.

It should also record whether the system only recommends actions or can execute them. A summarization tool with read-only access presents a different exposure from an agent that can send messages, approve transactions, or change production records.

Rebiah Bardot-Girard, AXA XL’s head of cyber risk consulting services, argues that organizations need to know where AI operates, what information it can access, and where it can influence action. That inventory becomes the starting point for resilience.

The recommendation closely matches the AI risk framework maintained by the US National Institute of Standards and Technology. NIST describes governance as a continuous function across an AI system’s lifespan.

Its framework calls for mechanisms that inventory AI systems according to organizational risk priorities. It also asks organizations to document responsibilities, monitor controls, assess third-party components, and plan for safe decommissioning.

Those activities sound administrative, but they determine whether a company can respond during an incident. A security team cannot revoke access quickly if it does not know which credentials an agent uses. Legal teams cannot evaluate exposure without knowing which records entered the system.

Business owners also need enough documentation to distinguish intentional behavior from failure. If an agent sends an unauthorized communication, investigators must reconstruct the inputs, model version, instructions, tool calls, approvals, and resulting actions.

That evidence may be scattered across vendor dashboards, local applications, identity systems, and employee messages. Without a defined record, the company may struggle to determine what happened or whether the same weakness remains elsewhere.

Maintaining a searchable knowledge base can help teams organize policies and technical records. However, documentation only helps when owners keep it connected to live systems.

Accountability is the second half of the problem. AI frequently crosses organizational boundaries, including security, privacy, legal, procurement, product, and operations. Each team may own one control while nobody owns the complete business outcome.

A model developer might manage testing but not the information supplied by employees. Procurement might review contract terms but not operational permissions. Security might monitor technical events without understanding the consequences of a flawed business decision.

Clear accountability does not mean assigning every issue to a central AI office. It means naming who accepts the risk, who maintains controls, who monitors behavior, and who can suspend the system.

That final authority matters. Teams need predetermined conditions for slowing, isolating, or disabling an AI workflow. Otherwise, commercial pressure can keep a questionable system running while departments debate ownership.

The AXA XL AI governance message is therefore not simply “write a policy.” It is “connect every deployed capability to authority, evidence, and a response path.”

The Real Tradeoff Is Access Versus Control

AI becomes more useful as it gains context and authority, but those same qualities increase the damage a compromised or unreliable system can cause.

A standalone chatbot can produce incorrect text. An integrated agent can retrieve private records, call internal tools, and act on the result. The second system may deliver more business value, but it also creates a wider path from error to loss.

AXA XL and S-RM identify data leakage, prompt injection, model manipulation, unreliable output, shadow AI, and excessive autonomy among the relevant threats.

Prompt injection occurs when malicious or untrusted content steers a model away from its intended instructions. The attack can appear inside a document, web page, email, or data source that the system processes.

The danger grows when a model can call tools. A manipulated response might no longer remain text on a screen. It could influence a database query, outbound message, workflow decision, or transfer of information.

Traditional access controls still matter in this environment. An AI system should not receive broad permissions merely because users find broader access convenient. Its identity should receive only the resources required for the approved use case.

Permissions also need boundaries around actions. Read access is not the same as write access. Drafting a response differs from sending it, while recommending a transaction differs from approving one.

Human oversight remains important, but the phrase can conceal weak controls. A nominal reviewer cannot provide meaningful supervision if hundreds of outputs arrive too quickly or without relevant context.

Organizations need to define which decisions require approval, what evidence the reviewer receives, and how the system behaves when nobody responds. They also need to measure whether reviewers routinely accept outputs without examination.

This tradeoff becomes sharper as companies connect agents to sensitive business processes. The system’s usefulness may depend on customer histories, technical documentation, financial records, contracts, or employee data.

That context can improve relevance. It can also expose valuable information through insecure integrations, excessive retention, compromised accounts, or careless prompts.

AXA XL’s five secure-design foundations address this issue through data governance, secure models and applications, resilient vendor ecosystems, access controls, and continuous monitoring. None provides complete protection by itself.

Data governance defines which information the system may use. Secure application design constrains inputs, outputs, and tool connections. Identity controls limit what the system can reach.

Monitoring should then detect unexpected access, unusual tool use, changes in output, and attempted policy violations. Incident plans must address both technical containment and business consequences.

The wider AXA organization illustrates how these controls can support deployment rather than prohibit it. AXA describes an AI governance program that includes an AI Risk Library, fairness tools, expert reviews, and group-wide guidance.

AXA has also been scaling shared AI infrastructure across its global operations. Insurance Business reported that its Global AI Hub was operating in five entities by September 2026, including work involving AXA XL.

That creates an instructive contrast. AXA is not warning businesses to avoid AI while remaining outside the technology. It is deploying AI while arguing that access, governance, and operational responsibility must advance together.

This does not prove that AXA’s own controls eliminate every risk. Its public descriptions cannot substitute for independent testing or evidence from real incidents. They do show that the debate is no longer between adoption and non-adoption.

The practical contest is between managed adoption and poorly observed adoption. The first treats access as a limited privilege tied to evidence. The second treats integration speed as success, then attempts to add controls later.

Insurance Exposes What Governance Frameworks Cannot Yet Measure

The insurance perspective reveals a difficult truth: organizations can describe AI controls more easily than insurers can quantify the resulting loss exposure.

Insurance depends on information about how often losses occur, how severe they become, and whether many policyholders can suffer at once. Generative AI offers little mature claims history for answering those questions.

One faulty system can also affect numerous businesses. Many organizations rely on the same foundation models, cloud providers, software services, or data pipelines. A shared weakness could produce correlated losses across many insured companies.

Those relationships complicate traditional risk pooling. An insurer may believe it has diversified exposure across industries while those customers depend on the same underlying AI provider.

The failure categories can also overlap. A hallucinated answer might create professional liability. Data exposure might trigger privacy and cyber claims. An automated decision might invite regulatory action or discrimination allegations.

An interruption affecting an AI-dependent workflow could produce operational losses. Fraud involving synthetic media might interact with crime coverage, identity controls, and internal authorization procedures.

That complexity explains why AXA XL asks companies to prepare for scenarios spanning cyber, fraud, liability, and business interruption. The organization must examine the complete chain of consequences, not only the first technical event.

A recent insurance market analysis from the Center for Strategic and International Studies describes similar obstacles. It argues that limited deployment data and information asymmetry constrain insurers’ ability to evaluate AI risk.

Information asymmetry means the customer knows more about its exposure than the insurer. A company knows which models it uses, what information they process, how prompts are managed, and whether human review actually works.

The insurer may receive only questionnaires or high-level control descriptions. It cannot easily observe day-to-day behavior inside every deployment.

That creates a strong reason for insurers to demand better evidence. An AI inventory, access logs, incident records, testing results, and vendor documentation can make risk more visible.

However, governance artifacts are not the same as governance performance. A complete policy does not show that employees follow it. A test result does not guarantee that a vendor update preserves previous behavior.

The skeptical reading of AXA XL’s recommendations begins here. The five priorities are sensible, but the report does not provide a universal measurement system for proving that a company has implemented them effectively.

Organizations differ sharply in their systems, regulatory duties, resources, and use cases. A control suitable for drafting marketing copy may be insufficient for healthcare, credit, employment, or critical infrastructure.

AI behavior can also vary with context. A system might pass a controlled test yet fail when users provide unfamiliar inputs or when connected tools return unexpected data.

NIST has emphasized testing, evaluation, verification, and validation across the AI lifecycle. Its 2026 work includes a draft framework for assessing real-world outcomes across models, multimodal systems, and agents.

That direction is important because static reviews cannot capture every operational condition. Organizations need repeatable evaluations tied to actual business consequences.

They must also decide which residual risks to accept, reduce, avoid, or transfer. Insurance can absorb part of a financial loss, but it cannot restore leaked information, reverse a harmful decision, or immediately repair damaged trust.

Coverage may also contain boundaries between cyber, professional liability, crime, and other policies. An AI incident that crosses those boundaries can create disputes about which policy responds.

Companies should therefore avoid treating insurance as a replacement for governance. Insurers, meanwhile, cannot assume that a governance framework automatically makes a risk measurable.

The stronger interpretation of the AXA XL AI risk position is conditional. Better governance creates better evidence, and better evidence can support more informed underwriting. Neither guarantees that every AI exposure becomes insurable.

Regulation Raises the Cost of Governance Drift

The gap between deployment and oversight becomes more expensive when AI systems cross jurisdictions, business functions, and regulated decisions.

AI rules do not arrive as one universal compliance standard. Organizations must account for privacy, cybersecurity, consumer protection, intellectual property, employment, sector regulation, and contractual obligations.

The European Union’s AI Act adds risk-based duties for systems within its scope. Other jurisdictions apply existing laws or develop different AI-specific rules. A multinational company may face several obligations around the same workflow.

That fragmentation creates operational pressure. A system approved for one market or purpose may require different documentation, testing, or human oversight elsewhere.

Vendor relationships make the problem harder. A customer may not build the model, control its training data, or determine when the provider changes it. Yet the customer still decides how the system affects people and business processes.

Contracts need to address security responsibilities, incident notification, data handling, audit rights, subcontractors, model changes, service continuity, and termination. Procurement teams also need enough technical context to evaluate those provisions.

A generic software review may miss AI-specific dependencies. The service could rely on several model providers, retrieval systems, data processors, and monitoring tools. Each component adds another point where behavior or exposure can change.

AXA XL’s recommendation for vendor due diligence therefore extends beyond checking whether a provider publishes responsible AI principles. Buyers need evidence connected to the actual service and use case.

They should know which party monitors model behavior, who retains logs, and how quickly the provider reports an incident. They should also understand what happens to customer data after the contract ends.

This does not mean every organization can inspect a vendor’s source code or training corpus. Many providers will not disclose that information. It means buyers must identify the resulting uncertainty and decide whether the use case can tolerate it.

An organization might accept limited transparency for low-risk drafting assistance. It should demand stronger evidence before relying on the same provider for consequential decisions or autonomous actions.

AXA’s 2025 future-risk findings showed why this governance gap already attracts attention. Experts ranked AI and big-data risk fourth globally.

Among respondents who selected AI as a leading risk, 43% of experts named threats to human interests or rights as their primary concern. Lack of transparency and inconsistent regulation followed.

Only 11% of those experts believed public authorities were well prepared for AI and big-data risks. Respondents prioritized stronger regulation and better risk-governance frameworks as public responses.

Those figures do not measure the quality of governance inside individual companies. They do show widespread concern that existing institutions have not matched the technology’s speed.

Governance drift occurs when the real system changes faster than its documented control environment. A new feature appears, a model version changes, users expand the workflow, or a vendor adds an integration.

The original review may remain on file while its assumptions become outdated. In that situation, formal compliance creates false confidence.

Continuous oversight must therefore include change management. Teams need triggers for renewed testing when models, data, tools, permissions, or intended uses change.

They also need feedback from incidents and near misses. An event that causes no loss can still reveal weak access controls, ambiguous ownership, or an unreliable escalation process.

The regulatory question is not simply whether a company has an AI policy. It is whether that policy still describes what its systems do.

Three Signals Will Show Whether Oversight Is Catching Up

The next stage of enterprise AI will be judged by operational evidence, not by the number of governance principles a company publishes.

The first signal is whether companies build reliable inventories that include embedded and unauthorized AI. This measure goes beyond counting approved models.

A credible inventory should connect systems to data, permissions, vendors, owners, and business consequences. It should also identify agents that can act, not merely generate content.

If organizations begin disclosing inventory coverage, audit results, or reductions in unknown AI use, AXA XL’s diagnosis will gain practical support. It would show that businesses recognize visibility as the foundation for control.

If most companies continue relying on self-reported tool lists and one-time approvals, the governance gap will remain. Shadow AI and embedded vendor features will keep expanding outside formal review.

The second signal is the adoption of continuous testing and incident exercises. Pre-deployment security assessments are increasing, but AXA XL argues that launch reviews are insufficient.

Organizations should test prompt injection, data leakage, excessive permissions, unreliable outputs, and vendor outages. Exercises should involve legal, security, operations, communications, and business owners.

The most useful tests will focus on consequences. Can the company detect unauthorized tool use? Can it isolate an agent’s credentials? Can it reconstruct a decision and notify affected parties?

A growing body of real incident data would strengthen both governance and insurance. It could help organizations compare controls while giving underwriters better information about frequency and severity.

A lack of shared incident evidence would weaken confidence. Firms might claim stronger oversight while repeating failures that remain invisible outside their own systems.

The third signal is whether insurers and regulators ask for comparable evidence. Watch for underwriting questions about AI inventories, access controls, human review, vendor dependencies, and monitoring.

Also watch how regulators translate broad principles into specific documentation and testing expectations. Clearer evidence requirements can reduce uncertainty for buyers, vendors, and insurers.

The wrong response would be a paperwork race. Companies can generate extensive policies without controlling live systems. Evidence should reflect actual permissions, behavior, monitoring, and response capacity.

A better response links governance to deployment decisions. Higher-risk systems should face stronger controls, more frequent testing, and clearer suspension rules. Lower-risk uses should receive proportionate treatment.

For developers and product teams, that means designing observability and review into the workflow before launch. Logging added after an incident may not reconstruct missing context.

Enterprise buyers should ask what a product can access, what it can change, and how its provider communicates updates. They should also identify who owns failures after integration.

Knowledge workers should understand that convenient AI features can create organizational exposure. Sensitive records, customer details, internal strategy, and proprietary documents require approved handling paths.

The AXA XL AI governance warning ultimately challenges a familiar deployment pattern: launch first, establish ownership later, and add monitoring after something goes wrong.

Businesses do not need to eliminate every AI risk before using the technology. They do need to know which risks they are accepting and who can act when assumptions fail.

The next one to three months should reveal whether companies respond with operational changes or additional policy language. Look for complete inventories, repeated lifecycle tests, and evidence-based underwriting questions.

Those signals will matter more than another wave of AI principles. Has your organization mapped every AI system that can reach sensitive data or influence a business action, and can it prove that map remains current?

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page