AI security riders are rewriting 'reasonable security.'
Cyber insurers are starting to require AI-specific controls before they pay a claim. It reaches the company buying coverage and the vendor selling the safeguards.

A hard floor for AI security already exists, and it came from insurers. Carriers have begun bolting AI riders onto cyber policies. Show documented red-teaming, model-level risk assessments and specific safeguards, or the claim does not get paid.
This is the kind of thing that actually moves a market. An insurance renewal comes due in ninety days and settles a question a regulation would argue about for years.
The underwriter is in the room now.
Once coverage depends on a control, the CFO and the general counsel start asking for that control by name. Security spend that used to be discretionary becomes the cost of staying insured.
If you carry the policy.
Read your rider before your renewal, not after a breach. The controls it names are the ones you will have to prove you run, so line up the evidence early and pick vendors whose output an underwriter will actually accept.
If you sell the safeguards.
Produce the evidence the rider asks for, in a form the carrier accepts. A line like “we improve your posture” does nothing. A line like “we generate the red-team documentation your carrier now requires at renewal” reads as a purchase order. Use the rider's own vocabulary, and make the output legible to an auditor.
Coverage now depends on evidence, and the renewal date is the deadline neither side can move.
Reasonable security will keep absorbing AI controls until they are simply assumed. The buyer who prepares for that and the vendor who maps to it both end up on the right side of the renewal.