The Shift Report · Issue 11 · 23 August 2026
What your insurer and your customers are about to ask you about AI
Your broker, a customer’s supplier questionnaire and whoever handles your IT are all about to ask where AI is being used in your operation. Build the list before the question arrives with four days on the clock.
There is a licence check on every forklift driver, calibration dates on the test equipment, an inspection record for the racking. Every one of those exists because at some point an insurer, an auditor or a regulator stood in front of somebody and asked for it in writing.
Three people are going to ask you for a new one this year. All three will be asking about AI, and none of them will use the word governance.
Your broker will ask at renewal. A customer’s procurement team will put it in a supplier questionnaire, because their customer put it in theirs. And at some point whoever handles your IT, in the building or in another town, will ask which machines on your site can be reached from outside it.
Three different questions, three different reasons, and all three want the same thing. A list. Where AI is being used in your business, on what, and who looks at the output before anybody acts on it.
Nobody has asked for that one yet. So it does not exist, and the first time it is requested there will be 4 days to produce it.
The awkward part is that the answer is not held in one place. Your quality manager knows what is in the management system. Your commercial team knows what has been promised to customers. Neither of them knows the transport planner has been pasting delivery notes into a free chatbot since April, because he found it quicker than the search in the ERP and nobody ever told him not to.
So the question on the form is really a question about whether you know how your own operation runs. You will be answering it on a Thursday afternoon with a customer waiting.
Three things worth knowing
1. Your existing policy may exclude the thing you are about to be asked about.
IT Pro looked at the state of AI insurance on 19 August. Gartner’s Lauren Kornutick: “many of the existing policies companies have in place have AI exclusions.” Gartner expects insurers to mandate AI risk controls as a condition of coverage by 2030. Drexel’s Pragati Awasthi sets out what underwriters already want to see: “documented model inventories, human-in-the-loop checkpoints for high-stakes decisions, monitoring for model drift and bias post-deployment, and a clear incident response plan specific to AI failures.”
My take: an exclusion is worse than a requirement. A requirement tells you what to do. An exclusion sits quietly in the policy and only shows up after something has gone wrong, on the day you find out what you were not covered for. So get the question early rather than at renewal. Ring whoever handles your insurance and ask 2 things: what will you ask us about AI next time, and is there an AI exclusion in what we have now. If they do not know, that is an answer too, and it means you have longer than you thought.
2. Five federal agencies say attackers are now writing industrial exploits with AI help.
On 19 August the NSA, CISA, the FBI, the Department of Energy and the Environmental Protection Agency issued a joint advisory on active targeting of Siemens S7 controllers. Attackers use ordinary open-source automation libraries and find exposed devices through internet scanning services. The sectors named are critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities. As Help Net Security reported the following day, the agencies were blunt: “this is not a theoretical risk, it is an active threat.”
My take: the line to read twice is the one about skill. Generating the scripts with AI is “dramatically reducing the technical expertise and time required”. The boring kit on your floor has been protected for 20 years by the fact that attacking it needed somebody who understood industrial protocols and had the patience to learn a proprietary stack. Those people were rare, and mostly employed. That protection is worth considerably less than it was in January, and no zero-day is involved. The way in is a controller sitting on the internet with the password it came with. This is the one on the list where the consequence turns up before anybody sends you a form.
3. Fabricated CVs are now 41% of detected hiring fraud.
Manufacturing Dive reported on 17 August on background screening in manufacturing, citing Checkr’s 2026 screening compliance report for the sector: fabricated CVs account for 41% of detected hiring fraud, and AI-assisted interview impersonation makes up nearly a quarter of reported cases.
My take: the collapse in cost that produced item 2 has also reached the paperwork at your gate. A convincing document used to take effort and a certain kind of nerve. It now takes a prompt. Most sites still verify a certificate by looking at it, which was a weak check 5 years ago and is close to no check at all now. The fix is cheap and dull: for anything safety-critical, verify with the issuer instead of the candidate. Ring the training provider. Check the ticket number against the register. Do it for the agency driver on their first shift, because the agency driver is the one on the truck this afternoon.
One thing to try this fortnight
Two phone calls. Neither of them takes 10 minutes and neither needs anybody’s permission.
Call one, your broker. Ask the 2 questions from item 1 and write down the answers. What will you ask us about AI at renewal, and is there an AI exclusion in the policy we have now.
Call two, your largest customer’s contact. Ask whether an AI question has turned up in their supplier questionnaire or their own audits yet, and if it has, what it asked for. People will usually tell you, because they are working out the same thing you are.
Both answers are dates, near enough. Between them you will know how long you have, and that is the one thing here you cannot work out by sitting and thinking about it.
If you want the harder version, walk the floor and stop at everything with a screen, a cable or an aerial on it. For each one, write what it controls and who can reach it from outside the building. You will not finish, and the unfinished list is still worth more than the complete one nobody was ever going to write.
Final thought
This is the ordinary kind of urgent, where the deadline belongs to somebody else and arrives with 4 days on it.
If you want to know what your people are already doing with AI before a customer or a broker asks you, I run a free 20-minute Shadow AI Check. No pitch, no deck. Reply and I will send you a time.
SOPwise turns a Standard Operating Procedure into a training package: task-based steps, critical mistakes, and scenario questions. £35 per SOP, no subscription. Built for UK manufacturing and chemical distribution.