AI compliance answer

What is the difference between shadow AI and sanctioned AI?

Freshness
Last verified: March 24, 2026
Coverage
Shadow AI governance
Jurisdictions
General guidance
Referenced records
2

Direct answer

Sanctioned AI is officially approved, documented, and governed by the organization's AI policy. Shadow AI bypasses all governance controls, creating unmanaged regulatory and insurance risk because AI exclusion endorsements apply to all AI use regardless of authorization.

Carrier Endorsement Details

CG-40-47

Verisk — CG 40 47 01 26

Excludes bodily injury, property damage, and personal/advertising injury arising out of generative AI under Coverage A and Coverage B. Part of the January 2026 ISO edition; companion forms address narrower scopes: CG 40 48 (Coverage B / personal and advertising injury only) and CG 35 08 (products and completed operations).

Key Provisions

Excludes BI and PD (Coverage A) and personal/advertising injury (Coverage B) arising from generative AI
Companion form CG 40 48 limits the exclusion to Coverage B only
Companion form CG 35 08 applies the exclusion to products/completed operations
Applies regardless of whether AI is owned, licensed, or embedded
Type: exclusion Policies: CGL
PC-51380

W.R. Berkley — PC 51380

Absolute AI exclusion for D&O, E&O, and Fiduciary Liability — eliminates coverage for any claim "based upon, arising out of, or attributable to" AI use.

Key Provisions

Absolute exclusion — no coverage for any AI-related claim
Applies to claims 'based upon, arising out of, or attributable to' AI
Covers owned, licensed, and third-party AI systems
No carve-back for incidental AI use
Type: exclusion Policies: D&O, E&O, Fiduciary

Where this lands operationally

Gridex turns the compliance or coverage question into operated workflow controls: intake, review points, audit trails, and the places a person stays in the decision.