Businesses are rushing to insure AI risks, but most don’t know what they’re exposed to and how to mitigate it
As AI becomes embedded across business operations, Indian companies are rapidly increasing adoption — and are now actively seeking protection against AI-led risks. However, this demand is not matched by understanding. Most businesses continue to treat insurance as a checklist decision, without fully understanding the extent of their exposure or what their policies actually cover. According to Plum’s internal data, there has been a 45% spike in queries over the past six months from companies exploring coverage for AI-related risks.
To address this gap, Plum today announced the expansion of its business insurance offering with a full-stack risk management suite, designed to help companies understand, design and manage risk more proactively.
Built around the idea of comprehensive risk management, the platform brings together advisory, technology and insurance infrastructure together, enabling organisations to:
- Understand exposure: Identify risks across AI, cyber and operational systems
- Design coverage: Structure policies aligned to actual business risk
- Manage policies: Track coverage, gaps and compliance in real time
- Respond effectively: Navigate claims and incidents with guided support
As adoption accelerates, the potential impact of AI-led failures is also significantly higher than traditional cyber incidents. As businesses embed AI into products and workflows, exposure expands beyond breaches into failures driven by hallucinations, errors and uncontrolled automation — impacting customer outcomes, decisions and product performance.
This is no longer theoretical. Deloitte’s State of AI in the Enterprise 2026 finds that 40% of Indian organisations are already running AI at significant or full scale–ahead of the global average–with adoption concentrated in functions such as product development, operations and customer-facing workflows, where even small errors can translate directly into business impact. These risks cut across multiple liability lines, from Errors & Omissions and indemnity to Directors & Officers and general liability, depending on where the failure occurs. At the same time, attackers are using AI to scale and automate threats. While cyber insurance addresses external attacks, much of today’s AI-driven risk sits outside what traditional policies were designed to cover.
Abhishek Poddar, Co-founder and CEO, Plum, said, “What we’re seeing is not a lack of access to insurance, but a lack of clarity. Companies are adopting AI at speed, but the way they think about protection hasn’t evolved. This is no longer just about protecting against cyberattacks; it’s about understanding AI risk across every touchpoint in a company, including processes at companies and the products they build. As AI becomes core to how businesses operate, the ability to understand and respond to that risk will define how resilient they are.”
Recent directives from the Insurance Regulatory and Development Authority of India (IRDAI) have significantly tightened expectations around cyber incident response — including stricter reporting timelines and increased accountability for insurers and intermediaries; however, the product and operational layers have not kept pace. Insurers remain dependent on timely, structured inputs from businesses, while most organisations are still unequipped to detect, document and escalate incidents in real time. Plum’s role within this ecosystem is increasingly that of a bridge.
Saurabh Arora, Co-founder and CTO, Plum, said, “AI is now embedded inside how businesses operate. Failures don’t always show up as incidents. They show up in outputs, decisions and customer interactions, which makes them harder to detect and even harder to contain. That’s where most traditional systems fall short. Having deployed AI in high-stakes environments like health insurance, we’ve seen these failure modes play out in production. That gives us a different lens on identifying and mitigating AI risk.”
In the event of a breach, Plum acts as the first-response layer between businesses and insurers, facilitating:
- Support on end to end claims lifecycle process, across intimation, documentation, redressal, and closure.
- Coordinated response, facilitating the deployment of forensic investigators and crisis teams, enabling both containment and regulatory reporting to happen in parallel.
This expansion builds on Plum’s existing business insurance suite — including cyber insurance, directors & officers (D&O) liability, and asset protection — extending it into a more continuous, system-led approach to risk management. Plum’s business insurance vertical today works with 1000+ companies in India, and is seeing a clear shift in how businesses approach risk — from reactive protection to ongoing visibility and control.
With this launch, Plum aims to help businesses move from simply insuring against risk to actively understanding and managing it — especially as AI continues to expand the surface area of exposure.
