Jun 17 2026 | Lawrence Shaw
What AI Reads Before the Claim
What AI sees, not what the organization says.
TL;DR
AI reads an organization from the outside in, before a customer or a regulator forms a view. It reads what the organization has published, including the sites and documents it no longer knows are online. That reading is now a live exposure, and it sits outside what risk management currently measures.
The exposure grows as each new model reads more of the estate. AI systems read across an organization’s published material, repeat what they find, and carry it into the answers people act on. In regulated settings the stakes are immediate: a pharmaceutical instruction taken from an outdated page, a regulator’s guidance summarized back to the public with its meaning changed. The failure traces less to the model than to the material it found to read.
The estate no one is reading
Websites unknown to digital teams
Share of websites the organization no longer recognizes
- 41% Unknown to digital teams
- 59% Known to digital teams
Source: AAAnow risk profiling, 2017–2023, 100M+ websites.
Most of this material is in plain view. Some of it the organization no longer recognizes. Sitemorse/P&C data, drawn from risk profiling across 2017 to 2023 and covering more than 100 million websites, indicates that 41% of websites are unknown to the organization’s digital teams. AI does not separate the estate a company maintains from the estate it has forgotten, so it reads both and represents the organization from the whole of it, which is how misrepresentation enters at scale.
The cyber exposure that dropped out of the conversation
One exposure inside the unknown estate has faded from view since the early cyber years. Old sites, dormant subdomains, and unmaintained pages are openings, and they multiply as the estate grows beyond what anyone is tracking. The maturity work places cyber exposure from the unknown estate at its highest where the fundamentals are weakest.
The capability reading that estate is advancing faster than the market is absorbing. In June 2026 the US government issued an export control directive on national security grounds, and Anthropic disabled its Fable 5 and Mythos 5 models worldwide, with the reported concern being the models’ cybersecurity capability. When a government treats a frontier model’s cyber capability as cause to remove it from the market, the same capability reading an organization’s oldest and least-watched pages is an exposure that belongs on the register.
Inclusion is now a reading problem
A second exposure is read in a way few risk registers capture: how accessible the organization’s content is to the systems now reading it. AI agents read a page through its structure, not its visual design. Some are vision-led, such as Anthropic’s Computer Use, which works from screenshots and is fragile when layouts shift. Others lead with the accessibility tree, the same structure that supports screen readers, and these are the approaches built for reliability and speed.
The effect on agents is measurable. In a study presented at CHI 2026, researchers at UC Berkeley and the University of Michigan tested an AI agent across 60 desktop and web tasks. Task success ran at about 78% under standard conditions, fell to 42% under keyboard-only navigation, and dropped to 28% under a magnified viewport. When the underlying structure is weak, the agent fails where an assistive-technology user fails.
AI agent task success by access condition
Percentage of 60 desktop and web tasks completed successfully
Source: A11y-CUA dataset, UC Berkeley and University of Michigan, presented at CHI 2026.
Inclusion shapes whether AI can read and act on the organization at all, which is why it carries weight in how the organization is read. AAAnow modeling, built on more than 3.7 trillion data points and 25 years of digital assessment across accessibility and privacy, places that weight at 19% of how AI reads an organization. Accessibility has already produced years of litigation under the ADA, and the same weaknesses that draw those claims now degrade how AI represents the organization.
Privacy sits in the same layer and is already on the board’s record. It is a published behavior the organization may not be tracking, read and weighed by systems forming a view of how far the organization can be trusted. Where privacy signals are inconsistent across the estate, the picture AI carries is inconsistent with the position the organization intends.
Measurement comes first
None of this can be managed in the abstract. It has to be measured, and measured independently, before any of it can be monitored or moved. A risk manager knows the order: without a baseline read from outside, there is no position to track, no evidence of change, and no defensible claim that exposure has come down. The first move is an independent measure of where the organization stands.
A standard for that measure now exists. The AI Readiness Maturity Scale places an organization on a 0 to 100% range across 6 bands, from Foundational to Leading, read from the outside in. Beneath it, 10 principles set out what AI sees when it reads each property, among them machine structure, authority and provenance, integrity and consistency, inclusion, and privacy and trust. Against that scale, AAAnow AI research assesses 3% (May ’26) of organizations at the Leading level, the top band, with the rest holding positions that carry more exposure than their boards have measured.
Measurement holds only if it keeps pace with the estate. Sites change, pages are added, and forgotten material surfaces, each shift carrying its own weaknesses into the position. Active discovery brings the unknown estate into view and keeps it there, surfacing the unknown unknowns before AI reads them on the organization’s behalf. A position measured once is a snapshot; a position discovered and monitored continuously is a control.

Reference: AI Readiness, AAAnow (June 2026)
The AI Readiness publication sets out the AI fundamentals maturity scale referenced in this article: a 0 to 100% range across 6 bands, from Foundational to Leading, read from the outside in.
Content is for informational purposes only and does not constitute legal advice.
What this gives the risk professional
This opens a conversation most clients have not been offered. Organizations carry the exposure without a way to see it, and many face claims they did not understand they were exposed to. John Farley, managing director of Cyber Liability at Gallagher, reads the same gap in the firm’s survey: 43% of businesses have a written incident response plan for AI losses, 1 in 5 have already had losses or claims, and 53% of insurance-sector leaders said cover fully met their clients’ AI losses. A measured position and active discovery give both sides the evidence they currently lack.
Two requirements would begin to close that gap. The first is an AI readiness position measured against a recognized scale, so the organization and its insurer can see where it stands. The second is evidence of active discovery, continuously monitoring the digital landscape and surfacing the assets no one is tracking. Both reduce the insurer’s exposure and the insured’s, because both replace assumption with a position that can be read.
A third requirement belongs to the layer above this one: governance of what AI can and cannot reach, so the systems reading the organization meet the right information at the right time. That is the subject of the next piece in this series.
The scale of AI is not a reason to wait for it to settle. It is the reason to read where the organization stands now, from the outside, while the picture is still forming. The organizations that measure first hold the position AI represents; those that wait inherit whichever position AI has already assembled. For the risk professional, that is the difference between a claim explained after the fact and an exposure seen before it forms.

Related reading
Gallagher’s John Farley, managing director of Cyber Liability, discusses the scope of AI liability for business leaders, the exposures organizations face, and how proactive incident response planning can mitigate them.
Sources
- Arthur J. Gallagher & Co., “Interview: What Business Leaders Should Know About AI Liability,” featuring John Farley, May 2026.
- A11y-CUA dataset, UC Berkeley and University of Michigan, presented at CHI 2026.
- SitePoint, Mike Barton, “How AI Agents Are Making Accessibility a Business-Critical Development Priority,” 18 May 2026.
- Anthropic, statement on the US government directive to suspend access to Fable 5 and Mythos 5, June 2026.
- AAAnow AI research and risk profiling data, 2017 to 2023.
