All Issues

Issue #15 — July 2026

The Reinsurance Treaty Cycle Meets AI

The KEV catalog’s late-June adds, the CERT-EU Ivanti Sentry advisory channel, and the NVD enrichment bottleneck arrive at the treaty desk together — weeks before the January 1, 2027 renewal cycle opens. The W26 reading reads quiet on the surface and consequential underneath.

Published July 1, 2026 12 min read 7 Sections ASI Market Index W26 37.6 ↓ −0.3

January 1, 2027 is the next major reinsurance treaty renewal date, and for the first time in the cycle’s history the submission packets crossing the treaty desks this autumn will be expected to carry a coherent AI-risk section. The line items that section will be priced against landed in the public record in the four weeks since Issue #14 went out. CISA added CVE-2026-20230 — a Cisco IOS XE SSRF with KEV-relevance — to the Known Exploited Vulnerabilities catalog in the late-June batch on June 25, 2026, with a near-term remediation due date.1 CERT-EU’s 2026 advisory series published 2026-008 on June 10 covering critical vulnerabilities in Ivanti Sentry — the kind of mobile-device-management edge component a reinsurer will read as a concentration-risk corroboration when the same vendor appears on multiple cedants’ stacks.2 The National Vulnerability Database continued publishing newly-scored CVEs through June 23 — CVE-2026-56113 through 56117 in a single day — against the backdrop of documented 2026 enrichment changes that have introduced measurable latency between CVE publication and full CVSS metadata availability.34 The AIRekt incident catalog continues to operate as the working community baseline for AI-incident classification, and the EU AI Act standardisation page remains the canonical reference for which harmonised standards a deployer can anchor a conformity narrative against ahead of the December 2, 2027 applicability date.56 Together these inputs answer a question the treaty market is asking out loud for the first time: what does an AI-risk submission look like when it lands on the desk during the renewal cycle?

Issue #14 specified the underwriting file as the artifact a deployer assembles for one renewal. This issue widens the lens to what a reinsurer does with that file when it arrives in a treaty submission alongside the cedant’s primary book. The reinsurance treaty cycle prices aggregate exposure across thousands of underlying primary contracts, and the AI section of those contracts has, for the first time, enough public-record inputs (KEV adds, CERT-EU advisories, NVD enrichment posture, incident-catalog corroboration) for a treaty actuary to model. The cycle has not waited for codification. It has begun pricing.

“The treaty desk does not ask the cedant for the underwriting file. The treaty desk asks the cedant for the aggregate. The underwriting file is the cedant’s defense of the aggregate when the treaty desk asks what is in it. This week named the inputs the treaty desk will use to test the answer.”

— ASI Intelligence Team observation, W26 2026

This edition examines how the renewal calendar has acquired an AI section, what a reinsurer underwrites differently for AI risk that a primary carrier does not, what the W26 reading at 37.6 (down 0.3) registers under the v3.1 methodology, how the KEV catalog functions as a pricing input rather than a security advisory, what the CERT-EU advisory channel and the Ivanti Sentry case signal about hardware-adjacent surface concentration, why the NVD enrichment bottleneck is itself a systemic risk input the treaty market reads, and the five operational moves a deployer should be making before the autumn submission window opens.

The Treaty Renewal Calendar Has Just Acquired an AI Section

01

January 1 Is the Hinge, the Autumn Is the Assembly Window

The global reinsurance treaty market clears on a small set of renewal dates — January 1, April 1, June 1, July 1 — with January 1 priced for North American property-casualty, European cyber, and most multi-line aggregate covers. Submissions are assembled in September and October, brokered in November, bound through December. The autumn assembly window is the period when a cedant’s aggregate AI-related exposure to loss stops being an internal accounting question and becomes a counterparty disclosure to a reinsurer who is going to price it. For the first time in the cycle’s history, the inputs that price will be sensitive to are not theoretical. The June 25 KEV addition of CVE-2026-20230 is one. The CERT-EU 2026-008 Ivanti Sentry advisory is another. The AIRekt catalog crossing the documented-incident threshold needed for actuarial use is a third. The treaty desk is no longer asking the cedant what AI risk looks like in principle. It is asking what the cedant’s aggregate looks like against a public-record baseline.

02

The Submission Will Be Read Against Three Public Anchors

A treaty actuary working an AI-exposed cedant’s submission this autumn will read it against three things they can independently corroborate. The first is the CISA KEV catalog — which entries the cedant’s stack inventory intersects, and what the cedant’s remediation cadence has looked like against the published due dates. The second is the public advisory channels — CERT-EU 2026 series, NCSC equivalents, vendor PSIRTs — for corroboration that the cedant’s disclosed posture aligns with what the upstream advisories actually said and when. The third is the incident catalog — AIRekt as the working community reference — for whether the cedant’s incident-history posture maps to a documented event classification that another carrier could independently verify. None of these are new sources individually. The change is that they are being read together, against a single submission, by a counterparty with pricing authority over the renewal.

What a Reinsurer Underwrites Differently for AI Risk

03

Aggregate Concentration Is the Question, Not Single-Risk Severity

A primary carrier prices a single deployer’s AI risk against the deployer’s controls, posture, and loss history. A reinsurer prices the aggregate of many deployers’ AI-related loss exposure against shared substrate. The questions diverge from there. A reinsurer cares less whether any single cedant has rotated provider tokens after the JetBrains plugin campaign, and more whether the cedant’s book is over-indexed on a single model provider, a single edge-management vendor (Ivanti, Citrix, F5), or a single MCP-gateway substrate that would correlate losses across hundreds of underlying contracts in a worst-case scenario. The June advisory channel is informative here because CERT-EU 2026-008 names Ivanti Sentry specifically — a mobile-device-management edge component used across financial services, healthcare, and federal sectors. A reinsurer reading the same advisory does not see a vulnerability; they see a concentration vector.

04

The Underwriting File Becomes the Aggregate Disclosure

The six-line-item underwriting file specified in Issue #14 (stack inventory, conformity narrative, incident-history posture, credential-boundary attestations, third-party CVD records, operational-control evidence) maps onto the treaty submission almost perfectly. Stack inventory becomes the concentration-risk disclosure: which providers, which vendors, what fraction of the book. Conformity narrative becomes the regulatory-tail disclosure: which jurisdictions, which standards, what the renewal-period regulatory risk looks like. Incident-history posture becomes the loss-development disclosure: how the cedant classifies its own incidents against the public baseline. Credential-boundary attestations become the operational-controls disclosure. Third-party CVD records become the dependency-exposure disclosure. Operational-control evidence becomes the engineering-discipline disclosure. The cedant who has assembled the file for the primary renewal arrives at the treaty submission with the aggregate disclosure already drafted. The cedant who has not will be assembling it under deadline against a counterparty whose pricing leverage is meaningfully greater than any single primary insured’s.

The W26 Reading Under v3.1 — A Quiet Down-Tick That Says Something

05

37.6, Down 0.3 from W25 — The Second Composite Motion Under v3.1

The ASI Market Index reads 37.6 for Week 26, down 0.3 from W25’s 37.9. This is the second composite-level motion since the W18 plateau began — the first was W25’s +0.2, the publication of the v3.1 methodology release, and now W26 is the first natural reading under the new aggregation scheme without a methodology-transition artifact in it. A v3.0 reading would have moved less; the eight-week exponentially-weighted moving average that v3.1 introduced lets the in-week motion show up at the composite where the cumulative-substrate mean would have flattened it. The public-signal readings for W26: VSS 55.1, TSS 48.4, AIRS 38.9. The vulnerability surface is flat against W25, the threat surface absorbs a small downward correction as the W25 incident cluster integrates into the rolling mean, and the engineering-signal reading is unchanged. Signal of the Week: model-provider / platform access-control changes, selected by the deterministic ranker at score 0.55 from a thin sweep candidate set — a week in which the model-supply substrate produced the highest-coherence signal even in the absence of a single dominant headline event.

The full index page carries the W26 audit. The methodology disclosure remains: the signal-aggregation step is an eight-week EWMA with a bounded incidence adjustment, transitioned at W25 (marked in the index metadata as v3_1_start: 25), and the v3.0 series remains in the weekly history for back-testing. A 0.3-point composite move is small in absolute terms. It is meaningful because it is the first such motion the new aggregation has produced from a normal week rather than a methodology change.

The KEV Catalog as the Treaty Market’s Pricing Input

06

CVE-2026-20230 and the Pattern of Late-June KEV Adds

CISA’s late-June Known Exploited Vulnerabilities additions, headlined by CVE-2026-20230 (Cisco IOS XE SSRF, NVD-published June 3, last modified June 26), continue the pattern Issue #13 documented under BOD 26-04: the KEV catalog is no longer a federal-mandate artifact read primarily by CISO offices in U.S. agencies. It is now read by reinsurance treaty underwriters in London and Bermuda as a pricing input. A cedant whose stack includes any KEV-listed component without a documented remediation timeline is presenting an exposure the reinsurer can independently corroborate by simply reading the catalog. The autumn-2026 submission window will be the first to be priced against KEV entries that name AI-adjacent components — gateways, model-provider access surfaces, MDM/MAM components that broker access to AI tooling from mobile endpoints.1

07

The Cisco SSRF Pattern Re-Activates the Edge-Concentration Question

CVE-2026-20230 is a Cisco-published SSRF in IOS XE, which means the affected substrate is the network edge of a meaningful fraction of the enterprise estate. SSRF chains pair with cloud-metadata service exposure and with internal API surfaces that AI agents often have access to via gateway substrate. The reinsurer reading this advisory does not need to interpret the AI angle directly; the AI angle is implicit in the network edge being the boundary that brokers traffic between AI agents and the systems they act on. The submission disclosure that documents the cedant’s KEV-remediation cadence is the line item that turns this advisory into a defensible position rather than an open exposure.

CERT-EU 2026-008 and the Hardware-Adjacent Surface

08

Ivanti Sentry as the Concentration-Risk Case Study

CERT-EU 2026-008, published June 10 covering critical vulnerabilities in Ivanti Sentry, is the kind of advisory a reinsurer files differently than a primary carrier does. Ivanti Sentry is mobile-device-management infrastructure broadly deployed across financial services, healthcare, defense, and federal sectors. When a single advisory names a vendor whose substrate appears on a meaningful fraction of an aggregate book, the advisory becomes a concentration-event indicator. The treaty actuary’s question is: across the cedant’s underlying portfolio, what fraction of insureds touch Ivanti Sentry, and what does the cedant’s incident-history posture look like for the post-advisory window. The AI angle is direct: an MDM/MAM substrate is where AI tooling tokens, IDE plugin policies, and provider API access on managed endpoints flow through. A compromise of the MDM is a compromise of the credential-boundary attestation line item of the underwriting file.2

09

The Advisory Channels Are the Corroboration Substrate

CERT-EU, the U.S. CISA advisories, vendor PSIRT feeds, and the OpenSSF advisory database are the public corroboration substrate the autumn treaty submission will be read against. A cedant who has documented its conformity-narrative line item without referencing the upstream advisory channel for its tooling is presenting a narrative the reinsurer cannot independently verify. A cedant who has anchored the narrative against the publicly-available advisories is presenting a narrative the reinsurer can cross-check in minutes. The difference is not about the accuracy of the disclosure; it is about how much friction the underwriter has to apply to validate it. Submissions with low validation friction price better.

The NVD Enrichment Bottleneck as Systemic Risk

10

Coverage Latency Is Now a Disclosed Input

The National Vulnerability Database continued publishing newly-scored CVEs through June 23 — CVE-2026-56113 through 56117 appeared in a single day’s output. The published-CVE volume is operating at expected levels. The latency between CVE publication and full CVSS metadata availability, however, has measurably widened under documented 2026 policy and resourcing changes — an enrichment bottleneck independent verifiers including Black Duck have documented across the year.34 A treaty underwriter who depends on CVSS metadata to triage exposure across thousands of underlying insureds is operating against a slower reference clock than the threat landscape is running on. This is itself an underwriting input. The cedant whose vulnerability-management program reads CVSS only when the enrichment lands is operating against a coverage gap. The cedant whose program reads CVE publication directly and triages on first-party advisory content is operating against the actual surface.

11

The Cedant’s Posture on the Bottleneck Is a Differentiator

The autumn submission disclosure that documents how the cedant’s vulnerability-management program handles the NVD enrichment latency — whether it reads first-party advisories directly, whether it carries a CVSS-equivalent internal scoring step, whether it consumes the KEV catalog independently of NVD enrichment — is a differentiator. The submission that does not address this question is presenting an exposure the reinsurer will have to ask about. The submission that does is presenting an exposure the reinsurer has already validated.

The Bottom Line — Five Moves Before the Autumn Submission Window

Watchlist — Preparing the Treaty Submission Before the Cycle Begins Pricing

June 29, 2026
01

Promote the underwriting file from a primary-renewal artifact to a treaty-submission disclosure

The six line items already specified for the primary renewal (stack inventory, conformity narrative, incident-history posture, credential-boundary attestations, third-party CVD records, operational-control evidence) now need a second view: the aggregate version. Identify which line items, when summed across the cedant’s book, produce a concentration disclosure the treaty desk will read. Assemble the aggregate version of the file in parallel with the primary version, anchored to the same evidence, before the September submission window opens.

02

Document KEV-remediation cadence as a pricing-input disclosure, not a compliance line

Identify every KEV entry that intersects the cedant’s stack or the aggregate stack across underlying insureds. For each, record the publication date, the federal due date, the cedant’s observed remediation date, and the residual exposure window. Produce a one-page summary that maps the cedant’s KEV posture onto a chart the treaty actuary can read in two minutes. CVE-2026-20230 is the current proximate example; the methodology generalizes.1

03

Map the cedant’s exposure to advisory-channel concentration vectors

CERT-EU 2026-008 (Ivanti Sentry) is the current illustration; the pattern is repeatable. Identify the small set of upstream vendors whose substrate, when an advisory lands, would correlate losses across a meaningful fraction of the cedant’s book. For each, document the cedant’s monitoring channel, response cadence, and historical advisory-handling timing. The reinsurer is going to ask this question; the submission that pre-answers it prices better than one that doesn’t.2

04

Disclose the cedant’s posture on the NVD enrichment latency directly

The submission disclosure that addresses how the cedant’s vulnerability-management program handles the documented enrichment bottleneck — first-party advisory ingestion, internal CVSS-equivalent scoring, KEV-direct consumption — is a differentiator. The cedant whose program reads CVSS only after enrichment lands is operating against a slower clock than the threat landscape. Document the alternative path the program uses; document the latency budget; document the controls that compensate.34

05

Anchor the conformity narrative against an EU AI Act harmonised-standards milestone in the renewal period

The Digital Omnibus shift to December 2, 2027 for Annex III places the next reinsurance renewal cycle squarely inside the assembly window for the conformity narrative. Identify which harmonised standards are currently in flight against the cedant’s deployment profile, document the cedant’s alignment posture quarterly, and tie the conformity-narrative line item of the underwriting file to a quarterly review against the AI Act standardisation page rather than against a static interpretation. The cedant who refreshes the narrative on the standards calendar is the cedant whose disclosure ages well across the renewal period.6

Subscribe for Weekly Intelligence

Every Monday. The AI security developments that shape enterprise risk, insurance, and governance — curated by our intelligence team.

Subscribe Free

Read Issue #14: The Underwriting File for High-Risk AI

Sources

CISA Known Exploited Vulnerabilities catalog (third-party diff view), late-June 2026 — June 25, 2026 additions including CVE-2026-20230 (Cisco IOS XE SSRF) with near-term remediation due dates; validate against CISA canonical listing

CERT-EU 2026 security advisories — 2026-008, June 10, 2026: critical vulnerabilities in Ivanti Sentry; advisory channel used for corroboration when KEV adds related items

NIST National Vulnerability Database, June 2026 — newly-scored CVEs published June 23 including CVE-2026-56113 through 56117; CVE-2026-20230 detail page records Cisco-published SSRF, NVD-publication June 3, last modified June 26

Black Duck blog, 2026 — analysis of NIST NVD operational changes and reduced enrichment in 2026; documented latency between CVE publication and full CVSS metadata availability; relevant to signal reliability and to vulnerability-management program design

AIRekt — AI Security Incident Catalog, refreshed June 2026; community-maintained index of AI failures and incidents; working community baseline for AI-incident classification used as one of three public anchors a treaty actuary will read a submission against

European Commission — Shaping Europe’s digital future, June 2026 — AI Act standardisation: harmonised standards create a “presumption of conformity”; Digital Omnibus links applicability dates of December 2, 2027 (Annex III high-risk) and August 2, 2028 (Annex I harmonisation-legislation)