Start Free Trial
Home/Regulations/NYDFS Cyber Insurance Risk Framework — Regulatory Reference
Regulatory Reference
Insurance State high

NYDFS Cyber Insurance Risk Framework — Regulatory Reference

Cybersecurity standards for cyber insurers — safeguards, incident detection, and vendor access controls map to AutoPIL.

Key Provisions
  • Circular Letter No. 2 (2021) — Cyber Insurance Risk Framework
  • Risk assessment, eligibility, escalating risk over time
  • Cybersecurity insurance market integrity expectations
  • Integration with 23 NYCRR Part 500 obligations
How AutoPIL Enforces It
  • AI agent access patterns considered when underwriting cyber risk
  • Audit chain supports loss-event investigation for AI-related incidents
  • Policy YAML expresses required safeguards in machine-checkable form
Policy EngineAudit LogSensitivity LabelsAlert Rules
AutoPIL Policy IDs
INS-NYDFS-CL2-001Cyber Insurance Risk Evidence
INS-NYDFS-CL2-002AI Incident Forensic Support
Official Sources

This page is a working reference and not a substitute for qualified legal review. Verify against official sources before use in compliance artifacts.

Frequently Asked Questions
What does the NYDFS Cyber Insurance Risk Framework require for cyber insurers?
NYDFS Circular Letter No. 2 (2021) requires insurers authorized to write cyber insurance in New York to establish and maintain a formal Cyber Insurance Risk Framework. This includes board-level governance of cyber insurance as a material risk, documented risk appetite, robust underwriting standards, data collection on policyholders' cybersecurity posture, and systemic risk mitigation practices. Insurers must also align their own internal controls with 23 NYCRR Part 500 — the NYDFS cybersecurity regulation — covering access controls, incident response, and third-party vendor risk. As AI agents increasingly handle policy data, claims processing, and fraud detection, those agents become in-scope access points that must meet the same safeguard and logging standards.
What are the vendor and third-party access control obligations under the NYDFS Cyber Insurance Framework?
Under the NYDFS framework and its integration with 23 NYCRR Part 500, insurers must conduct due diligence on third-party service providers and limit access to nonpublic information to what is necessary for the service. This applies directly to AI agent platforms and data connectors that touch policyholder records, claims data, or underwriting inputs. Insurers must be able to demonstrate that third-party access is authorized, logged, and limited in scope. AutoPIL satisfies this by requiring every AI agent to be registered with an explicit policy scope, enforcing that scope before any data is retrieved, and writing a tamper-evident audit record of every access decision — giving the insurer documented evidence of access controls for regulatory examination.
How does AutoPIL support loss-event investigation and incident response for AI-related cyber incidents?
The NYDFS framework expects insurers to maintain records sufficient to reconstruct the sequence of events in a cyber incident, including incidents caused by third-party or automated systems. AutoPIL's cryptographic audit chain records every agent access decision — including denials — with a tamper-evident hash linking each event to the previous one. If an AI agent is involved in a data exfiltration or unauthorized access incident, AutoPIL's log provides forensic-grade evidence: which agent, which data source, which policy governed the decision, what the outcome was, and the exact timestamp. This directly supports the incident investigation and breach notification obligations that flow from 23 NYCRR Part 500 Section 500.17.
When does the NYDFS Cyber Insurance Risk Framework apply to an insurer's AI deployments?
The framework applies to any insurer authorized to write cyber insurance policies in New York, regardless of where the insurer is headquartered. Because it integrates with 23 NYCRR Part 500, any insurer subject to NYDFS jurisdiction — including large commercial lines carriers, specialty insurers, and managing general agents writing cyber coverage — must treat their own cybersecurity controls as a risk management discipline. AI agents that access policyholder data, run underwriting models, process claims, or detect fraud are in-scope systems. If those agents can reach sensitive data without enforced access policies and durable audit logs, the insurer faces examination exposure for both the Circular Letter requirements and the underlying 23 NYCRR Part 500 obligations.
How does AutoPIL map to the NYDFS Cyber Insurance Risk Framework's safeguard requirements?
AutoPIL provides two policy configurations for NYDFS cyber insurance compliance: INS-NYDFS-CL2-001 (Cyber Insurance Risk Evidence) and INS-NYDFS-CL2-002 (AI Incident Forensic Support). INS-NYDFS-CL2-001 enforces access controls on AI agents touching underwriting and policyholder data, producing machine-readable evidence of safeguards for regulatory examination. INS-NYDFS-CL2-002 ensures the audit chain captures sufficient detail to support loss-event investigation when an AI agent is involved in or adjacent to a cyber incident. Both policies are expressed as YAML, version-controlled, and linked to every audit event — so the insurer can show exactly which policy governed each decision at the time it was made.
Covered Industries

The NYDFS Cyber Insurance Risk Framework applies to insurers authorized to write cyber insurance policies in New York State. As AI agents take on more of the underwriting, claims, and fraud-detection workload, they become governed access points subject to the same cybersecurity safeguard and audit obligations the framework imposes on the insurer's own systems.

AutoPIL Governance Platform

Enforce this regulation today

AutoPIL intercepts every AI agent data access call, enforces your policy, and writes a tamper-evident audit record — before sensitive data enters the agent context window.

Start Free Trial View All Industries