Skip to Content

Truyo launches new warranty program for privacy compliance, AI governance platforms

Truyo's new Warranty and Certification Program aims to plug the existing gaps in organization's cyber insurance policy coverage around privacy, consent management and AI governance.

Published
Subscribe to IAPP newsletters

Contributors:

Alex LaCasse

Staff Writer

IAPP

Companies' existing cyber insurance policies are being stretched amid emerging variables across the digital landscape. Compliance management around ever-changing global regulatory requirements, cybersecurity posture and the novel risks posed by the rising artificial intelligence development and use are among the prevalent issues at hand.

To help patch gaps in insurance policies, privacy compliance and AI governance vendor Truyo has launched a new Warranty and Certification Program for qualified customers of its Compliance Advisor and AI Governance platforms. The program offers customers protection valued up to USD500,000 to protect against regulatory, enforcement and litigation risks related to privacy and consent compliance, and up to USD1 million to protect against similar concerns related an organization's AI governance program. 

In an interview with the IAPP, Truyo President Daniel Clarke explained the warranty program is underwritten by cybersecurity risk management firm Cysurance and does not carry a deductible upon activation by a customer. Major areas of financial risk faced by companies on the privacy and AI governance fronts are potential litigation and regulators turning their focus on harms caused by AI, assuming current negative consumer sentiment continues toward the technology. 

"We're going to see a major wave of enforcement around AI from regulators starting early next year, and the reason they're going to go and enforce (against harms) so much more aggressively is because their constituents care about this issue" Clarke said. "We also see an enormous amount of (privacy-related) litigation. We're currently tracking over 2,000 lawsuits."

According to statistics compiled by the cybersecurity firm Heimdal, the overall number of cyber insurance claims decreased 50% last year, with ransomware attacks still leading as the top threat triggering an activation of an insurance policy in 60% of events. The average claim amount was USD115,000. 

Despite the decrease in the volume of claims, organizations still feel the need to protect themselves from a data breach, with 62% of global firms obtaining cyber coverage in 2025, which is up from 49% in 2024, according to Heimdal. 

Clarke said an issue with many cyber insurance policies is they do not cover financial penalties issued by government regulators, and, in some instances, private litigation brought against a company. Conversations with customers highlighted how their cyber insurance policies all carry deductibles and leave "ambiguous" wiggle room as to what types of incidents are covered. 

However, when the time comes to renew a policy, Clarke said companies are typically informed any new coverage specifically will exclude certain types of privacy and AI-related risks.  

"What happens if you're faced with one of these regulatory fines or some type of litigation, are you covered? This answer is probably not," Clarke said. "On renewal, all of the underwriters are explicitly excluding AI-related, all consent-related litigation. So, we know it's ambiguous today, but in the future it's very likely that you're not covered."

Truyo's Warranty and Certification Program is intended to serve as a "first line of defense" for customers to insulate themselves from hefty fines and damages stemming from lawsuits. Clarke said the program serves to reimburse customers without them having to file a cyber insurance claim. 

In order to qualify for the warranty program, Truyo customers must follow the vendor's existing compliance methodology. Truyo's platforms feature a daily scanner of a customer's data inventory on the Compliance Advisor side. For AI, Clarke said the daily scanning reviews for new use cases of AI models to ensure the flagged use is permitted. 

The scanning tool identifies both critical and non-critical issues that could trigger regulatory intervention or present a litigation risk. Customers are required to remediate a critical issue within five days and non-critical issues within 30 days to remain qualified for the warranty program. 

"If you perform these scans, then we warranty our platform," Clarke said. "We warranty that it's working properly, and we warranty that you're going to stay out of trouble."

CPE credit badge

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.

Submit for CPEs

Contributors:

Alex LaCasse

Staff Writer

IAPP

Tags:

Compliance techRisk managementAI governancePrivacy

Related Stories