Download

AI Exposes Gaps in E&O Coverage

Autonomous AI systems are outpacing legacy tech E&O policies, exposing businesses to uninsured algorithmic accountability risks.

E&O Insurance

"AI will not replace humans, but humans who use AI will replace those who don't."

Whether or not you agree with that sentiment from Sam Altman, the implication is undeniable: Yet as businesses embrace AI, a precarious gap has opened between its capabilities and the insurance frameworks designed to protect organizations in light of this technology.

The Breakdown of Legacy Tech E&O

The P&C industry has long relied on tech E&O for risk mitigation when it comes to digital services. But these legacy policy forms were largely built for a software era where human error was the main culprit. There was a relatively clear trail of accountability, and a failure typically meant a system crash or a coding bug.

Today, we see autonomous agents making decisions that result in financial loss. Dynamic, self-learning algorithms are making questions of liability much more complex. New rules are being written seemingly in real time.

Take the Air Canada example – perhaps one of the highest-profile instances of AI E&O. Back in 2024, the airline's chatbot hallucinated a policy offering retroactive bereavement refunds. When the passenger tried to claim the refund, Air Canada refused, arguing that the chatbot was a separate legal entity, responsible for its own actions.

A Canadian tribunal rejected this defense, saying that a company is responsible for all information on its website – whether it is delivered by a web page, or an automated agent. "The AI said it" was not a legal defense.

There has been a distinct rise in grey-zone liabilities like this – risks that don't fit neatly into the buckets of a standard data breach or a traditional professional error. Consider issues such as algorithmic bias, data poisoning, and technology-driven discrimination. These risks often fall in the cracks between cyber exclusions and professional liability triggers.

For brokers and insured businesses, this gap creates dangerous exposure to a new class of litigation where policy language simply hasn't kept pace with technology.

Same Regulations, New Litigation

The idea of "cyber risk" itself is evolving thanks to the impact of AI. Where it was largely about data privacy in the past, businesses today also need to think about algorithmic accountability.

One of the most striking examples is how the Americans with Disabilities Act (ADA) is being used as a tool for technology litigation. For example, if an AI-driven hiring tool or a financial services algorithm inadvertently discriminates against a protected group, the resulting legal challenge can be seen as a violation of professional standards and statutory law.

Workday came up against this in 2025, facing a massive class-action lawsuit (Mobley v. Workday) that alleged its AI-based screening tools discriminated against applicants based on race, age, and disability.

This case showed that blaming a technical glitch isn't legally defensible. When technology begins to make decisions that affect human rights and equity, an error is ultimately a failure of governance – it's people that are ultimately liable.

Traditional E&O policies often focus on language such as "failure of technology to perform." This wording doesn't handle socially-driven technical failures.

From Risk Transfer to Integrated Resilience

For the P&C market to remain sustainable and relevant, we can't just be reactive. Digital innovation now happens so fast that by the time a claim is filed, the underlying technology has likely already iterated several times over. New technological uses for AI are emerging every day.

To meet this moment, the insurance industry must pivot to an integrated resilience framework – a ground-up re-engineering of policy language that addresses the reality of modern autonomous systems.

This requires a shift from simple risk transfer to a "predict, prevent, and insure" model. In this new framework, insurance can't be a static document sitting in a folder somewhere. It must include:

  • A complete digital risk package that integrates cyber coverage, threat protection, and 24/7 incident response directly into the Tech E&O form.
  • Insurer bundles that feature real-time threat intelligence and proactive monitoring.
  • Explicit language to avoid exclusions and bridge the gap left by grey-zone liabilities.

By implementing these changes, we can provide incentives for early incident reporting (through motivators like retention waivers for fast action) rather than penalizing it – which ultimately leads to incidents that spiral into larger liabilities. We can create an environment where insurers and businesses are working together to strengthen resilience; rebuilding trust and collaboration.

Restoring Confidence Through Insurance

The ultimate goal of insurance should be to provide businesses with the confidence to innovate. In the early days of digital transformation, that meant protecting against hardware and human failures. Today, it means giving businesses of all sizes – from startups to enterprises – the self-confidence to deploy AI and SaaS solutions without the fear that an unforeseen algorithmic bias or a sophisticated social engineering attack could derail operations.

Simplicity is key here. Both cybersecurity and insurance have a reputation for being unnecessarily opaque. As we face sophisticated AI-related risks, our industry's response shouldn't be to add more jargon and complex exclusions. Instead, we should strive for unambiguous coverage that recognizes how professional services and digital delivery are connected.

Protecting Innovation for the Future

The path forward requires our industry to embrace a more proactive stance. We must move beyond the data breach and embrace a model where insurance is an active participant in a company's security posture. This means not only helping them respond to and recover from incidents faster, but perhaps more importantly, helping them predict and prevent incidents in the first place.

Validation for this approach is growing. We're beginning to see the market move toward all-in-one protection models that combine insurance with active risk management platforms. These platforms provide the tools and training necessary to strengthen controls before an incident occurs.

But the gap between legacy and modern Tech E&O is still growing. We need insurers and coverage models to keep pace with the ever-changing AI landscape.

The AI-fueled gap in Tech E&O is a challenge, but it is also an opportunity to build a more sustainable P&C market. By evolving our products to match the sophistication of the tools our clients use, we can ensure that the digital economy remains a safe space for growth and innovation for everyone.


Vishal Kundi

Profile picture for user VishalKundi

Vishal Kundi

Vishal Kundi is a co-founder and CEO of Boxx Insurance.  

He was previously chief sales officer at Arthur J. Gallagher and has lived and worked across the world, including in Dublin, London, Hong Kong, Santiago and Toronto.

AI Alone Cannot Close Insurance's Execution Gap

Volatile risk conditions demand faster decisions, yet many insurers cannot operationalize AI intelligence quickly enough to respond to market shifts.

Man sitting at a desk with an AI robot next to him pointing at a computer screen

Insurance has never lacked ambition when it comes to modernization. Most carriers recognize the pressures reshaping the industry. Risk is becoming more volatile, customers expect faster and more personalized experiences, and legacy operating models are making it harder to respond at the pace the market now demands. AI gives insurers an opportunity to close that gap by improving how decisions are made across the insurance journey. The challenge is to turn that intelligence into governed action fast enough to make a difference.

Across climate-exposed regions, carriers are reassessing where they write business, how they renew policies, and what levels of catastrophe exposure they can responsibly carry. In cyber insurance, threat vectors evolve faster than historical loss experience can reliably inform pricing and underwriting. Litigation trends, inflation, geopolitical disruption, supply chain instability, and specialty market complexity are all changing portfolio dynamics in ways that affect pricing adequacy, underwriting appetite, claims severity, capital allocation, and customer behavior at the same time.

In my opinion, the issue is no longer whether insurers recognize the need to adapt. The real challenge is whether their operating models can convert signals, models, rules, and human judgment into production decisions quickly enough to keep up with these changing conditions.

Risk is outrunning episodic decision cycles

Insurance operating models were largely built around periodic adjustment. Rate changes, underwriting rule updates, product modifications, compliance reviews, and distribution decisions often move through sequential processes. Those processes were rational in a market where risk signals developed more slowly and decision cycles could afford to be measured in months, but that environment is fading.

When market conditions shift faster than execution cycles, the consequences become real. Delayed rate action can weaken pricing discipline and expose margin before carriers fully see adverse selection building inside the book. Slow underwriting appetite changes create another form of exposure, especially when business continues to be written against assumptions that no longer reflect the carrier's strategy. Even customer signals lose value when they remain disconnected from pricing, product, and retention logic, leaving profitable relationships exposed.

Legacy systems are part of this tension, although they are not the villain. Policy administration systems, claims platforms, billing systems, and rating infrastructure remain essential systems of record. The problem is that many are being asked to support adaptive decision making work they were never designed to handle. Systems built to store, administer, and transact are now being pushed to sense, decide, govern, and adapt continuously.

The bottleneck is not the model

Boards and executive teams are investing in AI for good reasons. AI can accelerate analysis, automate repetitive tasks, improve modeling precision, and help teams process more complex data than traditional workflows allow. Working with customers, I see why that investment makes sense. The industry needs more speed, more precision, and better use of scarce expertise.

Yet many AI initiatives lose momentum once they move beyond experimentation. A pricing model can sharpen analytical precision without making the enterprise more adaptive if underwriting still moves through disconnected workflows, claims signals never reach product and portfolio decisions, and customer engagement tools improve outreach without connecting to the logic that determines risk, profitability, and retention.

The issue is not just model performance, but the ability to connect data, models, business rules, workflows, governance, and human oversight so AI can support real underwriting, pricing, claims, and customer decisions in production.

Insurance decisions carry financial, regulatory, and social consequences. They must be explainable, auditable, repeatable, and aligned with underwriting discipline and capital management. Horizontal AI tools can improve productivity, but insurance-grade decision making requires domain depth, governance, and operational context from the start.

Decision making needs an operating layer

Many insurers have made real progress inside individual functions, especially in pricing, underwriting, and claims. The problem is that local improvement does not automatically create enterprise agility. A stronger pricing model has limited strategic value if underwriting cannot act on the same intelligence, claims signals do not inform portfolio decisions, and customer engagement remains disconnected from risk and profitability. The deeper issue is not whether intelligence exists inside the business, but whether it can move across the business in time to change the outcome.

Insurers need governed decision making to work above and across existing systems. That layer should allow carriers to preserve operational stability while enabling intelligence to move across pricing, underwriting, claims, compliance, distribution, and customer engagement.

The aim is to reduce the distance between insight and action, giving carriers a more consistent way to test changes, understand likely impacts, govern approvals, deploy updates, and monitor outcomes as AI moves from experimentation to operational capability.

Governance makes speed deployable

Speed only strengthens resilience when it is matched by control. In insurance, faster decisions only create value when they remain explainable, auditable, and aligned with regulatory and business discipline.

This is where governance becomes a deployment advantage. Carriers that cannot explain how decisions are made will struggle to scale AI into production. Teams may trust a model in a pilot environment, but production use requires traceability, bias monitoring, approval workflows, performance monitoring, and clear human accountability.

That does not mean slowing the business down. It means building guardrails into the way intelligence operates. Pricing optimization, underwriting evaluation, portfolio steering, compliance validation, claims triage, and customer retention each require the right form of AI, the right level of automation, and the right degree of human involvement.

The New Operating Discipline for Insurance

Insurers need a new operating standard: one that connects intelligence across the policy lifecycle and gives carriers the speed, adaptability, and control to respond as conditions change.

The next phase of insurance transformation is as much about operating design as it is about AI. AI creates value when it is embedded deeply enough into the business to support faster, more disciplined, and more accountable decisions. That gives carriers a better way to recalibrate pricing, refine underwriting appetite, identify portfolio drift, support compliance, and respond to customer signals before opportunities or exposures have already moved.

AI capability alone will not close the insurance execution gap. The real advantage will belong to carriers that can make intelligence operational, connecting models, data, workflows, rules, and governance into decisions that keep protection available, profitable, and resilient.

How Agents Can Maximize Their Tech Stack

Independent agencies' biggest challenge isn't choosing or installing technology—it's getting the most from tools they already have.

Success

As an independent agent, you know how hectic running a business can be. You're rekeying client data, putting together proposals for every prospect, and chasing missing documents from clients. It's easy to fall into a routine with your tech stack without exploring what else it can do. You want to dig deeper, but you're not sure where to start.

You're not alone. According to recent research we conducted, agencies of every size say their biggest challenge isn't choosing a tool or getting it installed, it's getting the most out of the technology they've chosen.

To that end, here are a few strategies to help you and your busy team make the most of your current setup.

Revisit Your Why

Before exploring new features or workflows, take a step back and remind your team why the technology you've invested in matters. Your "why" might be that you're losing clients at renewal because your team can't get to everyone in time. Manual processes could be creating errors that expose your agency to E&O claims. Or it might be about creating time for higher-value work — hours freed for digging into coverage reviews and building deeper relationships with clients.

Teams don't resist change so much as they resist change that doesn't make sense to them. Research from Prosci's Best Practices in Change Management report shows that projects with excellent change management are seven times more likely to meet their objectives. When you introduce something, don't just explain what it does. Explain the challenges it will help alleviate.

When your team can see the connection between using their technology better and solving a problem they already feel every day, adoption will feel more like relief rather than extra work.

Start with Tasks You'd Like to Hand Off

The next step is to look for outstanding inefficiencies in your workflows that your management system can fill.

Ask your team a simple question: what part of their day would they hand off tomorrow if they could? The goal is to surface the tedious, admin-heavy work that technology can take off their hands. Whether the answer is repetitive data entry, drafting the same client emails five times a week, or finding account information, these responses will help shape where you focus first.

Email drafting and account retrieval can be a great place to start. A study commissioned by Slack found that 57% of small-business employees feel bogged down at work by menial tasks, with responding to emails (47%) and finding internal information they need to do their jobs (38%) topping the list.

The good news is that AMS technology can handle both. AI tools can generate polished email copy from a simple prompt and pull together summaries of client account history from emails, texts, and agent notes — saving time from reviewing every interaction manually.

These are impactful steps that don't change what your team does but rather give them a more efficient way of doing their work.

Recognize When You're Ready for More

Your team has found their rhythm. The tools you've introduced are working, people are using them, and things feel good. The question now is how to keep building without disrupting what's working.

A few ways to know when your team is ready for more:

  • They're using current tools without being reminded.
  • You're seeing real results — time back in the day, better client conversations, or fewer things slipping through the cracks.
  • They're asking what else the system can do.

When staff start asking, "Can it also help with…?" or "What if we used it for…?" — your team is not only finding true value in the technology, but starting to trust it. That trust makes introducing the next feature or workflow a much easier conversation.

Keep the Momentum Going

Technology adoption has a way of building when you lead with a clear purpose and focus on small wins. Over time, your team stops seeing technology as something they have to use and starts seeing it as something that works for them. That's how you free up the time and headspace for the high-value work that energizes you and your team.

Insurers Use AI to Combat Rising Fraud

Insurers are deploying AI to combat increasingly sophisticated fraud schemes, but detection still hinges on fundamental prevention and deterrence strategies.

Cyber Security

Insurance fraud has always been an arms race. Today, that race is accelerating as insurers face both increasingly sophisticated schemes and an expanding arsenal of tools to combat them.

Fraud spans nearly every major line of insurance, from auto and health to property, life, and commercial coverage. It also takes multiple forms, broadly falling into two categories: hard fraud and soft fraud.

Hard fraud involves deliberate acts intended to create a loss or fabricate one entirely. These are things like staged auto accidents, arson, phantom injuries, or organized fraud rings.

Soft fraud occurs when a legitimate claim or application is exaggerated or misrepresented. This could be prior damage claimed as new, understated mileage, inflated contents lists after a loss, or exaggerated injuries.

Soft fraud is often harder to prove, even when investigators suspect something is off, said Katie Pope, senior vice president, executive lines, for The Liberty Company Insurance Brokers.

"You have to get to a final judgment on the fraud for the policy not to cover," Pope said. "Even if there are strong allegations, that doesn't mean the insurance company won't end up paying."

That challenge explains why insurers increasingly focus on prevention throughout the policy lifecycle rather than relying solely on post-loss investigations.

Policy lifecycle risks

Fraud can occur at nearly every interaction point.

At application, carriers face misrepresentation risk, such as identity fraud, synthetic identities, or omitted information.

During the policy period, suspicious activity may emerge through unusual endorsement requests, coverage increases shortly before losses, or shifting risk characteristics.

At claim time, insurers confront the most visible fraud risks, which include inflated losses, fabricated documentation, and organized schemes.

Modern fraud programs increasingly aim to stop questionable activity earlier.

When it comes to AI, the technology is both a threat and a defense.

Fraudsters now use AI to generate convincing phishing emails, forged documents, and increasingly sophisticated social engineering attacks.

At the same time, AI has become one of the industry's most effective investigative tools.

Machine learning models can review thousands of variables simultaneously, identifying patterns that human investigators might miss, such as repeated repair facilities, geographic clustering, or claim similarities across files.

AI is particularly valuable as an early-warning system that helps prioritize cases for review.

Today's tools

Insurers today are also relying more heavily on third-party data to validate information at both application and claims stages, said Patrick Foy, senior director, property and casualty strategic planning for TransUnion.

Property records, public filings, historical claims databases, and external identity sources allow carriers to compare reported information against independent records.

Automated tools increasingly verify the identity of applicants and claimants through document authentication, biometric checks, and cross-referenced databases. These systems help reduce ghost applicants and impersonation attempts.

Behavior analytics is another emerging frontier.

Rather than focusing only on what information is submitted, insurers are increasingly examining how it is submitted. Systems can flag unusual activity patterns during applications or claims, such as abnormal typing behavior, copy-paste activity, multiple applications from the same device, or signs of automation.

These signals do not prove fraud, but they help identify cases for closer review.

Back to the basics

Even with today's advanced tools, fraud fighting still follows a familiar principle: detect and deter.

Detection identifies suspicious activity. Deterrence raises the cost and difficulty of attempting fraud in the first place.

Technology strengthens both sides, but successful fraud programs still depend on fundamentals.

Data quality, documentation practices, investigator training, cross-functional coordination, and disciplined claims handling remain essential.

Sophisticated AI cannot compensate for weak processes.

"Insurers that are most successful use an 'all fronts' approach," Foy said.

The technology may be changing rapidly. The objective has not. Get the basics right, identify suspicious activity early, and make fraud harder to commit.

What Happens Next in Iran — and What It Means for Insurers

We seem to be headed to a Gaza-like ceasefire, ostensibly restoring calm but leaving the underlying conflict unresolved. Many insurance lines will have to adapt.

Image
World Map

When allies of President Trump went on television over the weekend to say that a peace agreement between the U.S. and Iran was 95% complete, I was reminded of a truism among software developers in the 1990s: "The first 80% of a project takes 90% of the time, and the final 20% takes 90% of the time."

Comments on social media noted that even if negotiators had made it through 95% of the issues on their checklists, that progress meant that the U.S. and Iran still had to agree on what to do about Iran's stockpile of enriched uranium, about reopening the Strait of Hormuz and about U.S.-led economic sanctions against Iran. You know, the little stuff.

While there have been more reports today on potential progress, I'm ready to call it. Having covered an international mess or two in my time, I think the situation in Iran has all the markings of a long-term impasse. I'm convinced Iran will be an open wound for many years to come. The best we can hope for, I believe, is the sort of "ceasefire war" occurring in Gaza, where the fighting has officially been ended but the underlying conflict still festers.

Insurers need to prepare themselves. 

I'll still hold out hope that President Trump can achieve the kind of agreement with Iran he's been promising: reopening the Strait of Hormuz to any and all traffic, without tolls, while removing Iran's ability to ever build a nuclear weapon. But I no longer think any such resolution is likely. I don't even think a clean, lasting agreement is possible.

The clincher for me came this morning, when I read a column in the Washington Post by a former colleague of mine from the Wall Street Journal, Karen Elliott House, who is as plugged in to the Middle East as any journalist could possibly be. Karen won a Pulitzer Prize for her coverage of the Middle East in the 1980s and has stayed plugged in to the point that last year she published the definitive biography of Saudi Crown Prince Mohammed bin Salman. 

She wrote: "When the U.S. and Israel unleashed a blistering bombing campaign striking more than 10,000 Iranian targets, and Tehran’s response included attacks on Saudi oil installations and military bases, the Saudi air force initially struck back. But as President Donald Trump tolerated a ceasefire longer than the war itself, and repeatedly threatened to resume hostilities only to back off, the crown prince concluded that he must live with a hostile regime in Tehran. His focus now will be on placating Iran to protect Saudi."

If the Saudis have switched to appeasement — and I believe Karen implicitly — they leave Trump with almost no choice. Even if he felt he could ignore the need for congressional approval of a conflict lasting more than 60 days, under the War Powers Act, or could win approval from a Republican Congress increasingly nervous about an unpopular war as we head into the mid-term elections, Trump isn't going to resume hostilities without support from this major Middle Eastern ally. That means he's left having to negotiate with an extremist, theocratic regime that, by all accounts, thinks it has won the war.

Whatever deal ensues, Trump will surely claim a major victory, but Iran will remain volatile. Having shown the world that it can close the Strait of Hormuz, even while under attack by the world's greatest military power, Iran will keep shippers on edge, thus keep oil markets nervous. Iran will surely retain enough of a pathway to nuclear weapons that there will be the prospect of additional air strikes like the one the U.S. and Israel carried out on Iran last summer. If the U.S. eases economic sanctions, as Iran is demanding, Iran will surely funnel some of that money to its proxies throughout the Middle East as they try to destabilize Israel, Iraq, Lebanon, and Yemen. 

Because the Middle East is so unlikely to return to the conditions before the war, insurers should assume that conditions today will persist for at least many quarters and probably many years.

Shipping patterns will adjust to the higher risks in the Strait of Hormuz, and insurers will have to adjust to those new patterns. Global supply chains for all sorts of goods will change, keeping replacement parts for cars hard to get and limiting access to housing materials, so pressure on premiums will continue. 

Gasoline prices will drop somewhat but remain steep, keeping a lid on traffic and, thus, traffic accidents. People will fly less, in the face of increased air fares, reducing the demand for travel insurance. With gas prices driving inflation, interest rates are likely to stay elevated; the housing market is already a disaster, and sales will stay depressed, reducing opportunities for homeowners insurance companies to attract new customers. 

And so on. 

There will surely be secondary effects, too, though those are obviously harder to predict. The big question, for me, relates to the mid-term elections. With Trump's approval ratings already at record lows, and with Iran looking like a strategic error, the Republican party will almost certainly lose control of the House of Representatives and perhaps even the Senate. All those investigations that the Democrats have talked about wanting to launch into Trump administration actions could become reality next year. Democrats may be a bit cautious because some of the investigations they launched in the lead-up to the 2024 election backfired and let Trump generate support — or they may not. The federal government could pretty much shut down until the 2028 presidential election as Democrats and Republicans scream at each other. Meanwhile, issues that are important to the insurance industry, such as the fates of FEMA and the National Flood Insurance Plan, would be set aside.

My second biggest question relates to Taiwan. Might China decide that now is a good time to try to retake control of the island, with the U.S. looking weak and having used up so much of its weapons stockpile in Iran? What a catastrophe that would be for the whole global economy.

But now I'm getting really speculative. We'll have to wait and see how the secondary and tertiary effects unfold. For now, I really just wanted to note that I don't believe we'll have a clean resolution of the U.S.-Israel conflict with Iran and that we are likely going to be dealing with lingering effects for a long time.

Cheers,

Paul

 

Mobility Evolution Transforms Commercial Insurance

Autonomous and electric vehicles are shifting liability from drivers to manufacturers, reshaping commercial auto insurance underwriting's fundamentals.

Driverless Vehicle

The mobility landscape is evolving rapidly – once defined by individual vehicle ownership and predictable risk models, mobility now includes electric vehicle (EV) fleets, autonomous driving systems, shared mobility platforms and micromobility solutions. Driven by technological innovation, sustainability mandates and shifting consumer behavior, this transformation is reshaping transportation risk across industries and geographies.

For commercial insurers, these changes demand a rethink of traditional commercial auto insurance, spanning underwriting, pricing, liability allocation and risk management while increasing the need for data-driven decision-making.

Mobility Market Transformation

Modern mobility models are redefining how risk is created and transferred. Liability is shifting from human drivers to manufacturers, software developers, fleet operators, and platform providers. EV adoption is driving higher claim severity, while shared and usage-based mobility introduces fluctuating exposure that challenges static rating models.

Regulation is evolving alongside these market changes. States such as California, Arizona and Texas are establishing autonomous vehicle (AV)-specific operational and liability requirements, requiring insurers to adapt underwriting frameworks quickly to remain compliant and competitive.

Autonomous Vehicles: Fewer Crashes, More Complexity

Autonomous technology is moving from pilot programs to commercial deployment across logistics, delivery, and passenger transportation. According to a Goldman Sachs forecast, by 2040 autonomous liability and risk will shift to reduce the underlying cost per mile by over 50%, from $0.50 to $0.23.

We think that is more likely to underestimate, rather than overestimate, the cost reduction, and related societal benefits.

AVs are expected to deliver substantial safety improvements: Research from Deloitte found that human error causes 94% of crashes, while autonomous technology could reduce collisions by up to 90%. However, while AVs may lower collision frequency, they also introduce more complex loss scenarios when incidents occur.

In an AV accident, liability may rest with the vehicle manufacturer, software provider or fleet operator rather than the driver. This shift elevates the importance of product liability, technology errors and omissions (E&O) and contractual risk transfer. In California, commercial AV operations must hold $5 million liability per vehicle, signaling a long-term structural shift in commercial auto insurance.

Shared Mobility and Usage-Based Exposure

Shared mobility platforms, including ridesharing, carsharing and subscription fleets, scale rapidly, particularly in urban markets. These models generate highly variable exposure driven by multiple drivers, high usage rates and short-term vehicle use.

For insurers, shared mobility accelerates the move toward usage-based insurance (UBI) and telematics-driven pricing, enabling premiums to better align with real-world risk rather than fixed assumptions.

Electrification and Fleet Risk

Electrification is one of the most material forces reshaping commercial auto risk, with the IEA's Global EV Outlook 2025 underscoring the rapid growth in EV adoption.

According to published reports, EV fleets introduce higher average claim severity due to expensive battery systems, specialized repair requirements and longer repair cycles. Additional exposures include charging infrastructure liability, fire risk and business interruption related to extended downtime. EV fleets present opportunities for insurers to support environmental, social and governance (ESG) objectives through green underwriting incentives.

Micromobility and Last Mile Risk

Micromobility solutions such as e-scooters and e-bikes are increasingly used for last mile transportation and urban delivery. While they support congestion reduction and sustainability goals, they also create risk and new exposures and operate within inconsistent regulatory frameworks, particularly for commercial operators and municipalities.

These lightweight vehicles are redefining last mile connectivity. According to the Micro-Mobility Market Size, Share and Industry Growth Report 2025, the global micromobility market was valued at $63 billion in 2024 and is expected to grow to $162 billion by 2029.

KEY MOBILITY RISKS FOR COMMERCIAL INSURERS
  • Shifting liability from human drivers to original equipment manufacturers (OEMs), technology providers and platform providers
  • Higher EV repair costs and claim severity
  • Charging infrastructure and fleet hub property exposure
  • Regulatory uncertainty across jurisdictions
COMMERCIAL INSURANCE IN A NEW RISK LANDSCAPE

The mobility transformation creates significant opportunities for insurers:

  • Embedded Insurance Partnerships: Collaboration with OEMs, telematics providers and mobility platforms enables insurers to integrate coverage directly into fleet operations.
  • Usage-Based and EV-Specific Products: UBI and EV-focused coverage align pricing with exposure while addressing battery and infrastructure risk.
  • Advanced Analytics and Telematics: Artificial intelligence (AI)-driven underwriting and real-time monitoring improve pricing accuracy and loss prevention.
  • ESG-Aligned Insurance Solutions: Incentives tied to electrification and emissions reduction position insurers as sustainability partners, not just risk carriers.
MOBILITY TRENDS AND THEIR INSURANCE IMPACT
STRATEGIC CONSIDERATIONS FOR INSURERS

To remain competitive, commercial insurers should:

  • Invest in digital underwriting, telematics and AI
  • Develop flexible, modular underwriting models
  • Expand expertise in product liability and technology risk
  • Engage proactively with regulators
  • Build ecosystem partnerships across mobility value chains
INSURANCE AS AN ENABLER OF FUTURE MOBILITY

The evolution of mobility is redefining transportation and insurance. Electrification, autonomy, shared platforms and micromobility are reshaping liability, increasing loss severity in some segments and introducing new risk dimensions. They also offer insurers an opportunity to lead through innovation and collaboration.

Commercial insurers that embrace data-driven underwriting, embedded partnerships and sustainability-aligned solutions will move beyond traditional risk transfer to become enablers of the future mobility ecosystem. As mobility becomes a service, insurance must evolve with it to support safer, more sustainable transportation systems.


Jeff Huebner

Profile picture for user JeffHuebner

Jeff Huebner

Jeff Huebner is executive vice president of Mobilitas Insurance.

He has more than 30 years of insurance industry experience, including leadership roles in risk management, brokerage and insurance operations, and previously served as CSAA Insurance Group's chief risk officer.

Educating Clients on Summer Plumbing Risks

Vacant homes during summer travel face heightened water damage risk, positioning agents as trusted advisors through client guidance.

Pipe Leaks

Ah, summer vacation season. Your clients are eager to get theirs started. Did they pack their swimsuit, shorts and favorite tropical shirt? Check. Asked someone to pick up their mail and package deliveries? Check. Got all their toiletries and medicines? Check. But before they lock the door and leave the property, there's another item that should always be on their checklist.

After all, they might be heading to a sunny place near an ocean, river or lake, but when they return home, the last thing they want to discover is a flood in their living room.

Plumbing accidents can happen any time. Water damage claims cost U.S. insurers close to $13 billion annually, according to the National Association of Insurance Commissioners. Summer travel increases duration-of-loss risk and exposes those unfortunate gaps between assumed protection and actual protection. This is the time for agents to have conversations with clients about simple steps they can take to ensure peace of mind.

Vacant Homes Increase Risk

More than one million non-weather-related water damage claims are filed each year in the U.S., with average losses of around $15,400. In many cases, the issue isn't a major event. It's a small leak that goes unnoticed while no one is home.

Homeowners may associate burst pipes with winter, but the truth is that summer travel season creates its own perfect storm for water losses. Because of longer warm-weather trips, homes sit empty for extra days or weeks and small leaks become major claims before anyone notices. Non-weather water damage claims – cracked pipes, leaky appliances, slow drips – are highest in July and August when vacant homes are insufficiently monitored by travelers.

Smart Water Risk Prevention

While taking other pre-travel precautions, from fully charging doorbell camera batteries to making sure doors and windows are locked, only 22% of homeowners regularly shut off their water main before leaving for summer vacations.

More homeowners are installing smart water shutoff valves, Web-connected devices that learn a home's normal water patterns and cut the main line the moment something seems unusual, recognizing the difference between limited water usage for a shower and unlimited from a leak. These smart systems offer beneficial risk mitigation, whether a homeowner is at the grocery store for an hour or out of the house for weeks.

Insurers provide leak-detection credits for homes with smart water shutoff systems. But just having the technology isn't a secure safety net. As many as 30-50% of these systems are offline, disabled or improperly installed, rendering them unreliable or useless. Installation by itself doesn't equal protection.

Insurance Agents as Trusted Advisors

If technology alone isn't the answer, education is. Agents can help clients reduce loss exposure before a claim occurs, and that begins with regular communication. Prior to the summer travel season and the exposure of vacant homes, agents have the best opportunity to serve as trusted advisors discussing water risk mitigation with clients.

In person, over the phone, through email blasts or mailed guides, agents should be willing to discuss these key recommendations with homeowners:

  • Shut off the main water supply before extended travel, when practical
  • Know whether the main shutoff valve controls the full property and if it will turn off outdoor sprinkler and drip systems
  • Don't assume a leak detection system is functioning just because it's installed
  • Verify that smart water shutoff valves are online and have electricity, and periodically check their functionality
  • Check sensor batteries, Wi-Fi and notification settings before leaving town
  • Check appliance hoses, water heaters and older plumbing before peak travel season
  • Avoid leaving HVAC systems completely off in humid climates because moisture buildup can create secondary damage issues

Along with these tips, agents should also encourage homeowners to add emergency contacts to their monitoring systems, confirm that alerts go to the correct phone numbers and designate a nearby responder during long trips if an alert is triggered.

Beyond preventing property damage, these conversations reinforce agent/client relationships. Homeowners increasingly expect guidance from insurance professionals that goes beyond policy renewals and premium discussions. In a competitive market where consumers have many choices for coverage, trusted advice and practical expertise can strengthen retention, boost satisfaction and position agents as long-term partners in protecting homes. Something basic, like a seasonal checklist, keeps you top of mind for clients and helps them avoid costly disruptions and emotional stress.

Because a sunny vacation shouldn't be spoiled by returning home to a watery surprise.

Underwriting Needs Operating Models, Not Technology

Traditional insurers must rebuild their operating foundations before new technology can let them match the agility of MGAs and insurtechs.

Success

There's an urgent and slightly uncomfortable conversation happening across the insurance market right now. We talk a lot about growth, distribution, AI, data and digitization, but most of our operating models simply aren't built for the environment they're being asked to perform in.

This was the backdrop to Send’s recent INFUSE webinar, where we explored what it really means to move from a traditional, linear underwriting model to something fit for 2026. My view in one line: The challenge isn't innovation, it's whether our foundations can support it.

Brokers, MGAs and insurtechs are moving quickly. They're building smarter, more connected models, and in some cases, they're becoming more confident in their understanding of risk and pricing than the carriers behind them. Carriers haven't lost their edge, but there is a growing gap between what they have and what they can actually use. When your partners can ingest, process and act on data faster than you can, the balance starts to shift.

We're trying to make old models do new things

Many insurers are still running on legacy systems, fragmented data and manual workflows held together with spreadsheets. Trying to partner with more innovative businesses with that kit underneath you is a bit like putting Formula One parts onto the family car. In theory, it should make you faster. In reality, the underlying vehicle just isn't built for it.

What this is quietly doing to the data underneath doesn't get talked about enough. Carriers have always relied on their own book to set pricing, shape appetite and spot trends. As more of that book gets written by more advanced partners, the picture starts to erode. The partner is collecting richer, more granular data than the carrier ever did, but it doesn't plug neatly back into legacy systems. So, the carrier is left with two bad options: force new, unique data into systems that weren't designed for it, or hold underwriting discipline on a book they can only half see.

Meanwhile the boardroom conversation hasn't caught up. I still see leaders planning with the line, "we did well last year, so let's take that and add 10%," without really understanding how or why they got there. Managers are patting themselves on the back about the growth, while their underwriters are quietly wondering whether the wheels are about to come off. From the top floor it looks like a winning streak. From the underwriter's desk it looks like a book they can't quite see the edges of.

This isn't a technology problem. It's a trust problem.

Whenever the conversation turns to data, we default to the usual list of quality, consistency, standardization and validation. Those things matter, but for me the defining characteristic of good data is simpler. It's trust.

If an underwriter doesn't trust the data, they won't trust the outcome. And if they don't trust the outcome, they'll find a workaround. Spreadsheets sitting alongside core systems, manual overrides, parallel processes. Every one of those is a vote of no confidence in something that was meant to solve the problem.

We still talk about this as if it's a technology issue. It isn't. We know how to cleanse, enrich and validate data. The harder bit, and the one we keep ducking, is getting people to agree on what a data point actually means and how it should be used. That is where transformation programs stall. Not because the tools aren't good enough, but because the alignment isn't there.

Real change starts with asking better questions

We need to stop asking how to force people into the process and start asking why they're working around it. Those workarounds are telling us something. They point to gaps in trust, usability, clarity or alignment. If you don't understand the gap, no amount of new technology will close it in a lasting way.

You need the right driver, not just a better car

The firms moving fastest right now, particularly MGAs and newer entrants, don't just have better technology. They have a different mindset. They're entrepreneurial, closer to the customer, and they design their operating models around outcomes rather than internal constraints. They're still looking outwards.

You can give a business a Formula One car, but if the way it thinks and operates doesn't change, it won't deliver the performance you expect. Technology creates opportunities. It doesn't replace judgement, culture or customer understanding. You need both the right driver and the right vehicle. One without the other is either dangerous or going nowhere.

Looking ahead

I'm often asked where the market will be in three to five years. What I can say is that the organizations winning right now, in insurance and well beyond it, are the ones built around their customers. Netflix, Starling, Octopus Energy. They design around the customer first, and they run small, deliberate experiments so they can respond when things change. They don't bolt new technology onto broken processes and hope for the best.

Insurance isn't there yet. We know we're going to adopt better technology. The real question is whether we can build the operating models, data foundations and trust to actually use it. If we don't, we're just making the same car go a bit faster. And that won't be enough for what's coming next.


Emma Davies

Profile picture for user EmmaDavies

Emma Davies

Emma Davies is the founder of Waystone Consulting.

She brings 25 years of hands-on experience in financial services working for the likes of QBE, Chubb, RSA and AXA as an underwriter, portfolio manager and broker. 

AI Security Risks Challenge Cyber Insurers

As AI adoption outpaces security practices, insurers face a new cyber risk category with concentrated exposures and long-tail claim potential.

Cyber Security

A March 2026 security incident involving a tool widely used by developers to purportedly connect applications to large language models marks one of the first large-scale cyber incidents targeting the emerging artificial intelligence (AI) development stack.

For the insurance industry, this incident may be a warning that AI infrastructure risk is rapidly becoming an insurable reality.

AI is increasingly spawning a complicated ecosystem. New AI frameworks, open-source libraries and orchestration tools are drawing organizations into complex third-party supply chains that even they — and their insurers — don't yet fully understand.

Even without this full understanding, many organizations are racing to deploy AI capabilities, often faster than their security practices can manage. As AI adoption accelerates, so may a new category of cyber risk that insurers will be increasingly asked to absorb.

A New Layer in the Digital Supply Chain

The software supply chain is already complex. Now, AI is adding another layer to the complexity.

Modern AI deployments rarely rely on a single platform or vendor. Instead, organizations build applications by combining multiple frameworks, libraries, skills, tools and cloud services. This layered architecture is referred to as the "AI development stack." Tools like the one targeted in the recent incident are designed to serve as a connective tissue. They need access to sensitive data to be useful.

This can introduce risk that's concentrated and exponential. If malicious code is introduced at the top of the stack, it not only exposes the sensitive data within the application but also cascades downstream into potentially upwards of thousands of environments.

Many organizations don't have proper visibility into every component embedded in their AI environments.

For underwriting, this represents a blind spot and rapidly escalating risk. Traditional cyber risk questionnaires don't yet capture the nuances of developing AI stacks, and yet these components now house highly sensitive data and credentials. Beyond attestation, many carriers are not yet ready to require and review evidence of agentic AI oversight and security.

The cyber insurance industry has seen the effects of these supply chain risk dynamics before. What makes the AI stack risk different is the speed of adoption.

Shorting Cybersecurity Basics and Long-Tail Claims

In the rush to integrate AI functionality, some organizations may leave behind basic foundations of security. Automatic software updates are a prime example.

That's what foiled the organizations affected by the March incident. Though the malicious version of the software was only available for a few hours, many systems automatically adopted the new release without a security review. The attackers used an aggressive tactic to trigger the malicious code the moment a system automatically downloaded the update.

Even if an organization took steps to avoid automatic downloads, they could still be compromised if they used another tool that pulled in the malicious software automatically.

The affected software reportedly has millions of daily downloads. Even if a fraction of organizations were affected, attackers still may have gained unauthorized access to thousands or even hundreds of thousands of systems.

Each compromise may represent a potential long-tail claim scenario, in part due to credential management issues — another "cybersecurity basic" that's rapidly becoming more complex. AI applications frequently require access to multiple services, making them valuable targets for threat actors.

When attackers obtain access keys or API tokens, they can move more quietly through cloud environments, often escalating privileges and quietly exfiltrating data.

Because these activities may unfold gradually, the full impact of the resulting claims can emerge over months or even years. Organizations may first discover suspicious activity in one system, only to later uncover deeper compromises across multiple environments.

For insurers, this dynamic introduces uncertainty around the size and scope of potential claims.

Rising Demand for Incident Response and Forensics

Insurers should anticipate increased demand for forensic investigation and breach response services. As soon as an insured becomes aware of even a potential AI stack compromise, they need answers to critical questions:

  • Were automated updates enabled?
  • Were affected versions deployed?
  • Has there been unusual activity from your AI agents?
  • Were credentials exposed or exfiltrated?
  • Are there signs of data exfiltration?

Answering these questions requires specialized technical expertise, and even organizations with strong internal security teams often need external help. Insurers maintaining robust cyber partner networks can offer incident response services, forensic investigations, breach response coordination, and monitoring and mitigation strategies, and therefore, will be better positioned to support policyholders.

These capabilities are becoming central to the value proposition of cyber insurance. Beyond financial reimbursement, organizations facing emerging AI threats need expertise and coordinated response to properly assess and contain damage.

Immediate Steps for Insurers and Brokers

The recent AI supply chain attack offers a preview of what may come. It raises a central question for insurers of how policyholders are adopting AI technologies.

One immediate step insurers can take is vendor triangulation. Work with policyholders to identify whether they rely on AI development tools that may introduce new supply chain dependencies. Understanding these relationships can help assess potential systemic exposures and concentrated risks.

Now is also the time to begin incorporating AI-specific inquiries into underwriting processes. New considerations should include:

  • What AI and orchestration tools are being used?
  • How are software updates vetted and implemented?
  • How are credentials and API security managed?
  • How is the organization monitoring for cloud security threats?
  • Does the organization have incident response capabilities specific to AI infrastructure?
  • How is the organization analyzing in real-time what their AI agents are doing and if they are properly credentialed?

AI is likely to remain a transformative force across industries. As its adoption accelerates, these questions will become increasingly relevant to making sure underwriting assumptions reflect the evolving threat landscape.

How to Detect Early Financial Stress

Insurers need to monitor the financial health of all those they interact with, and payments data can now provide continuous updates.

Financial Health

Insurance finance leaders spend considerable effort assessing the financial health of the counterparties they depend on: reinsurers, brokers, MGAs, large commercial clients. Most of that assessment draws on periodic data: annual accounts, credit scores, ratings. What it rarely draws on is how those same counterparties actually behave when an invoice falls due. That behavioral layer exists, it updates continuously, and for the most part it goes unread.

Every accounts receivable team can see how its own customers pay. Almost none can see how those same customers pay everyone else. That asymmetry is the part of the conversation about payment behavior that tends to get skipped, and it is the part that matters most. A single supplier's ledger shows what is happening inside one relationship. Understanding whether that behavior is isolated or part of a wider pattern requires a network-level view. That view has existed for over a decade, built from the aggregated payment experience of millions of buyer-supplier relationships. Most finance teams are still not using it.

Across global invoice data, one figure stands out: 37% of the days-to-pay cycle now occurs after the contractual due date. That is not marginal slippage. It is a structural feature of how credit operates in 2026, and it is the kind of finding no individual enterprise can produce from its own data, however large its book.

Contractual terms describe an agreement. Payment behavior describes the execution. The gap between the two has become large and persistent enough to be read as its own variable, and unlike most inputs that feed periodic financial assessment, it refreshes continuously.

The Terms-to-Behavior Gap

Globally, businesses took an average of 51 days to be paid in 2025: 32 days of contractual terms plus 19 days of delay. The global average matters less than the distribution underneath it. The Netherlands sits near 40 days end-to-end, with only 12 days of delay. India runs to 77 days, with 43 days of delay on top of agreed terms. Two trading partners on similar terms can produce very different cash realities depending on geography, sector discipline, and the operational maturity of the supplier chasing the invoice.

The sector picture is pointed. In the United States, financial services, insurance, and real estate average 57 days-to-pay, with 27 days of delay, among the slowest of any sector in the data. For insurance finance teams, that figure cuts both ways. It describes how the sector pays, and how the sector's counterparties tend to pay. Anyone extending credit, managing broker settlements, or carrying reinsurance receivables within that ecosystem should know where their sector sits and what movement away from that norm looks like.

When Deterioration Looks Sudden But Isn't

Consider a scenario familiar to anyone who has worked a collections book. A buyer's average payment delay stretches from 18 to 30 days across two quarters. The promise-to-pay rate softens. Disputes take longer to resolve. Approvals route through additional layers. Six months later, the relationship is in serious trouble, described internally and externally as sudden.

From the outside, it appeared sudden. Inside the payment ledger, the drift had been measurable for months. Promised dates slip, partial payments creep in, the rhythm of communication shifts. None of it is dramatic on any given day. All of it is observable in aggregate.

Insurance finance teams understand this dynamic in their own reserving cycles: the loss was developing long before it was recognized. Payment behavior follows the same logic. The deterioration is rarely sudden. The visibility of it often is.

Where the Argument Breaks

None of this means payment delay is proof of distress. It very often isn't. Slow payment can reflect approval bottlenecks, ERP changeovers, dispute backlogs, or simply the prevailing discipline of a sector. Read in isolation, the signal generates false positives, and false positives at scale produce worse decisions, not better ones.

Behavioral payment data is useful precisely because it is contextual. Sector, geography, counterparty history, and the rhythm of a specific relationship all matter. Volume without interpretation is noise.

Cadence Is the Real Gap

Most financial assessment processes operate periodically. Payment behavior changes continuously. That gap is where deterioration goes unnoticed.

A supplier can observe that a counterparty is paying more slowly than last quarter. It cannot see whether that same counterparty is paying more slowly across all its relationships, or whether the slowdown is specific to one trading relationship. Those are very different situations, and the data to distinguish them does not exist inside any single company's ledger. It exists at the network level, across the aggregated payment experience of millions of buyer-supplier relationships.

For insurance finance teams managing exposure across brokers, reinsurers, and large commercial accounts, that distinction matters directly. A counterparty paying slowly because of an internal processing issue is a different proposition from one paying slowly everywhere it trades. The former is operational friction. The latter is worth understanding earlier.

The question is not whether this data exists. It does, at scale, and it updates continuously. The question is whether payment behavior is being read as a live operational signal or treated as a byproduct of the collections process. For most organizations today, it is still the latter.