Download

AI Systems Reshape Cyber Insurance Risk

AI-driven discovery of software vulnerabilities at machine speed challenges cyber underwriting models designed for environments where threats evolved gradually.

Cyber Risk

For years, cyber insurance discussions focused on ransomware, phishing, social engineering, and data breaches. The assumption underneath most underwriting models was relatively consistent: cyber events, while serious, would still unfold within human and operational constraints.

That assumption may be starting to change.

Recent discussions surrounding Anthropic's Claude Mythos and related frontier AI cybersecurity systems are beginning to raise a different concern across financial institutions, regulators, and cyber markets: what happens when vulnerability discovery and exploitation start operating at machine speed instead of human speed?

The concern is not theoretical anymore. Regulators, central banks, and major financial institutions have already begun discussing the potential systemic implications of AI systems capable of autonomously identifying and chaining software vulnerabilities at unprecedented scale and speed.

For the property and casualty insurance industry, this matters far beyond cybersecurity headlines.

A Different Kind of Cyber Risk

Traditional cyber underwriting was largely built around environments where threats evolved incrementally. Vulnerabilities were discovered gradually. Patches were released over time. Organizations generally had some opportunity to respond before exploitation became widespread. Frontier AI compresses those timelines.

Systems like Mythos reportedly demonstrate the ability to identify unknown vulnerabilities across software environments far faster than traditional human-led security processes.

That changes the shape of cyber exposure itself. The larger issue is not simply that attacks may become more sophisticated. It is that cyber risk may become increasingly correlated across interconnected systems and infrastructure dependencies.

Many commercial insureds already rely on shared cloud environments, software providers, managed service vendors, and common technology stacks. A single vulnerability tied to a widely used dependency can already create accumulation concerns for cyber carriers. AI-driven vulnerability discovery could intensify that problem significantly.

What previously unfolded over weeks or months may eventually unfold over hours.

Where Insurance Models Begin to Struggle

Most commercial insurance underwriting still operates through periodic snapshots of risk.

Applications are completed annually. Supplemental questionnaires capture point-in-time controls. Cyber posture is often evaluated during renewal cycles rather than continuously. But AI-driven cyber environments may not evolve on annual timelines anymore.

A company's attack surface can shift rapidly through vendor integrations, software dependencies, cloud architecture changes, and emerging vulnerabilities. If offensive capabilities accelerate faster than underwriting visibility, insurers may find themselves evaluating cyber risk using processes designed for a slower environment. That creates a growing mismatch between underwriting cadence and risk evolution.

This is part of what makes systemic cyber risk different from traditional independent-loss assumptions. One exploit path, one software dependency, or one infrastructure weakness could potentially affect thousands of organizations simultaneously across a carrier's portfolio.

For insurers, the concern increasingly becomes portfolio interconnectedness rather than isolated policyholder events.

What the Industry May Need to Rethink

The industry has spent years modernizing workflows, digitizing underwriting, and improving operational efficiency. But AI-driven cyber environments may require something deeper than workflow modernization alone.

They may require continuous visibility into changing infrastructure risk. That could gradually push cyber underwriting toward:

  • more dynamic monitoring
  • stronger software dependency mapping
  • infrastructure-aware accumulation modeling and
  • underwriting approaches tied more closely to telemetry and operational signals rather than static questionnaires alone.

At the same time, insurers themselves may become part of the exposure story. Many carriers operate on layered technology environments built over decades through acquisitions, vendor integrations, and legacy infrastructure. Advanced AI systems capable of identifying weak links across interconnected systems could expose vulnerabilities not only within insured organizations, but within the insurance ecosystem itself.

Therefore, conversations around systems like Mythos are drawing attention from regulators and financial stability groups—not simply because of cybersecurity, but because of the potential for correlated operational disruption across interconnected industries.

The broader issue is not whether AI will improve cyber operations.

It almost certainly will.

The deeper question is whether insurance systems can adapt to environments where cyber risk evolves faster than traditional underwriting and portfolio management structures were originally designed to handle. That may become one of the defining insurance challenges of the AI era.

The Hidden Problem With Commercial Trucking Claims

Routing commercial trucking claims through general adjusting operations costs carriers millions in preventable loss ratio leakage that specialty programs consistently avoid.

Tractor Trailer Driving on a Road

Commercial auto rates have been climbing. Every market participant knows this. The standard explanation involves nuclear verdicts, social inflation, and litigation funding. Those factors are real.

What gets less discussion is the operational side of the loss equation. Not the litigation. Not the verdict environment. The claims management practices that run between first notice of loss and final settlement, and what those practices cost on a book-level basis when commercial trucking is handled like any other commercial auto line.

It's a different animal. The industry broadly acknowledges this. But acknowledgment hasn't produced widespread changes in how these claims get handled.

The Supplement Rate as a Performance Indicator

Supplement rates on commercial trucking and heavy equipment claims average between 20% and 25% industry-wide. A supplement is a revised repair estimate — the initial figure gets approved, disassembly begins, and the shop returns with a higher number.

A 20% to 25% rate tells you something specific. It tells you the first estimate was wrong at a high frequency. That frequency isn't random. It reflects a systematic gap between the complexity of the equipment being assessed and the expertise of the person writing the first estimate.

A general auto adjuster reassigned to a Class 8 truck or a piece of construction equipment doesn't know what to look for. A specialist does. The operations using appraisers with dedicated heavy equipment expertise consistently hold supplement rates between 10% and 14%. That 10-point gap on a large commercial trucking book represents a material dollars-and-cents difference in indemnity spending. It shows up directly in loss ratios.

Most program administrators and MGA executives can't tell you their supplement rate on trucking claims.

Towing and Storage as Indemnity Leakage

Towing and storage on commercial vehicles is a significant and largely unmanaged cost category on most trucking programs. Storage fees of $125 to $200 per day accrue from the moment a vehicle is taken to a yard. Claims that sit unworked for 30 to 60 days generate thousands in storage exposure before a single repair decision is made.

The towing invoice itself is a second problem. Inflated mileage, charges for equipment that was dispatched but not deployed, fees for services not rendered. These line items go on the invoice and, in most cases, get paid without challenge because the adjusting operation doesn't have the market knowledge to identify what a reasonable commercial tow should cost.

One carrier reviewing its annual towing spending found it had overpaid by more than $650,000 in a single year. That's not an outlier. That's what happens when commercial vehicle towing invoices go through a general claims operation that doesn't specialize in this exposure.

On a book of any meaningful size, towing and storage leakage is a line item that belongs in loss ratio conversations. It rarely appears there because nobody is measuring it separately.

Subrogation Recovery as Underpriced Leverage

Commercial trucking subrogation is a specialty within a specialty. The values are high, liability is typically contested, and the file has to be built correctly from day one of the incident. When it is, win rates above 80% are achievable on eligible files.

Most general TPA operations don't run dedicated commercial trucking subrogation programs. The case complexity is high relative to the volume they handle in that category. Recovery rates on trucking subrogation through general programs reflect that mismatch.

For MGAs and program administrators with meaningful trucking exposure, subrogation recovery represents a straightforward improvement to the economics of the book. It doesn't require renegotiating terms. It requires routing eligible files to a team that knows what it's doing with them.

What the 2026 Claims Conversation Is Missing

The industry's attention in 2026 is rightly focused on AI-assisted claims processing, faster FNOL response, and data-driven loss analytics. The consensus view entering 2026 was that commercial auto rates would continue rising while claims automation would begin generating measurable efficiency gains. That framing is correct as far as it goes.

What it misses is that technology-assisted claims handling applied to a general adjusting model doesn't solve the expertise problem on specialized equipment. A faster general adjuster writing estimates on a crane or a loaded semi is still a general adjuster writing estimates on a crane or a loaded semi. Speed doesn't compensate for the knowledge gap that produces 22% supplement rates.

The gap between strategic intent and claims execution is where loss ratios on commercial trucking programs get made or broken. The intent to manage this exposure well is almost universal. The execution requires domain expertise that most general operations don't have and can't develop at a sufficient depth for an exposure this specialized.

The Program Design Question

For MGAs building or managing commercial trucking programs, the TPA selection question deserves the same analytical rigor as rate adequacy or reinsurance structure. The right question isn't which TPA can handle the claims. It's which TPA has the specific expertise to handle these claims at the supplement rates, towing spending, and subrogation recovery rates that a profitable book requires.

The specialty exists because general operations don't produce the outcomes this exposure demands.

The performance data from specialty operations — the supplement rates, towing savings, subrogation win rates — is publicly available for comparison. The loss ratio improvement potential is real and measurable. The question is whether program design conversations are treating claims expertise as a first-order variable or an afterthought.

For most trucking programs, it's still the latter.

Other Resources From Insurance Thought Leadership
  1. "Insurance 2026: Progress Via Technology, Collaboration" (Jan. 8, 2026): "The consensus view entering 2026 was that commercial auto rates would continue rising while claims automation would begin generating measurable efficiency gains."
  2. "4 Key Trends Reshaping P&C Insurance" (Feb. 5, 2026): "The gap between strategic intent and claims execution"

Adam Zuccato

Profile picture for user AdamZuccato

Adam Zuccato

Adam Zuccato is chief revenue officer at Veritas Claims.

Operating across all 50 states, Veritas handles appraisals, towing and storage resolution, subrogation, freight and cargo claims, and full TPA services for carriers, MGAs, and program administrators.

Reinventing Pricing in P&C Insurance

Despite technology advances, many insurers still price risk with spreadsheets while fast, agile competitors deploy sophisticated pricing engines.

Dollar Signs

In today's P&C insurance market, profitability no longer depends solely on underwriting discipline or claims management. Increasingly, it hinges on how effectively and how quickly insurers can price risk. With margins under pressure from inflation, rising claims severity, and climate-driven catastrophe losses, insurers are increasingly compelled to modernize the pricing function.

And yet, despite the critical role pricing plays and advances in technology, many insurers still manage it with the same spreadsheets and disconnected workflows they relied on 20 years ago. While core systems and claims have seen modernization efforts, pricing remains a new frontier for digital transformation.

Pricing as a Strategic Lever

The pressures reshaping the market are forcing insurers to treat pricing as more than an actuarial exercise. It has become central to profitability, where even small missteps in rates can quickly multiply across entire portfolios. It is equally critical to competitiveness, as more agile rivals can undercut static carriers, particularly in commoditized personal lines. And it is now inseparable from customer experience, with policyholders demanding personalized, transparent pricing that reflects their usage, geography, and unique conditions.

Boardrooms are starting to discuss pricing in the same way they discuss claims, distribution, and customer experience. The realization is simple: Pricing has shifted from a back-office function to a frontline driver affecting business strategy and success.

Pricing Solutions Driving the Future

Increasingly, insurers are turning to dedicated pricing engines, platforms that centralize pricing logic, enforce governance, and accelerate deployment. Unlike spreadsheets or legacy raters, these systems provide:

  • A single source of truth for all rating and pricing logic and assumptions
  • Auditability and governance to ensure regulatory compliance.
  • Integration with external data for more granular pricing.
  • Automation and APIs that connect pricing directly to core systems and distribution channels.

Vendors such as Earnix, hyperexponential, Akur8, Quantee, and Radar are redefining what insurers can expect from their pricing capabilities:

  • Earnix focuses on multi-line insurers, offering strong capabilities for SME and standardized products. It includes built-in predictive modeling and statistical tools, supports model migration, and provides pre-built connectors for major policy administration systems such as Guidewire. Earnix has also developed a wide range of AI-driven capabilities within its platform.
  • Hyperexponential (hx Renew) is a strong fit for insurance pricing operations where actuarial models need to be operationalized for underwriting teams. hx Renew does not provide built-in predictive modeling capabilities and is typically positioned more as a model execution and decisioning platform than a full machine learning development environment, with advanced modeling usually performed externally. Python is a core component of the hx platform, with most processes, workflows, model logic, and integrations configured using Python, providing a high level of flexibility and customization.
  • Akur8 was initially developed as a modeling-focused solution. It has a strong emphasis on predictive modeling capabilities, providing AI-powered tools that allow actuaries to build statistical models quickly while retaining the ability to inspect, adjust, and refine them as needed. The platform supports the pricing lifecycle from risk model development to pure premium aggregation and rating plan definition. It has also expanded into integration and deployment areas, including its own pricing engine and the ability to integrate with existing legacy systems.
  • Quantee is focused on the end-to-end pricing lifecycle, including predictive modeling, what-if analysis, testing, documentation, and integration. The platform supports the independent work of pricing teams and provides a stable environment for core pricing processes, along with a range of additional AI and advanced modeling features. Following its acquisition by Guidewire, the platform is expected to become more deeply integrated into the Guidewire ecosystem, enabling a more streamlined integration approach. As integration with the Guidewire ecosystem evolves, elements such as proration, cost breakdown structures, and operational process management may become more streamlined and centralized.
  • Radar (by WTW) offers a comprehensive suite of pricing and underwriting tools covering the entire insurance pricing process. Its modular platform includes Radar Base for tariff setup, Radar Live for integration with point-of-sale systems, and Emblem for rapid predictive modeling on large datasets, along with several other specialized tools. Radar enables actuaries to build, test, and optimize pricing models with real-time portfolio insights.

While their approaches differ, the common thread is clear: Pricing engines enable insurers to move at market speed with more control, accuracy, and transparency.

Five Strategic Advantages of Modern Pricing Solutions

The business impact of modern pricing goes far beyond operational efficiency. Insurers that deploy dedicated pricing engines can:

  1. Improve profitability through better segmentation and more precise risk adjustment.
  2. Accelerate speed-to-market for new products, endorsements, and rate changes.
  3. Enhance customer experience by offering personalized, transparent pricing aligned with expectations.
  4. Enable innovation and product flexibility by testing new pricing models, micro-products, and bundles without overhauling core systems.
  5. Strengthen regulatory readiness and compliance with built-in governance, transparency, and audit trails.
Capturing Advantage Through Modern Pricing

Modernizing pricing is not without hurdles. Legacy system dependencies, fragmented data structures, and organizational silos can slow progress, and actuaries and IT teams often struggle to align on ownership. Yet these challenges are surmountable, especially when insurers work with the right consulting partner and pricing solution.

Successful transformations are built on clear business alignment, executive sponsorship, and phased rollouts that deliver quick wins.

Looking ahead, the pricing function will evolve beyond faster rate changes and centralized governance. The next generation of pricing will harness AI, behavioral analytics, and real-time data streams to create adaptive models that continuously evolve with market conditions. At the same time, regulatory scrutiny will intensify. Fairness, transparency, and explainability will become mandatory, not optional. Insurers that can demonstrate accountability and governance in their pricing processes will not only earn regulatory approval but also build customer trust.

Modern insurance pricing is about improving how risk is measured and priced, with greater accuracy, speed, and transparency. In a volatile and changing market, the ability to price with agility, precision, and auditability will be a difference-maker and separate the leaders from the laggards.

AI Explainability Becomes Key for Insurance Claims

In claims, AI explainability has evolved from a technical concern to a business imperative for governance, compliance, and trust.

Colorful Lines

In a recent interview, Steve Hasker, chief executive of Thomson Reuters, said that in fiduciary professions like law, tax, audit, and compliance, what matters is not just speed but whether the output is authoritative, traceable, and accountable to professional standards. The same applies to insurance claims.

For a while, much of the conversation around AI focused on efficiency. Could it help insurers process claims faster? Could it reduce manual work? Could it improve consistency? Those are still important questions. But they are no longer the only ones that matter. The harder question now is whether the decisions AI helps shape can be understood, defended, and trusted.

This matters even more in claims, where a decision is rarely truly final when it is first made. It may be questioned by the policyholder, examined by regulators, revisited in an audit, or challenged in court. Under that kind of scrutiny, a system cannot just give an answer. It also needs to make clear how it reached that conclusion.

This is why explainability has moved from a mere technical concern to a business requirement. Explainability now sits at the center of governance, compliance, and customer trust. The broader market is also moving beyond initial excitement about what AI can do in theory and toward a more practical question: What does it take to use it responsibly in real operations? A recent Gartner report points to the same trend, highlighting governance, data readiness, and operational discipline as the factors that will separate early excitement from lasting value.

In claims, explainability is where that shift becomes real.

AI Does Not Change the Insurer's Responsibility

AI may be changing how work gets done, but it does not change the insurer's underlying obligations. Claims laws, consumer protections, and standards for fair treatment still apply, whether a decision is made by a person, a model, or a third-party vendor. If a claim is denied, delayed, escalated, or flagged for possible fraud, the carrier is still responsible for being able to explain why.

This is becoming even more important as regulators pay closer attention to how AI is used in insurance. In Europe, the EU AI Act raises the bar for transparency, explainability, and human oversight in high-risk uses of AI. In the United States, the regulatory picture is less uniform, but the direction is similar: insurers are increasingly expected to show that AI-supported decisions are fair, accountable, and subject to oversight.

For claims leaders, the takeaway is simple. The issue is no longer whether AI is allowed in claims. The issue is whether the carrier can stand behind the decisions it helps produce.

The Real Divide Is Not Who Uses AI

Across property and casualty insurance, the appeal of AI is easy to understand. Carriers want to improve consistency, reduce handling costs, and help claims professionals manage growing complexity. Used prudently, AI can support all of these goals.

But the real divide in claims is no longer between insurers that use AI and insurers that do not. It is between systems that produce outputs and systems that produce decisions the business can actually explain and defend. This difference matters because a decision made today can come back months or years later in a complaint, an audit, or a lawsuit. A recommendation that looks efficient in the moment can become a serious problem later if no one can clearly explain why it was made.

This is where black-box neural network systems begin to create friction. Models built for speed and prediction may perform well in testing, but if their reasoning cannot be understood in plain terms, every downstream review becomes harder. Claims teams are left trying to reconstruct logic after the fact from technical outputs or vendor explanations. By then the problem is no longer just technological; it becomes operational, legal, and reputational.

Why Explainability Cannot Be Added Later

One of the most common misperceptions among carriers is that explainability can be dealt with later, after a model is already in production and the business value has been proven. In practice, that is far more costly than it sounds.

Once a claims process is built around systems that do not make their reasoning easy to follow, real transparency is difficult to add later. You can layer on reports, write summaries with LLMs, or use tools such as SHAP values to suggest which factors may have shaped the outcome, but these are still only approximations. They are not the same as being able to see the path to the decision from the beginning.

In the real world, repair costs change, fraud tactics evolve, and what counts as normal in one region may not hold in another. These shifts can easily affect a black-box AI system, and the problem is often hard to see until real harm has already been done. By then, it may appear as a rise in customer complaints or as questions from a regulator about why similar claims are being handled differently.

The Gartner report makes much the same point in broader terms. The companies most likely to get lasting value from AI are the ones that build the right structure around it: good data, clear accountability, and controls that remain dependable over time. In claims, explainability is part of that structure. It is not something you can add later. It has to be there from the beginning.

The Problem Often Starts with the Data

Explainability is often talked about as if it lives only inside the model. In reality, it depends just as much on the data feeding the system.

A claims system cannot produce trustworthy reasoning if the underlying data is incomplete, poorly structured, weakly governed, or disconnected from the market where it is being used. If the inputs are flawed, the explanation may sound polished while still hiding the real problem. A carrier may think it has a well-controlled system, but if claim data varies widely across geographies, repair networks, documentation practices, or policy types, the system can still produce unstable or unfair outcomes.

Explainability helps bring those problems to the surface. It gives the business a way to spot when the model is leaning too heavily on the wrong signals, when patterns do not fit local conditions, or when assumptions that made sense in one setting are being carried into another where they no longer belong.

This was illustrated in an auto claims fraud model deployed in a Middle Eastern country. The legacy model consistently flagged accidents occurring after midnight on weekends as high risk. That logic had been inherited from North American and European training data, where late-night weekend accidents often correlate with alcohol-impaired driving. But in the market where the model was being used, alcohol consumption was prohibited and families commonly stayed out late on weekends. The signal was not just weak; it was systematically wrong. Because the reasoning behind the model's behavior was not visible in a usable way, the problem went unnoticed until it showed up in regulatory scrutiny and customer dissatisfaction.

What Explainability Should Look Like in Practice

The first question claims leaders should ask about any system influencing claim outcomes is not just whether it is accurate. It is whether the people responsible for the claim can understand the reasoning well enough to use it responsibly.

If a claim is delayed, escalated, denied, or flagged for possible fraud, the adjuster should be able to see the factors driving that result in language that makes sense in the context of the claim. That could include missing documents, timing issues, policy conditions, behavioral patterns, or other relevant signals. The point is not that every decision becomes simple. The point is that the reasoning should be visible enough for the business to evaluate it.

Just as importantly, the adjuster should be able to challenge the recommendation when it does not fit the facts. Human oversight only means something if the person reviewing the claim can see why the system is pointing in a certain direction and can document a reasonable override when needed. Otherwise, "human in the loop" becomes little more than a formality.

Good explainability also helps the organization over time see when outcomes are drifting, when similar claims are being treated differently, or when a signal that once seemed useful is starting to distort results. In that sense, explainability is not just about answering questions after a problem appears; it is also about spotting problems early enough to do something about them.

A Practical Test for Claims Leaders

For claims executives, the best way to judge whether a system is ready is to ask a few simple questions.

Can we explain how this AI-generated recommendation was produced?

Can we trace the data and reasoning behind it without relying on a technical team to rebuild it from scratch?

Can we show that similar claims are being treated consistently?

Can we detect when the AI model's behavior starts to shift?

Can an adjuster disagree with the AI-generated recommendation and explain why in a credible way?

These are not abstract governance questions, rather practical tests of whether the AI model can survive real-world scrutiny.

The Choice Facing Claims Leaders

Claims leaders now face a much clearer choice than many realize.

The question is no longer whether AI can improve speed, support triage, or strengthen fraud detection. In many cases, it can. The real question is whether insurers are building those capabilities on foundations strong enough to hold up when the decision is reviewed, challenged, or questioned later.

That is why explainability matters so much now. It is not just a safeguard for compliance teams, but also the practical link between AI and accountability. It connects decisions to oversight by helping expose weak data, hidden bias, and changing patterns before they become bigger problems.

The wider business conversation is moving in the same direction. As the early excitement around AI gives way to a more realistic view, companies are becoming clearer about what lasting value actually requires. The real issue is no longer just what AI can do, but whether it can be trusted, governed, and used responsibly over time. In claims, explainability is where that becomes visible in everyday decisions.


Amer Kayani

Profile picture for user AmerKayani

Amer Kayani

Amer Kayani is co-founder and CEO of TAO Trees, an AI-driven firm focused on detecting motor insurance fraud. 

Previously, he was the CEO of Northrop Grumman's joint venture in Saudi Arabia.

Insurance Built a Model for the Wrong Kind of Natural Disaster

With secondary perils accounting for 92% of losses, traditional catastrophe reinsurance architecture is fundamentally misaligned with modern risk.

Frightening Sky

Consider what 2025 demonstrated about the insurance industry's risk assumptions. No major hurricane made landfall in the United States. By the logic of traditional catastrophe modeling, which has always placed tropical cyclones at the center of loss scenarios, 2025 should have been a manageable year. Instead, global insured losses hit $107 billion. 

Secondary perils that catastrophe models have historically treated as background noise, including wildfires, severe convective storms and floods, accounted for a record 92% of that total, up from a 56% average over the prior decade. Severe convective storms alone delivered their third-costliest year on record.

The industry did not have the wrong year. It has the wrong product architecture.

The secondary perils mismatch hiding in plain sight

For decades, catastrophe reinsurance was built around a defensible logic: The events that would truly threaten the balance sheet were episodic, high-severity, well-modeled primaries, like a Category 5 hurricane or major earthquake. Secondary perils existed, but they were attritional, manageable, and amenable to the law of large numbers. That assumption is no longer valid. Secondary perils such as hailstorms, flash floods, wildfires, severe thunderstorms, and freezing events, produced $136 billion in total losses in 2024, well above their ten-year inflation-adjusted average of $110 billion.

The more important question is not why secondary perils are growing, but why, after a decade of this data, the market has not produced instruments adequate to transfer the risk. The answer is structural, and it is uncomfortable: The institutions with the capital and sophistication to absorb the frequency of secondary peril risk have rationally opted not to.

After 2022 and 2023 - years of punishing secondary peril losses - reinsurers raised attachment points sharply. Reinsurers redesigned their treaties to keep secondary peril frequency off their books. That was a rational response for their balance sheets, but it created a structural vacuum. Hailstorms, flash floods, wildfires, freeze events mark losses that aggregate across a portfolio but never reach a single-event treaty threshold. They now sit almost entirely on primary carriers, who lack the capital efficiency to hold them and are responding the only way their product architecture allows: raising premiums, tightening underwriting, and in some markets, leaving altogether.

What carriers' market exits actually signal

The consequences of this structural mismatch are accumulating in observable ways. In California, standard carriers have non-renewed more than 1 million wildfire-exposed policies since 2018. The California FAIR Plan, the state's insurer of last resort, grew from around 200,000 policies in 2020 to more than 450,000 by late 2024, a 123% increase driven almost entirely by wildfire-related withdrawals from the standard market. Nationally, approximately one in seven owner-occupied homes is now uninsured, a figure that jumped more than 6% between 2023 and 2024 alone as rising premiums priced households out of coverage. The E&S market has absorbed the spillover, reaching $86 billion in direct premiums in 2023, growing for a fifth consecutive year. But E&S is a pressure valve, not a solution. And 70% of residential flood losses go uninsured annually in the United States, representing roughly $17 billion in losses absorbed by households and taxpayers each year.

The instinct is to read this as a pricing problem: If the industry just charges enough, it will re-enter. But that logic misses the target. Premium increases are not restoring market access. They are accelerating the concentration of risk in residual markets that are structurally worse at absorbing it than the private market they replaced. Market exit is not a correction mechanism. It is the protection gap widening in real time, underwritten by public balance sheets that were never designed for the purpose.

Closing the gap between the trigger event and the realized loss

Traditional indemnity insurance requires an adjuster, a loss assessment, and a claims process calibrated to a world where individual events are large, distinct and infrequent. That workflow is expensive even when functioning correctly, and it was never designed to handle the accumulation of dozens of mid-severity events per year across a portfolio. Parametric structures remove that friction entirely. A defined trigger, such as hail accumulation exceeding a threshold, wildfire perimeter within a defined radius, flood depth at a gauge station, or freeze degree-days above a specified level, is met or not met. Settlement is rapid. There is nothing to negotiate.

There is a further irony that the insurance industry has been slow to absorb: Secondary perils are more parametrizable than primary ones, not less. Hurricane track and wind-field modeling involve genuine uncertainty that makes trigger design difficult. Hail accumulation, flood depth, wildfire proximity, and freeze intensity are all measurable in near-real-time from satellite and ground-based observation networks. The basis risk problem that has historically constrained weather derivatives - the gap between the trigger event and the realized loss - closes considerably when AI-driven models can calibrate triggers at the property level rather than the regional index level. The technical barriers to frequency-risk transfer are lower than they have ever been. The remaining barrier is product design inertia.

Where the unpriced accumulation is building

The geographies that have already experienced market disruption are not the only exposures deserving attention. The next unpriced accumulation is building in the Midwest and upper South, where severe convective storm frequency has been running at record levels for three consecutive years and reinsurance treaty structures still treat hail and tornado losses as below-threshold attritional items.

The carriers and risk managers who treat secondary peril accumulation as a known quantity that can be managed through pricing and underwriting tightening alone will find, in the next five years, that they have been solving the wrong problem. The cat model was built for the kind of disaster that makes the front page. The losses that will define the next decade are the ones that happen every season: individually unremarkable, collectively devastating, and structurally unhedged by the instruments the industry currently relies on.


Siddhartha Jha

Profile picture for user SiddharthaJha

Siddhartha Jha

Siddhartha Jha is the founder, chairman and CEO of Arbol, a global climate risk solutions platform focused on data-driven parametric insurance.

Jha is also a co-founder of dClimate, the first decentralized climate information ecosystem. Prior to Arbol and dClimate, he had over 13 years of experience in the financial industry. Jha launched an agriculture futures trading portfolio, managing over $100 million at a major commodity trading firm.

Climate Risks Challenge Family Offices

As climate risks mount and insurers retreat, family offices must shift from awareness to strategic action through defined risk philosophies.

Puzzle Pieces

Today's family offices know they face a growing list of climate-related risks. From catastrophic wildfires in California to severe wind and hail events across the Midwest, losses are increasing at an unprecedented scale. According to Aon's 2026 Climate and Catastrophe Insight, the Palisades and Eaton Fires were the costliest events of last year at $58 billion, while severe convective storms – associated with thunder, lightning, heavy rain, hail, strong winds and sudden temperature changes – resulted in the highest aggregated losses at $68 billion. While no hurricanes made landfall in the United States in 2025, the previous eight years saw an average annual economic loss of over $75 billion from named storms.

In high-threat zones, rising insurance premiums and shrinking coverage options are making it more difficult for family offices to rely on traditional risk transfer alone. While awareness of climate risks and their related coverage issues is widespread, the real challenge is to move into strategic action. A clearly defined risk philosophy can help lead the way.

What is a risk philosophy?

A risk philosophy defines how a family approaches risk tolerance, risk transfer, and risk mitigation across their portfolio of assets. It guides decisions around deductibles, insurance structures, and capital investments in property protection.

The value of a risk philosophy

While the insurance market is starting to soften, property owners in some regions are seeing a 20% increase in premiums based on the individual characteristics of the location. Family office managers reviewing their insurance spend are seeing a clear and significant upward trend with premiums.

Coverage options are also becoming more limited. In regions prone to wildfires, hurricanes or severe convective storms, insurers are pulling back. Limits are declining, and deductibles are increasing – or insurance carriers are exiting these locations altogether. This has prompted family office managers across the country to consider the question: What can we do to better manage and mitigate these growing risks? A thoughtful risk philosophy can help answer that question.

How to design a risk philosophy

Every family will have their own risk philosophy and tolerance. For some, this means prioritizing lower deductibles on primary or high-use properties. It could also involve taking a self-insured approach for certain properties, redirecting savings into resiliency strategies. Ultimately, it is a balancing act that comes down to determining what matters most and applying that perspective consistently across a family's property portfolio.

That consistency is key, especially for family offices managing multiple homes. However, a strong risk philosophy is not rigid – it should allow for nuance and evolution. For example, a portfolio of houses may generally favor higher deductibles, but a single property located in a high-risk wildfire or hurricane zone might warrant a different approach. In that case, a family might take the self-insured route and invest more in mitigation. It all comes down to each homeowner's unique risks.

Depending on a property's location, there are many different strategies a homeowner could put in place to help improve resiliency. In coastal flood-prone areas like Florida, this may include evaluating elevation, improving drainage and installing flood vents. In wildfire-exposed regions like California, creating defensible space, installing ember-resistant vents and adding roof sprinkler systems can all help reduce risk.

Conclusion

Building a risk philosophy is not a one-time strategy. Risk is dynamic, and both environmental conditions and the insurance market continue to evolve. It is important to re-evaluate risk philosophies annually and think about what can be done differently to help make a property more resilient.

For family office risk managers, staying ahead of emerging risks and solutions is essential, and a clear risk philosophy can inform a more strategic approach. If you are not already having these discussions with an advisor, now is the time.

This article is provided for general purposes only and does not provide individual advice. This article should not be viewed as a substitute for the guidance and recommendations of a retained professional. Readers should seek advice from their own qualified professionals before making decisions based on this article.


Jason Ott

Profile picture for user JasonOtt

Jason Ott

Jason Ott is the president of Aon Private Risk Management.

He joined Aon 20 years ago and has spent the last 23 years focusing exclusively on the affluent personal lines insurance marketplace.

What Happens to Auto Insurance When There Are No Drivers?

Tesla's driverless Cybercab signals an industry shift that commercial auto insurers have not seriously prepared to address.

Autonomous Vehicle

In April, something significant happened in the auto industry: Tesla confirmed that production had begun on its Cybercab, a fully autonomous vehicle with no steering wheel, no pedals, and no human in the loop. Until now, the conversation has focused on what this means for Uber and Lyft and on whether robotaxis are going mainstream.

But perhaps there's an equally consequential question. What happens to the insurance industry once the driver has gone the way of the Edsel? Unfortunately, the industry has not seriously tried to answer it.

The Model Was Built Around the Human

Commercial auto insurance was designed around a single variable: the person behind the wheel. That is why insurance prices reflect driving behavior; liability follows whoever was driving, and policy language assumes a human making decisions on the road in real time. The full architecture of risk assessment, premium calculation, and claims resolution rests on the assumption that human judgment is what gets priced.

Open almost any commercial auto policy today, and the human driver as the unit of risk appears on nearly every page. But remove the driver, and pricing assumptions, liability triggers, and claims logic all rest on a human variable that no longer exists. So the language built for that world has to be rewritten.

Autonomous vehicles are no longer theoretical. From Level 3 consumer vehicles to more than 700,000 weekly robotaxi rides globally, deployment is moving faster than the regulatory frameworks meant to govern it. With that comes an even deeper anxiety the industry rarely discusses openly - autonomous vehicles are much safer than vehicles with human drivers. Research in Traffic Injury Prevention found Waymo cut injury-causing crashes by 79%, with intersection crashes down 96%. Tesla reports Full Self-Driving (Supervised) improves U.S. road safety by over 80%.

On its face, all of this is nothing but good news. But for an industry where roughly half of all premiums are tied to auto, those numbers describe an existential shift. Fewer claims are indeed good for society, but they also represent a fundamental challenge for a business model never redesigned to reflect it.

The Transition Is the Real Challenge

The most challenging chapter is perhaps underway, in the chaotic middle ground before full autonomy becomes the norm.

Waymo's current operating model shows how messy this can be. In Austin, it has partnered with Uber, while in San Francisco it competes directly against Uber and Lyft. In both markets, it works with maintenance fleets including Hertz, Avis, and new AV service companies. Each raises different insurance questions.

Once a Waymo comes off the road and a human driver takes it in for service, there is no settled answer for what is being insured. These vehicles can be worth hundreds of thousands of dollars due to their embedded sensors and software. If a maintenance technician damages a radar unit and that vehicle later causes an accident, is the resulting liability an auto insurance issue or product liability? Current policies do not offer a clean answer.

Mixed-fleet operations carry that ambiguity: overlapping liability, unclear ownership of risk, and policy language written for a world that no longer exists. The work ahead, therefore, is a fundamental redesign of how liability gets assigned in multi-party autonomous operations. When something goes wrong, the question of responsibility, whether the OEM, the platform, the maintenance fleet, or the software provider, has no clean answer.

Data is the starting point, and fleets like Waymo and Tesla are sitting on enormous amounts of operational data that could reshape how risk is understood and priced. But that means insurers need access to that data, and the frameworks to build products around how these vehicles actually operate.

Regulators have a significant role to play, too, because the state-by-state patchwork that just about worked for rideshare will not scale for autonomous vehicles. Federal coordination on liability standards and minimum insurance requirements for AVs would give the industry a target to build against.

The Window to Get Ahead Is Narrower Than It Looks

The rideshare era offers a partial template. When Uber arrived, insurance took years to catch up, but the industry muddled through. However, the trajectory this time looks faster. Nevertheless, unlike the rideshare era, the industry already knows how to build insurance products for markets without a rulebook.

But the scale is different, the liability questions more complex, and the next major AV incident will create enormous pressure to fix things quickly, in public, under scrutiny. Waiting for that moment is the wrong strategy.

Insurance has to shift from static to dynamic, using real-time data to map how risk is distributed across platforms, fleets, maintenance partners, and technology providers. Liability has to follow that data through every link in the chain.

Adapting will not be enough, because a model that priced human behavior for a century is finished. What replaces it will look almost nothing like today's commercial auto insurance. Carriers treating this as a rebuild will define the next era of mobility risk. Everyone else will be left writing policies for a road that no longer exists.


Dan Bratshpis

Profile picture for user DanBratshpis

Dan Bratshpis

Dan Bratshpis is a co-founder of INSHUR.

He began his career on Wall Street, working on the transition to algorithmic technology. Believing that the insurance industry is ripe for similar disruption, he moved into the on-demand economy space in 2016. As an immigrant to the U.S., he realized that the on-demand economy enables lots of entrepreneurs to make a living on platforms such as Uber, Amazon, and Turo. 

He is a graduate of Cornell University.

Carriers Face Retention Problem

Record insurance shopping driven by economic stress forces carriers to shift from reactive pricing tactics to proactive retention strategies.

Winning Chess Pieces

American household budgets are facing pressure from every direction. Grocery bills remain stubbornly high. Gas prices have shot up—and face further surges as politically volatile oil-producing regions continue to roil.

Meanwhile, layoffs across technology, retail, and financial services sectors have put millions on uncertain footing—many of them "white-collar" members of the homeownership class. In response, consumers are putting every line of their monthly budget under a microscope. As families cut out food delivery and forgo or downgrade streaming services and other niceties, a four-figure annual insurance premium is no longer the kind of expense people renew reflexively.

Together, pricing pressures and income instability combine to drastically change insurance shopping behavior. This puts carriers in a race to understand—and hopefully prevent or at least forestall—what looks like a retention crisis. (It's not the first time we've been here: the post-9/11 hard market of 2001-2003 triggered a similar wave of shopping and switching as carriers raised rates sharply across nearly every line, and the mid-1980s hard market produced comparable consumer flight before conditions softened.) The carriers that "crack the code" to curb inflation through efficiency will provide needed breathing room for their customers, while creating competitive advantages with a potentially long tail.

The Numbers Reflecting a Stressed Consumer

The percentage of U.S. consumers shopping around for a new auto insurance carrier reached a record 57% in 2025, up from 49% in 2024, and about 29% switched carriers outright, according to the J.D. Power 2025 U.S. Auto Insurance study survey. Progressive CEO Tricia Griffith assertively underscored what's driving this dynamic on a 2025 earnings call: "I think it's just easier to shop. And I think with all the other inflationary items out there, people are looking to figure out a way to save money."

This is not simply a market anomaly or part of a business cycle. It's evidence of a financially stressed customer base doing exactly what financially stressed people do: seek relief wherever they can find it.

For many households, reducing insurance costs is the rare large recurring expense that responds to user effort. When a family is already shopping in-house brands at the supermarket and delaying purchases, saving several hundred dollars on an auto renewal is a meaningful win.

Carriers that recognize the emotional and financial context behind that shopping behavior (hint: it's not a simple matter of competitive comparison shopping; it's born of necessity) will approach this moment via innovation and empathy.

Raising the Ceiling by Focusing on the High-Value Customer

Not all shopping activity carries equal risk. Many consumers most actively reconsidering their policies right now also happen to be the ones with the greatest profit potential. One-third of customers shopping in 2024 were seeking auto and home insurance bundles, according to the latest J.D. Power Insurance Shopping Study. These are multi-policy, long-tenured households, precisely the customers who anchor a carrier's book.

Winning one bundled household is worth multiples of a single-line acquisition. It's why insurance brands lean so hard into bundling offers and messaging. Carriers building strategies targeting this specific segment will see outsize returns. The opportunity lies not in chasing after new customers from a depleted pool, but from reaching the ideal existing customers at precisely the moment they are open to having constructive conversations about finding economies through scaling the relationship with their insurer.

Maximizing the Value of Every Touchpoint

To do this, your playbook doesn't need to be more complex, but your tactics need to be more intentional. Research consistently demonstrates that insurers who reach out to policyholders before renewal, with plain-language explanations tied to real cost drivers, see stronger results than those who respond only after a customer complains about a rate increase.

A customer who just paid more for ground beef, gas, and a car repair is not well-positioned to absorb a renewal increase without being told why. The same customer, reached proactively with a clear explanation and a conversation about coverage options, feels "seen" rather than squeezed. That distinction drives decisions more reliably than any pricing adjustment alone.

Reaching the customer before they open a comparison tool changes the entire dynamic. It signals that their relationship with you matters, which is exactly what a financially pressured household needs to hear.

Remaking Traditional Workflows

Seventy-six percent of carriers now deploy AI in at least one underwriting or pricing function, according to industry data. The carriers positioned to win are the ones who use it thoughtfully: "how will this AI-enabled workflow help us reach our [financial performance/customer service/NPS] targets consistently?" Surprisingly, this philosophy is not as common among insurers as one would hope. Carriers that get this right understand a critical distinction: the goal is rethinking how work gets done, not how they can reduce the number of people doing it. AI doesn't replace an underwriter's judgment or an agent's relationship with their client—it removes the friction that keeps both from doing their best work. McKinsey's research on AI in insurance further underscores this point, noting that the highest-performing carriers treat AI as a workflow redesign challenge, not a headcount equation.

Use AI to flag households where a proactive coverage conversation can strengthen relationships, rather than give competitors a foot in the door. AI deployment of this sort builds an advantage that compounds over time, making every renewal a trust-building touchpoint, rather than creating potential pricing negotiation standoffs.

The Open Window

Market disruption creates winners and losers—only now this happens at, well, the speed of AI. The carriers gaining the most ground in the next three years will not be those that waited for customers to leave before responding. They will be the ones who anticipate and respond to a record-size shopping market driven by "kitchen table" financial stresses as an opportunity to demonstrate why their policy is the one worth keeping.

The carriers who view this moment as an inflection point created by decades of shifting macroeconomic factors (wage stagnation, globalization, etc.), rather than a discrete trend to watch, will look back on 2026 as the year they separated themselves from a crowded field. The real choice is not whether to compete for customers who are shopping. It is acting with intent to keep your customers while giving consumers good reason to choose you over your less responsive competitors.


Diane Brassard

Profile picture for user DianeBrassard

Diane Brassard

Diane Brassard is an operations and AI transformation leader specializing in the insurance industry. With three decades of experience spanning underwriting, claims, and BPO strategy at major carriers, she helps insurers design and execute practical, scalable workflows, whether powered by AI or process redesign, that drive measurable business results.


James Ballot

Profile picture for user JamesBallot

James Ballot

James P. Ballot is an insurance research, thought leadership, and content strategy leader with more than a decade of experience helping industry, regulatory, business, consumer, and higher education audiences understand and navigate complex industry transitions – including the rapid evolution of insurtech and AI-driven automation.

Managing the Risks From Thinking Machines

As AI shifts to autonomous decision-making across insurance, traditional governance cannot identify or control the resulting systemic risks.

Robot Pointing to Its Head

This article is the second of three parts. The first and third parts are here and here.

 

The question is not whether intelligent machines can have emotions, but whether machines can be intelligent without emotions – Marvin Minsky

Artificial intelligence, particularly generative and agentic systems, has altered insurance risk not by optimizing processes but by transforming how decisions are formed, executed, and propagated. As AI operates autonomously across tightly coupled workflows, failures that were once local and visible become systemic, invisible, and fast-moving. Errors no longer emerge gradually through human judgment but accumulate unnoticed across the value chain, amplify through feedback loops, and crystallize as financial, regulatory, or reputational risk before intervention is forced.

For insurers, the core question is no longer whether AI can improve underwriting, claims, or service efficiency, but whether the risks introduced by autonomous decision-making, model opacity, concentration, and fragmented governance can be identified and controlled within existing institutional structures. This article focuses on mitigating AI-related risk, outlining the governance, control, and contractual mechanisms required to manage autonomous, probabilistic systems.

Managing the Risks

The same features that make AI powerful also introduce fragility and new risk categories. Speed amplifies error, autonomy removes human checkpoints, and adaptive model behavior can degrade silently until losses accumulate. AI systems, including generative and agentic models, are already embedded in underwriting, pricing, claims, fraud detection, and portfolio management. In these systems, errors can propagate at automated scale, model drift can distort outcomes without warning, and concentration in shared models and platforms can create correlated exposures across firms and markets. Managing these risks requires governance, commercial discipline, and continuing regulatory engagement that differ from traditional technology risk management (see Figure 1).

Figure 1: Managing AI Risks

Governance Imperative

Generative and agentic AI introduce unprecedented risks for insurers, yet governance has not kept pace. Companies are absorbed by rapid technology growth and new capabilities, focusing on building and deploying AI rather than governing it. Effective AI governance requires disciplined algorithm and model management, covering interpretability and auditability across production systems. These standards cannot be sustained without executive ownership.

AI Risk Committee

AI governance at the model and validation level requires a cross-functional AI risk committee with decision-making authority over model deployment, not an advisory body. As AI becomes embedded across the entire insurance value chain, the committee and its subcommittees must work in close coordination. The committee must review models for bias and opacity before deployment, enforce continuous monitoring standards, and retain accountability when automated decisions cause harm.

Establishing AI Leadership

Insurers must formalize AI leadership to make strategic oversight a baseline requirement. The role that meets this need is the chief AI officer, a senior executive with authority to align AI strategy with business goals and enforce consistent governance. An AI center of excellence under this role centralizes expertise, aligns AI initiatives, and enforces accountability to reduce risk and meet regulatory obligations.

Vendor Diversification

Vendor diversification is critical to managing generative and agentic AI risk. Insurers must assess AI providers technically, not treat procurement as commercial exercise, and avoid over-concentration on a single vendor. In periods of geopolitical stress, providers may face state or regulatory action that restricts access to platforms or services, disrupting the insurance operations.

Organizational AI Literacy

AI literacy does not require technical depth across the organization. It requires underwriters, claims managers, and executives to spot failure signals, question automated decisions, and override them when needed. This human judgment underpins all technical controls. Governance fails when people do not understand model limits or risks, or when outputs are treated as authoritative and human review becomes procedural.

Controlling the Machine

As AI systems shift from decision support to autonomous action, control becomes an engineering and governance problem rather than a procedural one. Decisions are executed continuously at speeds beyond human review, collapsing the gap between judgment and consequence. Risk no longer stems from discrete failures but from interaction and scale. Managing such systems requires authority over machine behavior in production, the ability to recognize unsafe autonomy, and early intervention before errors become embedded or irreversible.

Human-in-the-Loop

Human‑in‑the‑loop override is an operational requirement inherent to automated and agentic AI systems, arising from their technical limits rather than preference. Automated and agentic systems act based on their training data, objectives, and delegated authority, and when real‑world conditions fall outside those bounds, decision quality degrades, often without warning. The ability for a qualified human expert to review and override an agent's decisions at defined control points, supported by an organizational culture that encourages such intervention, remains the primary safeguard against silent systemic error, particularly when those errors propagate quickly and are hardest to detect.

Adversarial Red Teaming

Insurers should adopt adversarial red teaming as formal control for AI risk. An internal team independent of model development and deployment should probe production AI systems to identify how they fail rather than confirm that they operate as designed. In practice this includes testing whether claims models can be misled by fabricated evidence, whether pricing models can be manipulated through synthetic applicants, and whether automated damage assessment systems can be induced to produce incorrect outcomes. Testing that is limited to known attack patterns is regression testing rather than red teaming. Effective red teaming focuses on discovering previously unknown failure modes, which are the failures most likely to surface in real‑world operations.

Independent Model Validation

Insurers should treat independent model validation as a core control that complements regulatory audit and counters the natural incentives of model owners to focus on intended performance rather than failure. This requires validation teams with genuine independence from the business units they review, supported by out‑of‑sample testing, adversarial stress testing, and reporting lines insulated from the business units whose models are being validated. The cost of adequate model validation is a fraction of the expected loss exposure from a single ungoverned model failure, whether through pricing error or discriminatory outcomes.

Data Lineage Tracking and Drift Management

Knowing precisely where training data came from, how it was processed, and what rights are attached to it is essential to address IP liability, regulatory exposure, and bias risk at the same time. Without this, the insurer will be building intelligence models on a foundation whose integrity cannot be verified. Insurers need robust, data‑driven schedules for retraining and updating AI systems, with automated triggers that pause models when performance falls below a defined threshold to address drift directly.

Model Output Guardrails

Model output guardrails define the boundaries within which an AI system is allowed to operate. They serve as a standing control that limits the impact of vulnerabilities identified through red teaming. In insurance deployments, guardrails should operate at the content, decision and output levels. This includes constraining pricing outputs to actuarially defensible ranges, enforcing mandatory human review for high‑impact or regulator‑sensitive decisions, and restricting generated customer communications to legally verified positions.

Kill Switch

The kill switch is the operational mechanism by which a deployed AI system can be immediately suspended, constrained, or rolled back when its behavior is identified as harmful, anomalous, or outside the parameters permitted by its governance framework. This is not a conceptual safeguard, but a technical mechanism embedded in production workflows. A functional kill switch includes automated triggers that act when predefined thresholds are breached, such as surges in adverse underwriting decisions, pricing outputs that fall outside actuarially defensible limits, or claims error rates that exceed tolerance levels. Governance requires kill switches that operate at machine speed and authority structures that allow rapid intervention that is proportional to potential risk.

Risks and Coverage

Insurers occupy dual positions as both providers of coverage for AI-related risks and users of AI-enabled technologies within their own operations. AI-related risk and liability implications extend beyond insurers' internal operations to the external threats across the risks they underwrite. AI introduces loss dynamics that differ materially from traditional drivers, and agentic systems require a reassessment of how coverage is defined, how fault is attributed, and how liability is distributed. The nearest relatable risk category to this is cyber risk, not because the mechanisms are identical, but because both introduce systemic, non-linear losses that propagate across insured ecosystems. This exposure requires tight alignment between underwriting intent, policy wording, and operational risk appetite, to ensure that the liabilities insurers accept can be priced and controlled within the boundaries implied by the coverage they offer.

Rethinking Policy Wording

Traditional insurance policy contracts were not designed for a risk environment in which losses arise from the use of autonomous systems by customers across their operations, products, and services. Updating policy wording therefore requires more than incremental change. Insurers must reassess how coverage is defined, how causation and responsibility are attributed when autonomous systems fail, and which categories of AI-driven risk they are prepared to underwrite. AI-specific inclusions and exclusions must be drafted deliberately and precisely, rather than adapted from existing cyber or professional indemnity language. The legal and financial distinction between AI system failure and conventional technical or operational error must be explicit, as ambiguity will inevitably lead to coverage disputes.

AI-Specific Exclusions and Sub-Limits

Traditional underwriting approaches must be extended to address AI-specific risk vectors, particularly those introduced by generative and agentic systems that remain difficult to price reliably. Insurers should use targeted exclusions and sub limits to bound exposure to failure modes such as losses arising from hallucinated or fabricated outputs and cascading agent behavior that propagates errors across systems. Sub limits that cap cumulative exposure from a single automated decision thread or agent-driven process are a prudent portfolio control, especially in early deployments where behavior remains unstable. Coverage should also be restricted where generative outputs are used without mandated human review, where models are retrained or prompted outside approved controls, or where autonomous systems adapt objectives not disclosed at the beginning.

AI‑Native Risk and Coverage Constructs

Insurance coverage for AI must evolve because risk triggers shift from discrete, event‑based, human‑initiated failure to continuous, autonomous behavior operating at scale. Traditional coverage lines such as cyber liability, professional liability, directors' and officers' liability, product liability, intellectual property, employment practices, and regulatory liability were built around predictable failure modes, identifiable human acts or omissions, and linear causation. These assumptions break down with respect to agentic systems that learn, interact, and act autonomously in production. Recalibration therefore requires changing how these existing covers attach and respond. They must be re‑anchored to observable system behavior rather than point failures and structured to distinguish between system failure and intentional interruption of automation. At the same time, the shift in risk source necessitates entirely new coverage constructs to address exposures traditional frameworks were never designed to absorb, such as model failure protection, autonomous decision indemnity, AI‑enabled fraud coverage, AI supply chain liability, AI‑triggered business interruption, and catastrophic AI accumulation risk.

The Customer Obligation

As decision making authority shifts from people to machines, the insurer's obligation to the customer changes in character, and meaningful recourse. Trust in an AI-driven insurance model depends on whether customers can know when automation is at work and are able to challenge outcomes through processes that are independent, effective, and humane.

Explainability and Transparency Disclosures

The obligation of the insurer to explain pricing and underwriting decisions in terms that a customer can understand is both a regulatory requirement and a minimum standard of fairness. Transparency disclosures about when and how AI is used, including key data points that affect pricing, and what recourse is available when something goes wrong, are the foundation of informed consent in an AI-driven market.

Addressing Protection Gaps

AI increasingly enables granular risk segmentation and personalized pricing, leading to a decomposition of the insurance risk pool. Consequently, lower-risk individuals benefit from reduced premiums, while higher-risk individuals are priced closer to full actuarial cost, which may even make insurance unaffordable to some. The resulting protection gap disproportionately affects low-income households and small businesses, which often carry higher structural risk and lack the resources to absorb higher premiums or meet AI-related risk requirements. To address this, regulators and policymakers may need to define limits on permissible risk granularity and pricing personalization to preserve insurance's social function and economic resilience. As the coverage of last resort to absorb catastrophic AI failures, public-private risk pools, including government-backed schemes, may be necessary for AI-related systemic events. Such mechanisms function as the reinsurance equivalent for systemic AI exposure and complement regulatory constraints on pricing and underwriting practices.

Customer Appeal Mechanisms

A customer appeal mechanism is the operational and legal pathway through which an individual, who was adversely affected by an automated insurance decision, can challenge that decision and obtain a review that is substantively independent of the system that produced it. The effectiveness of the mechanism depends on design rather than mere availability. An effective functional appeal mechanism requires that the customer is informed, in clear terms, of the factors considered in making the decision. Upon appeal, the earlier decision must be reviewed by a qualified human with authority to change the outcome. For insurers, appeal mechanisms are the procedural complement to explainability obligations.

Build for Scrutiny

The regulatory environment for AI in insurance has moved beyond principles and consultation. Regulators across many jurisdictions have published governance and audit requirements for AI systems in use, especially in underwriting or claims. Regulators advise insurers to adopt a risk-proportionate supervisory approach, calibrated to whether a system is customer-facing and to the scale of deployment.

Internal Regulatory Readiness

Internal regulatory readiness requires creating an inventory of all AI systems in production. These should be audited for bias, including sensitivity analysis, error rates, and plain language explainability. It also requires audit trails that can withstand regulatory examination. Regulatory requirements now specify action thresholds at which a model must be remediated or disabled, supported by full validation documentation available for internal and third-party audits.

Immutable Logs

An immutable log is a record of AI system activity that, once written, remains fixed and tamper-proof, preserving a complete and authoritative account of the actions and decisions it records. Immutable logs capture model inputs, decision outputs, human overrides, and timestamps in a sequenced and verifiable form. In insurance context, it is a record of how AI systems influence underwriting, pricing, claims handling, and customer decisions. The requirement for immutability arises when an automated decision is later challenged by a policyholder, a regulator, or a court. In those situations, insurers must demonstrate exactly what data was used, which model version was active, what decision was produced, and whether any human intervention occurred, based on contemporaneous records rather than post hoc explanations.

Proactive Regulatory Engagement

Proactive regulatory engagement goes beyond risk management and requires deliberate action. For insurers, this means engaging regulators early on specific AI use cases, sharing evidence on model performance, limitations, and failure modes. It also involves testing proposed governance approaches against production systems rather than principles. Effective engagement includes supervisory discussion on model validation, monitoring, and override processes, as well as transparent disclosure of where automation is used in customer-facing decisions. Insurers that engage in this way are better positioned to influence standards toward technically workable requirements and to demonstrate credible oversight grounded in operational reality.

Governing AI in Production

AI adoption in insurance has moved beyond experimentation, but governance maturity is yet to keep pace. While AI is deployed across the insurance value chain, controls do not operate effectively because they are not adequately resourced, and AI systems that are not governed at the model level remain an unmanaged risk. Responsible AI deployment requires governing the model, not just monitoring outcomes. This includes accountable leadership and intervention capabilities that allow automated decisions to be challenged or withdrawn. It also requires legal structures, including coverage design and policy wording that align with autonomous decision-making. Customer protection depends on ensuring that speed and scale do not outrun obligations to explain decisions, price fairly, and provide effective appeal. As AI deployment is already underway, the issue is more about whether governance is sufficient to avoid regulatory intervention, litigation, and loss of trust.

The Risks of Thinking Machines

As AI shifts from advisory tool to autonomous decision-maker, insurers face new risk categories that traditional frameworks weren't designed to address.

Robot

This article is the first of three parts. The second and third parts are here and here.

 

By far the greatest danger of AI is that people conclude too early that they understand it. – Eliezer Yudkowsky.

In recent years, artificial intelligence (AI), especially generative and agentic AI, has crossed a major qualitative threshold. Traditional AI functioned mainly as an analytical tool, trained to infer patterns from historical data. In contrast, generative and agentic AI can originate ideas, sequence actions, and pursue objectives with limited human input. These systems do not merely recommend outcomes but produce them and act in real time. For insurers, this shift from advisory AI that supports decision formation to autonomous, execution‑oriented AI that initiates actions fundamentally shifts the structure and propagation of risk.

A substantial body of literature already exists detailing the benefits of AI in insurance. Instead of parroting those stock arguments, this article focuses on the new categories of risk AI introduces. While AI introduces both advantages and vulnerabilities, the direction in which the needle points depend less on the technology itself and more on the design choices and accountability of its deployers.

Risks on the Radar

Generative and agentic AI systems act autonomously, pursuing objectives through connected, chained decisions. The same properties of speed, autonomy, scale, and tolerance for complexity that make AI powerful also create fragility. Speed becomes a systemic risk when a flawed model operates across thousands of policies before detection. Autonomy becomes a governance crisis when no human has reviewed a harmful decision. Scale becomes a concentration risk when the industry relies on a small number of foundational models supplied by a few technology companies. Complexity becomes a risk when systems operate across interdependencies that no human can fully observe or interrupt once execution is underway.

Insurance is a contract expressed through actuarial representations such as mortality tables, exposure curves and loss triangles, supported by the arithmetic of large numbers. It assumes uncertainty can be analyzed and managed through human judgment and controlled processes. AI does not change this premise, but as systems reason and act autonomously, they introduce new forms of uncertainty that traditional insurance frameworks were not designed to absorb. These include models that fail silently and tightly coupled systems where a single flaw can cascade across portfolios, or markets within seconds.

Over several decades, AI systems have improved continuously, shifting both the benefits and risks of insurance. Because these advances were incremental and focused on augmenting human decision-making, the industry absorbed them without disrupting business models. Risk frameworks were built for static models, historical data, and failure modes that emerged slowly. However, these frameworks are poorly suited to systems that decide autonomously, act in real time, adapt to context, and learn continuously. Current progress is exponential, disrupting business, operational, economic, and risk models. AI‑related risks can be grouped into four domains, namely, model and system integrity, operational and financial stability, regulatory and governance exposure, and societal risk. (See Figure 1)

Figure 1: Risks on the Radar

Model and System Integrity Risks

Model and system integrity risks originate within the logic, learning, and dependencies of AI systems themselves. Unlike traditional model risks, they are not confined to isolated failures but emerge from how models evolve, interact, and scale in production. These risks operate silently, compound over time, and typically surface only after losses or exposures have already accumulated.

Algorithmic Bias

Algorithmic bias is among the most widely discussed AI risks in insurance. It reflects the tendency of models to reproduce and sometimes amplify discriminatory patterns embedded in historical data. Models trained on decades of underwriting decisions learn from outcomes that systematically disadvantage certain groups. This creates a black box problem in which decision logic remains opaque. As a result, insurers may be unable to explain outcomes for which they remain legally responsible, allowing biased decisions to persist and increasing litigation and regulatory exposure.

Model Drift, Degradation, and Feedback Loops

Models are trained on historical data and deployed into a dynamically changing world. When the environment changes faster than models are updated, or when model decisions begin to shape the environment they measure, output quality degrades. This degradation often occurs without warning, as models interact dynamically with the market and create self‑reinforcing distortions that are difficult to detect internally.

Feedback loops worsen this problem. A model rewarded for retention may underprice risk to secure renewals. A claims model rewarded for speed may approve claims with limited scrutiny. While the optimization target is clear, the trade‑offs are often not. AI tends to optimize for the metrics by which it is evaluated, creating the appearance of improved performance while degrading outcomes that are important to the business. Systems can learn to exploit proxy measures of success, thereby masking underlying deterioration in decision quality, fairness, and longer‑term risk.

Silent Risk

Silent risk is not unrealized risk, but a risk that accumulates while generating no signal that prompts action. In AI-driven insurance systems, this occurs when models degrade gradually, masking deterioration behind apparent stability. A pricing model can drift from reality without triggering alerts. A fraud model can lose effectiveness against adaptive fraudsters without raising incidents. Because these failures emerge incrementally and lack clear leading indicators, losses are typically attributed to discrete events rather than to the underlying degradation.

Confidently Wrong

Generative AI introduces a risk known as hallucination. Large language models can produce incorrect outputs with high confidence, expressing the same certainty whether content is accurate or not. An underwriter relying on an AI-generated summary may act on information that omits a critical exclusion, invents a risk attribute, or misrepresents a coverage clause. The error is not evident from the output because the model does not signal uncertainty. This risk is amplified by fluency-induced epistemic trust, which leads to cognitive offloading, where the human-in-the-loop applies reduced reasoning and independent scrutiny to the output.

Concentration Risk

Every industry, including insurance, is converging on a small set of foundational AI models from a few technology firms. These include large language models, cloud-based scoring services, and third-party risk platforms. This creates an unprecedented structural vulnerability. If a widely used model contains a systematic bias or error, the correlated impact across insurers can be severe. A pricing flaw that underprices a specific risk class could create simultaneous reserve shortfalls for multiple insurers using the model. Reinsurers, the traditional absorbers of such shocks, face the same exposure if they rely on the same models to price treaties.

Data Privacy and Personal Data Rights

Generative AI increases the scale of privacy risk. Unlike traditional AI, which works on defined data sets, generative AI processes far larger volumes of unstructured data in ways that are harder to audit or govern. Risk is highest when systems access unauthorized data, use data beyond the scope of consent. Continuous monitoring of customer behavior can constitute privacy intrusion even when individual data points are not sensitive. A large language model trained on proprietary customer data carries exposure that rule-based systems do not. Data rights such as erasure are difficult to apply because large models embed training data in ways that are hard to isolate or remove. For insurers operating across jurisdictions, these factors create layered regulatory exposure that existing data governance frameworks were not designed to manage.

Operational and Financial Risks

Operational and financial risks arise not only from how AI models are designed, but from how their outputs are embedded into routine insurance operations. As AI systems move from advisory roles into decision-making and execution, errors propagate directly into underwriting, pricing, and claims processes.

Autonomous System Malfunction

Human errors in manual processes are contained because they occur at human speed, so a systematic underwriting error typically affects a limited number of cases before detection and correction. Failures in generative and agentic AI processes, by contrast, are largely unconstrained. They occur at machine speed, operate autonomously, and propagate at scale, allowing a single systematic error in an autonomous underwriting system to affect many cases in a short time, a risk poorly captured by existing systemic risk models. This reflects a shift from traditional automation, which executes predefined rules for anticipated situations, to autonomous systems that exercise judgment across situations no human has reviewed or approved. An agentic AI system that assesses risk, determines eligibility, sets terms, and issues policies without human input is deciding rather than applying rules. This distinction is critical for governance and control design. When an automated system fails, the cause is a faulty rule, whereas when a deciding system fails, the cause may be an emergent pattern learned over time that was never explicitly designed or approved and cannot be reconstructed after the fact.

Attribution of Risk

Coverage disputes from AI‑related losses arise from a mismatch between the specificity of the loss and the generality of policy language. When loss results from autonomous system actions rather than human decisions, responsibility becomes unclear and may extend across the organization that deployed the system, the vendor that developed it, the operator that integrated it into business processes, or the data sources that influenced its behavior. Existing policies assume human judgment and rely on concepts such as intent and negligence, or on losses traceable to physical or technical failures. AI‑generated losses often do not fit these assumptions. As a result, insurers may be required to adjudicate claims under policy language misaligned with the facts, in legal regimes that have not yet settled whether software behavior can constitute negligence or how liability should be attributed.

AI-Driven Cyberattacks

Traditional AI systems have long been exploited to enhance cyberattacks by increasing speed and targeting precision. Generative and agentic AI introduce an additional and distinct cyber risk in the form of model manipulation, where carefully crafted inputs induce systems to behave in unintended ways. Prompt injection is the most immediate manifestation of this risk, allowing attackers to influence outputs, extract sensitive contextual information, or trigger unauthorized actions without breaching system perimeters or modifying code. In insurance, where AI increasingly processes customer submitted documents, this exposure is particularly acute. A compromised model may continue to produce fluent and authoritative outputs even after its integrity is undermined, making detection difficult and affecting both data security and decision quality. As a result, model manipulation risks do not fit neatly within existing cyber or operational risk frameworks and remain insufficiently addressed by current monitoring and governance structures.

Erosion of Trust

Insurance is a contract built on future promises and relies on trust. A policyholder who pays premiums for years without claiming expects the insurer to be present and fair when needed. AI introduces mechanisms that can damage this trust by changing how insurance decisions are made. Explicit AI‑driven decisions that appear unfair, unexplainable, or inconsistent with accepted norms can trigger regulatory scrutiny and class action. Hidden risk correlations extend this exposure beyond discrete decision failures and create additional legal risk. A model may identify a statistical relationship between an apparently neutral variable and loss frequency that proves to be a proxy for a legally protected characteristic. Using such a variable may be technically viable, but justifying its use can be unlawful and reputationally damaging.

Moral Hazard Inversion

The conventional moral hazard in insurance is the tendency of policyholders to take greater risks once their loss is covered. Moral hazard inversion is the opposite phenomenon and a distinct consequence of AI delegation. Here, individuals and organizations become less careful not because they expect compensation for losses, but because they trust AI systems to prevent those losses. A claims handler may approve a settlement without independent review because a fraud model has not flagged it, or an underwriter may accept a risk because a pricing model has approved it. Both scenarios represent a transfer of cognitive responsibility to a system whose reliability is uncertain. Losses previously prevented by human vigilance may increase as that vigilance is withdrawn and replaced by trust in AI systems, rendering existing loss frequency assumptions invalid. Pricing models built for a world of human oversight are now applied to one in which attention has been delegated to the model itself, leading to silent and self‑reinforcing underestimation of risk that is difficult to detect until experience diverges materially from expectations.

Regulatory and Governance Risks

The pacing problem, also referred to as regulatory lag, describes the structural gap between the speed at which AI systems are developed and the slower cycle of legislative and supervisory response. In the short term, this gap enables experimentation and rapid innovation ahead of formalized rules. Over time, however, the same gap increases exposure to regulatory correction, including retroactive enforcement and reinterpretation of existing statutes. Given the scale, autonomy, and cross‑sector impact of modern AI systems, regulators are no longer treating this lag as tolerable friction. Governance frameworks are evolving rapidly, shifting from permissive ambiguity toward active oversight and enforcement, a trajectory unlikely to preserve existing assumptions or favor incumbent practices that rely on regulatory inertia. Regulators are moving toward mandatory explainability requirements, model certification processes, audit trail obligations, and capital surcharges for firms deemed to carry unquantified AI risk. For insurers that moved quickly while assuming regulation would evolve gradually, this creates significant compliance exposure. The tension between model performance and explainability is structural. More accurate models are often less interpretable. A regulator who requires a plain‑language explanation for every pricing decision is, in effect, imposing a ceiling on model complexity and therefore on pricing accuracy.

Societal Risks

Insurance serves a social function that goes beyond the contract between insurer and policyholder by enabling the collective management of risk. Many customers pay small premiums so those who suffer large losses are protected from ruin. This mutualization principle, sharing risk across a community rather than pricing each person with full actuarial precision, underpins the social value of insurance. AI, by pushing pricing toward ever greater precision, can weaken this foundation. As risk segmentation becomes more granular, risk pools fragment. Low‑risk individuals pay less while high‑risk individuals face premiums closer to the full actuarial cost of their exposure, making premiums unaffordable and collapsing the pooling function. This produces a widening protection gap. Low‑income populations, already exposed to higher structural risk, are priced out more precisely, while small businesses unable to meet AI‑driven insurance requirements are left without coverage for increasingly significant risks.

As access to coverage narrows, algorithmic exclusion adds a procedural risk. Customers are denied coverage because of opaque decisions they cannot understand or contest. This is not only a service failure but also a governance failure with civil rights implications. At the same time, autonomous systems spreading across the economy create new liability categories that existing insurance architectures were not designed to handle. When systems rather than people cause harm, the attribution of fault among users, developers, operators, and data providers is unclear. Legacy policy language drafted for human decision‑making produces coverage disputes between insurers and policyholders.

Persisting Questions

AI is already deployed across underwriting, pricing, claims, fraud detection, and customer service. Generative and agentic AI, however, represent a qualitative shift. If insurers treat these systems as just another IT initiative, they risk becoming not merely slower than peers, but strategically exposed. The unresolved question is whether insurers will act responsibly. That responsibility extends beyond technical performance to governance adequacy, consumer protection, the identification and management of systemic risk, and the equitable distribution of benefits in a way that reinforces, rather than erodes, the social function of insurance.

Every prior technology wave in insurance introduced new capabilities and new risks simultaneously. Generative and agentic AI pose the same challenge, but at far greater scale, speed, and autonomy. The tools to address these risks are still emerging. Governance frameworks are taking shape and regulatory expectations are hardening. Risk management practices are being adapted for systems that self‑learn and take autonomous action. The open question is not whether insurers have tools available, but whether they will invest in building and scaling them fast enough.